Service data sheet · 02 of 05Offensive security · SP-SVC-02
Objective-Based Red Team Operation
A multi-phase operation against your crown-jewel assets, emulating a named threat actor with their documented TTPs — with your detection and response as the system under test.
Critical escalation
4 hours
How it runs
01
Threat modelling — crown-jewel selection, actor choice from CTI, rules of engagement and deconfliction contacts.
02
Initial access — phishing, exposed services or physical entry; custom C2 and implants that appear in no vendor signature set.
03
Objectives — persistence, privilege escalation and lateral movement to the agreed objectives — AD CS, Kerberos, cloud IAM, CI pipelines.
04
Replay and debrief — every action mapped to ATT&CK technique IDs; joint replay with your blue team; board and engineering readouts.
What you get
- Attack narrative with timestamps, technique IDs and evidence hashes
- Detection-gap register: what should have fired, and why it did not
- Findings with CWE, CVSS 3.1 vector and working reproduction
- Purple-team replay session and detection-as-code recommendations
- One retest round within 90 days and an attestation certificate
Methodology
MITRE ATT&CK v17
TIBER-EU · CBEST compatible
PTES · OWASP WSTG
CREST-accredited personnel
Typical scope
Internet-facing estate, identity infrastructure (AD, AD CS, Entra ID), workstations and servers, cloud tenants, CI/CD, physical premises where authorised.
Not included
Denial of service. Destructive actions on production data. Third-party SaaS you do not own. Vulnerability scanning delivered as findings.
Each is a separate engagement — they need separate authorisation.
A time-boxed assessment establishes what was found within the agreed scope and window. It does not certify the absence of vulnerabilities, and we will never say that it does.
securepeak.com
engagements@securepeak.com