Security · Red Team Engagement
Can your team detect a real intrusion — not just find the hole that let it in?
An undisclosed adversary, a real objective, and a small senior team pursuing it exactly like an attacker would. Your defenders respond without knowing it's a drill — because that's the only way to actually test whether they'd catch one.
Simulated attack path — illustrative
Detected by SOC? Not until the debrief.
What's included
A scoped engagement, not a scan
Every Red Team Engagement is built around one real objective — reaching a specific system, account, or dataset — and run by a small senior team, not an automated sweep.
Objective & Rules of Engagement
A written scoping document: the target objective, your white-cell contact, off-limits systems, and stop conditions — agreed before anything starts.
Full kill-chain execution
Reconnaissance through objective achievement, using the same techniques — phishing, exposed services, physical access, cloud misconfiguration — a real adversary would chain together.
ATT&CK-mapped findings
Every technique used is mapped to a MITRE ATT&CK ID, so "what should have triggered detection" becomes a concrete engineering backlog, not a narrative.
Executive summary
A board-readable overview of what was reached, how, and what it means for the organisation's risk posture.
Attack-path timeline
A reconstructed, step-by-step account of the engagement — every pivot, every credential, every decision point.
Live purple-team debrief
A session with your security/IT team where the red team walks through what happened — collaborative, not adversarial.
Methodology
Six stages, MITRE ATT&CK-aligned
Most of an engagement's duration lives in stage 4 — lateral movement is the long game, not the headline moment.
Scoping & Rules of Engagement
Often takes as long as a full pentest's scoping and execution combined — the objective, the white-cell contact, and every boundary get written down first.
Reconnaissance
OSINT, employee enumeration, and external footprint mapping — building the same picture a real attacker would build.
Initial access
Phishing, an exposed service, a physical attempt, or a purchased foothold — whichever path the scenario calls for.
Persistence & lateral movement
The long phase. Establishing footholds, escalating privilege, and moving toward the objective while staying under the radar.
Objective achievement
Demonstrated, never executed for real — proof that the goal was reachable, without touching production data.
Purple-team debrief
A live walkthrough, technique by technique, turning the engagement into an actionable detection-engineering backlog.
How this differs
Not a deeper penetration test
A penetration test and a red team engagement answer two different questions. Most organisations need both — just not at the same time.
Penetration Testing
- What vulnerabilities exist in these systems?
- Scope: a defined asset list
- Usually disclosed and scheduled
- Tests vulnerability existence
- Days to weeks
- Where most organisations start
Red Team Engagement
- Can an attacker reach this goal — would we notice?
- Scope: a single objective
- Undisclosed except to one white-cell contact
- Tests detection & response, end to end
- Weeks to months
- The next step once hygiene is in place
Is this for you
Who this is — and isn't — built for
Good fit
- You already run vulnerability scanning or penetration testing
- You have a SOC, MDR, or internal detection team you want to genuinely test
- You need to demonstrate detection maturity for a board, insurer, or regulator
- You want findings your engineering team can actually action, not a scare story
Start elsewhere first
- You haven't run a penetration test yet — start there
- You don't have anyone who'd respond to an incident today
- You need a broad vulnerability inventory, not a single objective
- You want employee-level phishing awareness metrics — see Phishing Test →
Before you talk to a consultant
View all FAQs →How is this different from your Penetration Testing service?
A penetration test finds vulnerabilities across a defined set of systems, disclosed and scheduled with your IT team. A Red Team Engagement pursues one real objective, undisclosed to your defenders, and measures whether they'd detect and respond to a genuine intrusion — not just whether a hole exists.
Full answer →Will our own IT/security team know this is happening?
No — by design. Only a small "white cell," usually the CISO or one executive, knows the engagement is underway. That's what makes the detection-and-response test meaningful.
Full answer →What if the team finds something that looks like a real attack in progress?
The Rules of Engagement, agreed before the engagement starts, include a safe-word and stop conditions precisely for this. The white-cell contact can pause or end the engagement immediately if needed.
Full answer →How long does an engagement take?
Typically several weeks to a couple of months, depending on the objective and environment — most of that time goes into the lateral-movement phase, not initial access.
Full answer →Do we need a working penetration-testing programme first?
Yes, generally. Red teaming assumes foundational vulnerability hygiene already exists — the value is in testing detection of an attacker who's already gotten past the easy stuff.
Full answer →What do we get at the end — just a report, or a live walkthrough?
Both: a written executive summary, attack-path timeline, and ATT&CK-mapped findings, plus a live purple-team debrief session with your team.
Full answer →Why isn't there a price on this page?
Every engagement is scoped to a real objective and environment, so a published price list would be misleading rather than useful — the market for this service is quote-driven industry-wide. Tell us your goal and we'll return a scoping call.
Full answer →Related pricing
Penetration Testing
Broad vulnerability discovery across a defined asset list — most organisations start here.
Security Services
All 7 Brocent security services in one directory — bundle, audit, scanning, training, and more.
Phishing Test
A focused, standalone benchmark on human risk — no subscription required.
Scope your engagement
Every Red Team Engagement is quoted individually — objective, environment, and duration all shape it. Tell us your goal and we'll return a scoping call.