SecurePeakService data sheet · 02 of 05
Offensive security · SP-SVC-02

Objective-Based Red Team Operation

A multi-phase operation against your crown-jewel assets, emulating a named threat actor with their documented TTPs — with your detection and response as the system under test.

Duration
4–16 weeks
Team
3 named operators
From
€78,500
Critical escalation
4 hours
How it runs
01
Threat modelling — crown-jewel selection, actor choice from CTI, rules of engagement and deconfliction contacts.
02
Initial access — phishing, exposed services or physical entry; custom C2 and implants that appear in no vendor signature set.
03
Objectives — persistence, privilege escalation and lateral movement to the agreed objectives — AD CS, Kerberos, cloud IAM, CI pipelines.
04
Replay and debrief — every action mapped to ATT&CK technique IDs; joint replay with your blue team; board and engineering readouts.
What you get
  • Attack narrative with timestamps, technique IDs and evidence hashes
  • Detection-gap register: what should have fired, and why it did not
  • Findings with CWE, CVSS 3.1 vector and working reproduction
  • Purple-team replay session and detection-as-code recommendations
  • One retest round within 90 days and an attestation certificate
Methodology
MITRE ATT&CK v17
TIBER-EU · CBEST compatible
PTES · OWASP WSTG
CREST-accredited personnel
Typical scope
Internet-facing estate, identity infrastructure (AD, AD CS, Entra ID), workstations and servers, cloud tenants, CI/CD, physical premises where authorised.
Not included
Denial of service. Destructive actions on production data. Third-party SaaS you do not own. Vulnerability scanning delivered as findings.
Each is a separate engagement — they need separate authorisation.
A time-boxed assessment establishes what was found within the agreed scope and window. It does not certify the absence of vulnerabilities, and we will never say that it does.
securepeak.com
engagements@securepeak.com