Practice 02
Offensive Security
Objective-based operations against crown-jewel assets, emulating named threat actors with their documented TTPs. Detection and response are the system under test; the report maps every action to ATT&CK technique IDs and every finding to a CWE and CVSS 3.1 vector.
Engagement parameters
FrameworkMITRE ATT&CK v17 · TIBER-EU · CBEST · PTESDuration4–16 weeks · multi-phaseToolingCustom C2 · in-house implants · no commercial scannersDeliverablesAttack narrative · TTP matrix · detection gap register · retest
Data sheet · A4 · SP-SVC-02Open PDF sheet
Operators · identities withheld
Named to clients under NDA at scoping100%
Initial access success rate
< 72h
Median time to domain admin
200+
CVEs disclosed
Zero
Operational security failures
Operators · identities withheld
Named to clients under NDA at scopingReferences
