We test not just code and infrastructure — people and processes too. Social engineering, phishing, physical access, privilege escalation. Like a real attacker, only with a report.
Different goals, different approach
| Parameter | Pentest | Red Team |
|---|---|---|
| Goal | Find vulnerabilities in the system | Penetrate the company by any means |
| Vectors | Technical | Technical + people + physical |
| Does IT know? | Yes | No (only management) |
| Duration | 3–14 days | 21+ days |
| Result | List of vulnerabilities | Realistic compromise scenario |
Every vector of a real attack
Gathering information about the company, employees, infrastructure. Building a threat model and an operation plan.
Vishing, pretexting, manipulation of employees. Testing how resilient the staff is to manipulation.
Targeted phishing campaigns aimed at specific employees. Credential harvesting, implant deployment.
Office penetration, bypassing access control, planting devices, badge cloning.
After initial access — moving across the network, privilege escalation, reaching domain admin.
Mimicking a real attacker: persistence in the environment, Command & Control infrastructure.
A structured operation with a clear result
We agree on boundaries: what's allowed, what's not. NDA plus written authorization. We define operation goals (get domain admin, reach specific data).
Gathering information about the company, employees, infrastructure. Building an attacker model and an operation plan.
We use all agreed vectors: phishing, social engineering, physical access, perimeter vulnerabilities.
Lateral movement, privilege escalation, achieving operation goals. Everything is logged with a timeline.
A detailed report with attack timeline, techniques used (MITRE ATT&CK), and recommendations. A live debrief with the security team.
Red Team — for those who want to know the real security posture, not just close CVEs. Write to us — we'll discuss the task.