Red Team
A multi-vector offensive campaign run like a real attack: no predefined target, no warning to the defense team, combining social engineering, external surface, wireless networks, physical intrusion, and internal network domination.
Service overview
ACT's Red Team is an adversary simulation: instead of going through a list of targets looking for as many vulnerabilities as possible, the team behaves like a real attacker and pursues the greatest possible impact, through any authorized path. There's no predefined target, and the client's defense team isn't warned, because the ability to detect and respond is exactly what's being measured. The result answers a question that no point-in-time test can: if an adversary decided to attack this company today, what would they achieve, and at what point would they be noticed?
Open objective
No target agreed in advance. The team pursues the greatest impact it can achieve, and the report documents exactly how far it got and by what path.
Multi-vector campaign
People, digital perimeter, wireless networks, and physical premises treated as a single surface, exactly as a real adversary sees them.
Measures detection and response
The deliverable isn't just the flaw exploited: it's a record of what your operation detected, what went unnoticed, and what was seen without triggering a reaction.
Pentest or Red Team?
Both services are offensive and run by the same team, but they answer different questions. The table below makes the distinction explicit, to avoid contracting the wrong service.
| Criteria | Pentest | Red Team |
|---|---|---|
| Central question | What flaws exist in this scope? | How far would an adversary get, and would we be able to notice? |
| Goal | Coverage: find the maximum number of vulnerabilities | Impact: achieve the deepest possible compromise |
| Scope | Closed, with targets listed in advance | Broad and adversarial, with no predefined path |
| Vectors | One line per project (web, network, or social engineering) | All combined in the same campaign, including physical |
| Defense team | Aware and following the tests | Not warned; only a restricted group knows about the campaign |
| Execution | Concentrated within the contracted window | Spread over a wide calendar window |
| Deliverable | Vulnerabilities classified by severity, with remediation | Attack narrative, detection matrix, and recommendations for the defense team |
| Maturity required | Any level | Environment that has already undergone prior remediation |
The services are complementary: pentest fixes the surface, Red Team validates whether the operation can see whoever tries to cross it.
Who this service is for.
Red Team assumes the basics are already covered. If the environment hasn't undergone an intrusion test yet, pentest delivers more value per contracted hour, finds more flaws, in less time, with more direct remediation. Red Team is the next step: it measures the security operation as a whole, not just the assets.
Campaign vectors
All the vectors below can be freely combined within the same campaign. The team chooses the path based on what reconnaissance reveals, exactly as a real adversary would, who isn't limited to a single type of attack.
| Vector | What's executed |
|---|---|
| Intelligence (OSINT) | Gathering public information about the company, its structure, technologies, vendors, and people, to build plausible, targeted attack scenarios |
| Social engineering | Spear phishing targeted at chosen individuals, pretexting with scenarios built around the company's real context, and phone or message contact |
| External and web surface | Exploitation of the perimeter exposed on the internet: applications and portals, VPNs and remote access services, public services, and previously leaked credentials |
| Wireless networks | Attack on the facility's wireless networks, assessment of the guest network, and validation of segregation between the wireless environment and the corporate network |
| Physical intrusion | Unauthorized access to facilities: tailgating, movement through restricted areas, use of accessible network points, devices connected to the environment, and removable media |
| Internal network and Active Directory | From the access obtained: internal reconnaissance, privilege escalation, lateral movement, account compromise, and paths to the domain |
The vectors actually used depend on what's authorized in the scope agreement and the contracted hours.
Campaign starting point
Defining where the campaign starts is a cost-benefit decision: starting from outside measures the perimeter's resistance, but can consume a good part of the hours before reaching the internal environment.
| Model | How it starts | What it prioritizes |
|---|---|---|
| Pure external | No prior access at all, just the company name | Measures the real resistance of the perimeter and the human factor, from zero to the first foothold |
| Assumed breach | Client provides a host or regular user credential | Concentrates the hours on what happens after initial compromise: lateral movement, privilege, and reach |
| Hybrid model | Starts external and migrates to assumed breach at an agreed point | Prevents the entire campaign from being spent on the entry attempt, preserving the internal environment assessment |
The hybrid model is the most recommended in most cases: the client measures the perimeter without risking ending the campaign with no information at all about the internal environment.
Campaign phases
The campaign follows the same cycle as a real attack. Each phase is logged with a date and time, allowing the attack timeline to later be cross-referenced with the client environment's logs and alerts.
-
1
Pre-engagement
Definition of the authorized scope, limits, trusted agents, calendar window, and hours; signing of the authorization agreement and NDA
-
2
Intelligence
External reconnaissance and OSINT: mapping the surface, technologies, organizational structure, and people
-
3
Initial access
Obtaining the first foothold in the environment, through any of the authorized vectors
-
4
Access consolidation
Maintaining the access obtained throughout the campaign, within what was authorized in scope
-
5
Internal reconnaissance
Mapping the environment from the inside: domain, servers, critical systems, accounts, and trust relationships
-
6
Privilege escalation
Elevating privileges on workstations, servers, and the domain
-
7
Lateral movement
Moving between hosts and segments, toward the highest-value assets
-
8
Action on objectives
Proving the maximum impact achieved, access to critical systems and data, logged as evidence and without any real exfiltration
-
9
Closeout
Removal of access, artifacts, and changes introduced during the campaign, with a record of what was removed
-
10
Report and debrief
Consolidation of the narrative, ATT&CK mapping, detection matrix, and closeout session with the client's teams
Operational secrecy and trusted agents
The value of Red Team depends on the element of surprise: if the defense team knows it's being tested, measuring detection and response loses its meaning. That's why secrecy is formally structured, not improvised.
Trusted agents
- A restricted, named group of client people who know about the campaign
- The IT team, SOC, and other staff are not informed
- A reserved communication channel between ACT and the trusted agents
- Responsible for authorizing, following, and, if needed, stopping the campaign
Safeguards
- An emergency channel available to stop the campaign at any time
- Deconfliction: if a real incident occurs during the period, ACT immediately confirms what is or isn't part of the campaign
- An authorization letter carried by the operator during physical intrusion, proving the action's legitimacy if they're confronted
- Complete activity logging, for later reconciliation with the client's logs
If the defense team detects and reacts, the campaign did its job.
Being discovered isn't a test failure: it's the best possible outcome for the client, and it's logged in the report with the exact time of detection, the action that triggered it, and the response that followed.
Sizing and recurrence
Hours are custom-sized, like ACT's other offensive services, but distributed differently: the campaign occupies a wide calendar window, with action at moments chosen by the team, not continuously.
| Item | Specification |
|---|---|
| Contracting model | Scope and hours sized project by project, according to the environment's size and criticality |
| Execution window | Wide calendar window, with hours spread over the period; execution isn't continuous |
| Objective definition | Open and adversarial: with no predefined target, the team pursues the greatest achievable impact |
| Recommended prerequisite | An environment that has already undergone an intrusion test and remediation of identified flaws |
| Recurrence | Periodic campaigns are recommended to measure the evolution of detection and response capability over time |
| Formalization | Authorization agreement, NDA, and definition of trusted agents before any activity |
Comparing successive campaigns is the most reliable maturity indicator: same methodology, different environment, faster detection.
Rules of engagement and limits
A Red Team campaign is the most intrusive activity in ACT's offensive portfolio and, for that reason, the most rigidly bounded. All the rules below are formalized before it begins.
What we do
- Act exclusively on targets, facilities, and vectors authorized in the scope agreement
- Active exploitation and proof of the real impact achieved
- Timestamped logging of every action performed, for reconciliation with the client's records
- Removal of access and artifacts introduced at the end of the campaign
Limits observed
- Denial-of-service tests only occur with specific prior communication and authorization
- No real data exfiltration: access is proven, data isn't removed from the environment
- Destructive actions and operational disruption are not performed
- Third parties, vendors, and assets outside the scope are not attacked
- Campaign stopped immediately at the trusted agents' request
About physical intrusion and social engineering.
These vectors involve people who don't know about the test. The engagement preserves employees' integrity and dignity: no result is presented individually or punitively, and the goal is always to measure processes and controls, not to expose who was targeted.
Specifications
| Format and delivery | PDF report, sent by email at the end of the campaign |
| Executive summary | Business risk reading: what was achieved, the potential impact, and the maturity demonstrated by the operation |
| Narrative and timeline | Full chronology of the campaign, action by action, with date and time, path taken, and decisions made throughout the attack |
| MITRE ATT&CK map | Tactics and techniques used, mapped against the ATT&CK matrix, allowing the campaign to be compared against existing detection coverage |
| Detection matrix | Classification of each action as detected and responded to, detected without response, or not detected |
| Detection recommendations | Logs, alerts, and rules that would have identified the campaign; direct guidance for the defense team to close the gaps found |
| Evidence | Proofs of concept, captures, and artifacts proving each step and the impact achieved |
| Joint debrief | Closeout session with the defense team, reviewing what was detected, what got through, and why |
Restricted distribution by design.
The report circulates exclusively between the team responsible for the campaign and the people the client names to receive it. A Red Team report describes the full path of environment compromise; it's by nature the most sensitive document in the project, and all material collected is handled under an NDA.
Want to know if Red Team solves what your operation needs?
Talk to ACT and understand, with clarity, how this solution fits your environment.
Talk to ACT