Red Team

A multi-vector offensive campaign run like a real attack: no predefined target, no warning to the defense team, combining social engineering, external surface, wireless networks, physical intrusion, and internal network domination.

Multi-vector Human · Digital · Physical
No warning Defense team not informed
MITRE ATT&CK Technique mapping
Custom-sized Hours and window planned per client
01

Service overview

ACT's Red Team is an adversary simulation: instead of going through a list of targets looking for as many vulnerabilities as possible, the team behaves like a real attacker and pursues the greatest possible impact, through any authorized path. There's no predefined target, and the client's defense team isn't warned, because the ability to detect and respond is exactly what's being measured. The result answers a question that no point-in-time test can: if an adversary decided to attack this company today, what would they achieve, and at what point would they be noticed?

Open objective

No target agreed in advance. The team pursues the greatest impact it can achieve, and the report documents exactly how far it got and by what path.

Multi-vector campaign

People, digital perimeter, wireless networks, and physical premises treated as a single surface, exactly as a real adversary sees them.

Measures detection and response

The deliverable isn't just the flaw exploited: it's a record of what your operation detected, what went unnoticed, and what was seen without triggering a reaction.

02

Pentest or Red Team?

Both services are offensive and run by the same team, but they answer different questions. The table below makes the distinction explicit, to avoid contracting the wrong service.

Criteria Pentest Red Team
Central question What flaws exist in this scope? How far would an adversary get, and would we be able to notice?
Goal Coverage: find the maximum number of vulnerabilities Impact: achieve the deepest possible compromise
Scope Closed, with targets listed in advance Broad and adversarial, with no predefined path
Vectors One line per project (web, network, or social engineering) All combined in the same campaign, including physical
Defense team Aware and following the tests Not warned; only a restricted group knows about the campaign
Execution Concentrated within the contracted window Spread over a wide calendar window
Deliverable Vulnerabilities classified by severity, with remediation Attack narrative, detection matrix, and recommendations for the defense team
Maturity required Any level Environment that has already undergone prior remediation

The services are complementary: pentest fixes the surface, Red Team validates whether the operation can see whoever tries to cross it.

Who this service is for.

Red Team assumes the basics are already covered. If the environment hasn't undergone an intrusion test yet, pentest delivers more value per contracted hour, finds more flaws, in less time, with more direct remediation. Red Team is the next step: it measures the security operation as a whole, not just the assets.

03

Campaign vectors

All the vectors below can be freely combined within the same campaign. The team chooses the path based on what reconnaissance reveals, exactly as a real adversary would, who isn't limited to a single type of attack.

Vector What's executed
Intelligence (OSINT) Gathering public information about the company, its structure, technologies, vendors, and people, to build plausible, targeted attack scenarios
Social engineering Spear phishing targeted at chosen individuals, pretexting with scenarios built around the company's real context, and phone or message contact
External and web surface Exploitation of the perimeter exposed on the internet: applications and portals, VPNs and remote access services, public services, and previously leaked credentials
Wireless networks Attack on the facility's wireless networks, assessment of the guest network, and validation of segregation between the wireless environment and the corporate network
Physical intrusion Unauthorized access to facilities: tailgating, movement through restricted areas, use of accessible network points, devices connected to the environment, and removable media
Internal network and Active Directory From the access obtained: internal reconnaissance, privilege escalation, lateral movement, account compromise, and paths to the domain

The vectors actually used depend on what's authorized in the scope agreement and the contracted hours.

04

Campaign starting point

Defining where the campaign starts is a cost-benefit decision: starting from outside measures the perimeter's resistance, but can consume a good part of the hours before reaching the internal environment.

Model How it starts What it prioritizes
Pure external No prior access at all, just the company name Measures the real resistance of the perimeter and the human factor, from zero to the first foothold
Assumed breach Client provides a host or regular user credential Concentrates the hours on what happens after initial compromise: lateral movement, privilege, and reach
Hybrid model Starts external and migrates to assumed breach at an agreed point Prevents the entire campaign from being spent on the entry attempt, preserving the internal environment assessment

The hybrid model is the most recommended in most cases: the client measures the perimeter without risking ending the campaign with no information at all about the internal environment.

05

Campaign phases

The campaign follows the same cycle as a real attack. Each phase is logged with a date and time, allowing the attack timeline to later be cross-referenced with the client environment's logs and alerts.

  1. 1

    Pre-engagement

    Definition of the authorized scope, limits, trusted agents, calendar window, and hours; signing of the authorization agreement and NDA

  2. 2

    Intelligence

    External reconnaissance and OSINT: mapping the surface, technologies, organizational structure, and people

  3. 3

    Initial access

    Obtaining the first foothold in the environment, through any of the authorized vectors

  4. 4

    Access consolidation

    Maintaining the access obtained throughout the campaign, within what was authorized in scope

  5. 5

    Internal reconnaissance

    Mapping the environment from the inside: domain, servers, critical systems, accounts, and trust relationships

  6. 6

    Privilege escalation

    Elevating privileges on workstations, servers, and the domain

  7. 7

    Lateral movement

    Moving between hosts and segments, toward the highest-value assets

  8. 8

    Action on objectives

    Proving the maximum impact achieved, access to critical systems and data, logged as evidence and without any real exfiltration

  9. 9

    Closeout

    Removal of access, artifacts, and changes introduced during the campaign, with a record of what was removed

  10. 10

    Report and debrief

    Consolidation of the narrative, ATT&CK mapping, detection matrix, and closeout session with the client's teams

06

Operational secrecy and trusted agents

The value of Red Team depends on the element of surprise: if the defense team knows it's being tested, measuring detection and response loses its meaning. That's why secrecy is formally structured, not improvised.

Trusted agents

  • A restricted, named group of client people who know about the campaign
  • The IT team, SOC, and other staff are not informed
  • A reserved communication channel between ACT and the trusted agents
  • Responsible for authorizing, following, and, if needed, stopping the campaign

Safeguards

  • An emergency channel available to stop the campaign at any time
  • Deconfliction: if a real incident occurs during the period, ACT immediately confirms what is or isn't part of the campaign
  • An authorization letter carried by the operator during physical intrusion, proving the action's legitimacy if they're confronted
  • Complete activity logging, for later reconciliation with the client's logs

If the defense team detects and reacts, the campaign did its job.

Being discovered isn't a test failure: it's the best possible outcome for the client, and it's logged in the report with the exact time of detection, the action that triggered it, and the response that followed.

07

Sizing and recurrence

Hours are custom-sized, like ACT's other offensive services, but distributed differently: the campaign occupies a wide calendar window, with action at moments chosen by the team, not continuously.

Item Specification
Contracting model Scope and hours sized project by project, according to the environment's size and criticality
Execution window Wide calendar window, with hours spread over the period; execution isn't continuous
Objective definition Open and adversarial: with no predefined target, the team pursues the greatest achievable impact
Recommended prerequisite An environment that has already undergone an intrusion test and remediation of identified flaws
Recurrence Periodic campaigns are recommended to measure the evolution of detection and response capability over time
Formalization Authorization agreement, NDA, and definition of trusted agents before any activity

Comparing successive campaigns is the most reliable maturity indicator: same methodology, different environment, faster detection.

08

Rules of engagement and limits

A Red Team campaign is the most intrusive activity in ACT's offensive portfolio and, for that reason, the most rigidly bounded. All the rules below are formalized before it begins.

What we do

  • Act exclusively on targets, facilities, and vectors authorized in the scope agreement
  • Active exploitation and proof of the real impact achieved
  • Timestamped logging of every action performed, for reconciliation with the client's records
  • Removal of access and artifacts introduced at the end of the campaign

Limits observed

  • Denial-of-service tests only occur with specific prior communication and authorization
  • No real data exfiltration: access is proven, data isn't removed from the environment
  • Destructive actions and operational disruption are not performed
  • Third parties, vendors, and assets outside the scope are not attacked
  • Campaign stopped immediately at the trusted agents' request

About physical intrusion and social engineering.

These vectors involve people who don't know about the test. The engagement preserves employees' integrity and dignity: no result is presented individually or punitively, and the goal is always to measure processes and controls, not to expose who was targeted.

09

Specifications

Format and delivery PDF report, sent by email at the end of the campaign
Executive summary Business risk reading: what was achieved, the potential impact, and the maturity demonstrated by the operation
Narrative and timeline Full chronology of the campaign, action by action, with date and time, path taken, and decisions made throughout the attack
MITRE ATT&CK map Tactics and techniques used, mapped against the ATT&CK matrix, allowing the campaign to be compared against existing detection coverage
Detection matrix Classification of each action as detected and responded to, detected without response, or not detected
Detection recommendations Logs, alerts, and rules that would have identified the campaign; direct guidance for the defense team to close the gaps found
Evidence Proofs of concept, captures, and artifacts proving each step and the impact achieved
Joint debrief Closeout session with the defense team, reviewing what was detected, what got through, and why

Restricted distribution by design.

The report circulates exclusively between the team responsible for the campaign and the people the client names to receive it. A Red Team report describes the full path of environment compromise; it's by nature the most sensitive document in the project, and all material collected is handled under an NDA.

Want to know if Red Team solves what your operation needs?

Talk to ACT and understand, with clarity, how this solution fits your environment.

Talk to ACT