PUBLIC · securepeak.comAS216096 · L-717869-S
SecurePeak
Practice 02

Offensive Security

Objective-based operations against crown-jewel assets, emulating named threat actors with their documented TTPs. Detection and response are the system under test; the report maps every action to ATT&CK technique IDs and every finding to a CWE and CVSS 3.1 vector.

Engagement parameters
FrameworkMITRE ATT&CK v17 · TIBER-EU · CBEST · PTESDuration4–16 weeks · multi-phaseToolingCustom C2 · in-house implants · no commercial scannersDeliverablesAttack narrative · TTP matrix · detection gap register · retest
Data sheet · A4 · SP-SVC-02Open PDF sheet
Red team · SP-SVC-02.01

Objective-based operations

Crown-jewel modelling, custom attack paths, multi-phase operations over 4–16 weeks. Initial access via phishing, exposed services or physical entry; persistence, privilege escalation and lateral movement with in-house implants that do not appear in any vendor signature set.

Adversary emulation · SP-SVC-02.02

Named-actor TTP emulation

APT28 identity-infrastructure tradecraft, Scattered Spider help-desk social engineering, Volt Typhoon living-off-the-land in OT-adjacent networks — executed from CTI, with your blue team watching or not. TIBER-EU and CBEST compatible.

Research · SP-SVC-02.03

Vulnerability research & exploit development

Memory-safety and logic bugs in VPN concentrators, identity providers, HSM firmware and CI runners. 200+ CVEs, each with a working PoC, CWE and CVSS vector, disclosed on the 90-day clock. Exploits are written for the report, then destroyed.

Identity · SP-SVC-02.04

Active Directory & identity assessment

AD CS abuse (ESC1–ESC16), Kerberos delegation and relay chains, Entra ID token and consent abuse, AD FS trust attacks of the kind exploited in CVE-2026-56155. Median time to domain admin across engagements: under 72 hours.

Cloud & CI · SP-SVC-02.05

Cloud, Kubernetes & pipeline assessment

IAM privilege chains, IMDS and workload-identity abuse, container escape via Copy Fail-class kernel bugs (CVE-2026-31431), poisoned pipeline execution and runner takeover. Findings mapped to the CIS benchmark you are already measured against.

Reality check · SP-SVC-02.06

LLM-assisted operations: measured, not marketed

Isozaki et al. found neither Llama 3.1-405B nor GPT-4o completed a single end-to-end penetration test, even with human assistance. 2026 has shown frontier models accelerate bug discovery — Firefox shipped 61 and 76 AI-assisted patches in February and March — but not exploitation. We use models for triage and variant analysis, and operators for everything that touches your network.

Operators · identities withheld
Named to clients under NDA at scoping
OP-03
Principal · vulnerability research
Name withheld · active CVD embargoes
Firmware
Browser
HSM
OP-07
Lead · detection engineering
Name withheld · client SOC placement
Streaming ML
Sigma
DFIR
OP-11
Senior · cryptographic engineering
Name withheld · government PKI programme
HSM ceremonies
PQC
Formal verification
OP-14
Network engineer · AS216096
Name withheld · NOC rotation
BGP
RPKI
Dark fibre
100%
Initial access success rate
< 72h
Median time to domain admin
200+
CVEs disclosed
Zero
Operational security failures
Operators · identities withheld
Named to clients under NDA at scoping
OP-03
Principal · vulnerability research
Name withheld · active CVD embargoes
Firmware
Browser
HSM
OP-07
Lead · detection engineering
Name withheld · client SOC placement
Streaming ML
Sigma
DFIR
OP-11
Senior · cryptographic engineering
Name withheld · government PKI programme
HSM ceremonies
PQC
Formal verification
OP-14
Network engineer · AS216096
Name withheld · NOC rotation
BGP
RPKI
Dark fibre
References

What this practice is currently working against.

Papers and public CVEs · updated Sep 2026
ReferenceFinding / paperSource
CVE-2026-31431"Copy Fail" — Linux page-cache privilege escalation; 13+ public exploits, breaks rootless containersLinux kernel · Apr 2026
CVE-2026-56155AD FS zero-day exploited in the wild; CISA KEV deadline 28 Jul 2026Microsoft · Jul 2026
CVE-2026-49164Heap overflow in AD DS — unauthenticated RCE against domain controllersMicrosoft · Jul 2026
CVE-2026-33017Code-injection RCE in Langflow agentic platform, exploited in the wildLangflow · Mar 2026
Isozaki et al.Towards Automated Penetration Testing — zero end-to-end completions by LLM agentsarXiv · 2024
Deng et al.PentestGPT: an LLM-empowered automatic penetration testing toolUSENIX Security · 2024
Next: Binary & Supply Chain Security