Service

Red Team
realistic
attack simulation

We test not just code and infrastructure — people and processes too. Social engineering, phishing, physical access, privilege escalation. Like a real attacker, only with a report.

Discuss the operation Pentest →
Red Team Social Engineering Phishing Physical Access Privilege Escalation APT Simulation NDA
21+
days minimum
3
vectors: technical,
people, physical
14+
years of experience
100%
NDA

Red Team vs Pentest

Different goals, different approach

Parameter Pentest Red Team
Goal Find vulnerabilities in the system Penetrate the company by any means
Vectors Technical Technical + people + physical
Does IT know? Yes No (only management)
Duration 3–14 days 21+ days
Result List of vulnerabilities Realistic compromise scenario

What's included in Red Team

Every vector of a real attack

OSINT

Reconnaissance

Gathering information about the company, employees, infrastructure. Building a threat model and an operation plan.

Social

Social engineering

Vishing, pretexting, manipulation of employees. Testing how resilient the staff is to manipulation.

Phishing

Phishing and spear-phishing

Targeted phishing campaigns aimed at specific employees. Credential harvesting, implant deployment.

Physical

Physical access

Office penetration, bypassing access control, planting devices, badge cloning.

Escalation

Escalation and lateral movement

After initial access — moving across the network, privilege escalation, reaching domain admin.

C2

Persistence and C2

Mimicking a real attacker: persistence in the environment, Command & Control infrastructure.

How we work

A structured operation with a clear result

01

Rules of Engagement

We agree on boundaries: what's allowed, what's not. NDA plus written authorization. We define operation goals (get domain admin, reach specific data).

02

Reconnaissance (OSINT)

Gathering information about the company, employees, infrastructure. Building an attacker model and an operation plan.

03

Initial access

We use all agreed vectors: phishing, social engineering, physical access, perimeter vulnerabilities.

04

Attack development

Lateral movement, privilege escalation, achieving operation goals. Everything is logged with a timeline.

05

Report and debrief

A detailed report with attack timeline, techniques used (MITRE ATT&CK), and recommendations. A live debrief with the security team.

FAQ

How is Red Team different from a pentest?
A pentest checks specific systems for vulnerabilities. Red Team simulates a realistic targeted attack using all available vectors — technical, social, physical. The goal is to check how realistically an attacker could penetrate the company.
How long does an operation take?
Minimum 21 business days. A full Red Team for a mid-sized company — 4–8 weeks. Realistic timing depends on company size and depth of the operation.
Who knows about the Red Team?
Only a limited circle of management (usually CEO, CISO). IT and security staff are not warned — otherwise the result would not be objective.
Do you actually break into systems?
Within the agreed Rules of Engagement — yes. We get real access and demonstrate the ability to achieve attack goals. No destructive impact on data or systems.

Ready to really test your defenses?

Red Team — for those who want to know the real security posture, not just close CVEs. Write to us — we'll discuss the task.

Telegram: @FzControl OSINT →