Contact

Red Teaming

Cyber security for complex IT and OT environments

Senior specialists, supported by AI

01
Scoping
Objectives and rules of engagement
02
Reconnaissance
Gather information
03
Initial access
Establish a foothold
04
Lateral movement
Escalate privileges
05
Objective reached
Reach crown jewels
06
Debrief
Findings and improvements

From initial access to mission objective

Red teaming examines whether a capable adversary can achieve a defined objective within the organisation. The exercise does not focus on isolated vulnerabilities. It follows complete attack paths from reconnaissance and initial access to privilege escalation, lateral movement and access to critical systems, data or operational processes.

Technology, people, procedures, detection and response are assessed as one connected defence. The red team adapts its methods as the operation progresses and uses realistic attacker techniques (TTPs) to bypass controls, maintain access and move towards the agreed objective. The exercise remains governed by predefined rules of engagement, safety boundaries and escalation procedures.

Scenarios are based on the organisation’s threat profile, critical assets and operational context. Activities are mapped to MITRE ATT&CK and can include technical intrusion, social engineering and, where relevant, physical access scenarios conducted in close cooperation with Triangular Group Insights. Threat-led exercises can also be aligned with TLPT, TIBER-EU and DORA requirements where applicable.

The outcome is a verified attack narrative that shows which controls stopped the operation, which signals were detected and where the attacker remained unnoticed. Technical teams receive the attack path, observed detection gaps and concrete improvement actions. Management receives a factual assessment of operational resilience and the decisions required to strengthen it.

DeepBlue is a member of Cyberveilig Nederland

Validate complete attack paths

A red team exercise determines which attack paths remain viable against the organisation’s current defences. The operation tests more than technical controls. It also examines detection, escalation, decision-making and coordination between the SOC, IT, security teams and management.

Each exercise starts with a threat scenario based on the sector, critical assets and expected adversary behaviour. The red team progresses from reconnaissance and initial access to privilege escalation, lateral movement and the agreed mission objective. The operation continues until the objective is reached, the activity is detected and contained, or a predefined stop condition applies.

MITRE ATT&CK provides the structure for recording techniques, observed controls and detection opportunities. The analysis distinguishes between controls that prevented progress, controls that generated useful telemetry and controls that failed without detection. This creates a technical account of how the defence performed across the full attack path.

For organisations in financial services, government, defence, energy, logistics and critical infrastructure, red teaming provides evidence of operational resilience under realistic conditions. Where relevant, the exercise can support TLPT, TIBER-EU, DORA and NIS2 programmes. The result provides direct input for detection engineering, incident response procedures, security architecture and executive decision-making.

ATT&CK · technique card
T1003.001
Credential Access · TA0006
LSASS Memory
↳ sub-techniek van T1003 OS Credential Dumping
Aanvallers dumpen het geheugen van het LSASS-proces om wachtwoorden, NTLM-hashes en Kerberos-tickets te onttrekken. Vaak via comsvcs.dll, procdump of directe API-calls, gevolgd door pass-the-hash of offline kraken.
Platforms
Windows
Data sources
Process access · Sysmon EID 10 · cmd-line
Mitigations
4 actief · Credential Guard, RunAsPPL, LSA-protection, EDR
71% engagement-rate
#1 credential access

Controlled operations with defined objectives

A red team exercise must remain realistic without introducing unmanaged operational risk. Objectives, target assets, safety boundaries, stop conditions, escalation procedures and permitted techniques are therefore documented before the operation begins. The resulting rules of engagement define the freedom available to the red team and the conditions under which activity must be paused or disclosed.

The operation is adapted to the organisation’s maturity, threat profile and critical processes. A limited exercise may focus on one attack path or detection question. A broader engagement can combine digital intrusion, identity compromise, social engineering, physical access and long-term persistence. The level of secrecy is also defined in advance, including which stakeholders are informed and which internal teams remain unaware.

Learning value depends on preserving realistic pressure. The red team therefore operates independently within the agreed mandate and adjusts its techniques as controls, defenders and operational conditions change. The objective is not unrestricted compromise. It is to produce reliable evidence of how prevention, detection, escalation and response perform against a capable and persistent adversary.

Red Teaming

Adversary emulation

The operation is based on a defined threat actor, objective and campaign profile. Techniques are selected from relevant intelligence and mapped to MITRE ATT&CK. The red team adapts its tooling, infrastructure and tradecraft to test whether current defences can disrupt the simulated adversary before the mission objective is reached.

Red Teaming

Social
engineering

Phishing, pretexting, telephone approaches and other human-focused techniques can be integrated into the attack path. The assessment examines whether identities, procedures and escalation routes can be manipulated to obtain access or information. The focus remains on control effectiveness, not on judging individual employees.

Red Teaming

Physical
access

Digital attack paths can be combined with physical access scenarios in close cooperation with Triangular Group Insights. Activities may include pretexting, tailgating, unauthorised entry and placement of controlled equipment. Physical access is treated as part of the wider attack path rather than as an isolated security test.

Red Teaming

Detection validation

Specific attack techniques can be executed to determine whether the SOC, EDR, SIEM and other detection controls generate useful telemetry and actionable alerts. The assessment records which activity was detected, how quickly it was investigated and whether escalation and response procedures functioned as intended. This provides direct input for detection engineering and blue team improvement.

Frequently asked questions about Red Teaming

When should an organisation conduct a red team exercise?

A red team exercise is most relevant when baseline security controls are already in place and the organisation needs to understand how they perform against a coordinated attack. It is commonly used before major transformations, after significant security investments, during regulatory resilience programmes or when leadership needs evidence of actual defensive capability.

What is the difference between red teaming and penetration testing?

A penetration test focuses on identifying and validating vulnerabilities within a defined technical scope. Red teaming assesses whether a capable adversary can achieve a broader objective by combining technical intrusion, identity abuse, social engineering and other attack methods. It also evaluates detection, escalation and response across the organisation.

How long does a red team exercise take?

Duration depends on the objective, scope, level of secrecy and number of attack paths involved. A focused exercise may take several weeks. Broader operations involving multiple environments, social engineering or physical access can take longer. Preparation, execution, analysis and debriefing are all part of the engagement.

Who should know that a red team exercise is taking place?

The informed group is kept as small as operationally possible. This is usually limited to a control group with authority to manage safety, escalation and legal boundaries. Security operations, IT teams and other defenders may remain unaware when the objective is to test detection and response under realistic conditions.

Can red teaming be performed in production environments?

Yes, but only under strict rules of engagement. Critical systems, prohibited techniques, stop conditions and escalation procedures are defined before the operation starts. High-risk activities can be simulated, restricted or coordinated separately when availability, safety or business continuity could be affected.

What happens after a red team exercise?

The operation concludes with technical analysis and a structured debrief. The organisation receives the reconstructed attack path, evidence of successful and blocked techniques, observed detection gaps and concrete improvement actions. A purple team session can then be used to translate the findings into improved detections, playbooks and security controls.

Direct access to senior cybersecurity expertise

Discuss a security requirement, active risk or complex IT or OT environment with one of our senior specialists. The initial conversation focuses on the technical context, operational constraints and the most appropriate course of action.

  • No mailing lists or automated sales follow-up
  • Information is handled confidentially

Urgent assistance required?

Call +31 (0) 70 290 6 290
or email  info@deepbluesecurity.nl

Thank you. The message has been received and will be reviewed by one of our specialists.
The form could not be submitted. Please try again or contact info@deepbluesecurity.nl.

You are in good company

Latest technical insights

Technical analysis, field observations and sector-specific perspectives across IT, OT and cyber resilience.