AI-generated image

Red Team · Adversary simulation

Red Team services: adversary simulation for companies

A Hard2bit Red Team exercise simulates a real adversary against your organisation —with agreed objectives, stealth and techniques documented in MITRE ATT&CK— to measure what a pentest does not: whether your SOC detects the intrusion, how long it takes to respond and how far an attacker would get before anyone stops them.

Typical duration
4–12 weeks
Reference framework
MITRE ATT&CK
Financial sector
TLPT · TIBER-EU

No obligation · Confidential from the first conversation.

Definition

What is a Red Team exercise?

A Red Team exercise is a targeted, covert attack simulation in which an offensive team emulates the tactics, techniques and procedures of a real adversary to try to reach agreed business objectives, without the defence team being warned.

Unlike a technical audit, it does not aim to list every vulnerability: it only needs the ones required to move forward. What it assesses is the whole —people, processes and technology— against an attacker with time, method and motivation. That is why it is also known as adversary simulation or adversary emulation.

The techniques we use are catalogued against MITRE ATT&CK, which makes it possible to compare the outcome with your SOC's detection coverage and repeat the measurement over time.

The three questions it answers

  1. Whether anyone sees it

    Which attacker actions raise an alert in your SIEM, EDR or NDR, and which go by without leaving a useful trace.

  2. How long the reaction takes

    The real time between the first signal and containment: triage, escalation, decision and playbook execution.

  3. How far an attacker gets

    Which business objectives are reached —data, payment systems, Active Directory— before someone stops the intrusion.

Fit

When a Red Team makes sense, and when it does not yet

A Red Team pays off when there is a defence to put to the test. If that is not your case, we would rather say so and propose the step that genuinely moves you forward.

It fits if…

  • You run a SOC or MDR, in-house or managed, and want evidence of whether it detects a targeted attack.
  • You have been through several pentesting cycles and fixed the findings: the next step is measuring response, not listing more vulnerabilities.
  • The board, senior management or a strategic customer asks for a realistic resilience test, not a compliance report.
  • You have deployed EDR or SIEM, or changed SOC provider, and need to validate the investment.
  • You have suffered an incident and want to confirm the improvements hold against the same type of adversary.
  • You are a financial entity designated to perform TLPT under DORA.

Not yet, if…

  • There is no monitoring to measure

    Without a SOC, EDR or centralised logging the outcome is already known: nobody will detect anything. Starting with a managed SOC pays off more.

  • A pentest has never been done

    If basic vulnerabilities are still open, a pentest finds them sooner and with less effort.

  • There is no asset inventory or regular patching

    The Red Team will walk in through the obvious and the exercise will add little. First, vulnerability management.

  • The defence team cannot absorb the outcome

    If the Blue Team is very new, a collaborative Purple Team teaches more than a covert exercise.

Engagement types

Four ways to simulate an adversary

The engagement type depends on what you want to measure and how mature your defence is. In the scoping session we recommend one, and explain why.

Full-scope Red Team

8–12 weeks

A covert exercise from start to finish: from external reconnaissance to action on the agreed objectives, combining the digital vector with social engineering.

  • Known only to the control cell
  • Scenarios based on real actors targeting your sector
  • Measures detection and response end to end

Assumed breach

3–6 weeks

We start from an already compromised workstation or set of credentials. Effort goes where detection is hardest: privilege escalation, lateral movement and access to critical assets.

  • Highest return per week of exercise
  • Ideal as a first Red Team
  • Reproduces the aftermath of a successful phishing attack

Purple Team

1–3 weeks

Attack and defence work together, technique by technique: we execute each TTP, check whether it is detected and tune rules and playbooks on the spot.

  • Measurable improvement in ATT&CK coverage
  • Direct knowledge transfer to the SOC team
  • Natural follow-up to a Red Team

TLPT under DORA · TIBER-EU

Active phase ≥ 12 weeks

Threat-led penetration testing of critical functions on live production systems, with the roles, phases and documentation required by DORA and the TIBER-EU framework.

  • We act as the external Red Team provider
  • Entity-specific threat intelligence
  • Closure with replay, Purple Team and remediation plan

Methodology

How a Red Team exercise unfolds

Six phases, from defining objectives to reconstructing the attack with your team. Each maps to MITRE ATT&CK tactics, so the outcome is comparable and repeatable.

  1. 01 · Scope, objectives and rules of engagement

    Together we define the business objectives the exercise should try to reach, what is out of bounds, who sits in the control cell and how any contingency is handled. Everything is signed off before we start.

    • Rules of engagement
    • Control cell
    • Formal authorisation
  2. 02 · Threat intelligence and scenario design

    We identify which actors have a demonstrated interest in your sector and which techniques they use. That produces credible scenarios, not a generic catalogue of attacks.

    • Threat Intelligence
    • Adversary profile
    • ATT&CK TTPs
  3. 03 · Reconnaissance and preparation

    OSINT on exposed assets, people and suppliers; leaked credentials; set-up of command-and-control infrastructure and social engineering pretexts.

    • Reconnaissance
    • Resource Development
  4. 04 · Initial access

    We look for a way in just as the emulated adversary would: spear phishing, vishing, exposed services or valid credentials. Always within the agreed rules.

    • Initial Access
    • Execution
  5. 05 · Stealthy post-exploitation

    Privilege escalation, lateral movement and persistence using our own tooling and implants, adapted to evade the controls in your environment. This is where the Blue Team is really put to the test.

    • Privilege Escalation
    • Defense Evasion
    • Lateral Movement
    • Persistence
  6. 06 · Action on objectives and closure

    We demonstrate impact in a controlled way —without damaging or extracting real information—, remove every artefact and reconstruct the attack with your defence team.

    • Collection
    • Simulated exfiltration
    • Replay

Realistic for the attacker, safe for the business

A Red Team operates in production, and that demands strict safeguards. These are the ones we apply in every exercise and write into the rules of engagement.

  • No destructive actions and no service degradation: impact is demonstrated, not caused.
  • No real information is extracted. Exfiltration is tested with marked files created for the exercise.
  • A control cell with a direct 24×7 channel and the authority to pause or stop the exercise at any time.
  • Deconfliction with real incidents: if the SOC opens a case, the control cell confirms within minutes whether it is us.
  • An inventory of every artefact deployed, with verified removal at closure.
  • Evidence and findings handled under an ISMS certified to ISO 27001 and Spain's ENS, HIGH category.

Outcomes

What we measure in a Red Team exercise

The value of the exercise lies in turning a simulated attack into indicators your SOC, your CISO and your management can track over time.

Metric Question it answers What it is used for
Time to first detection (MTTD) How long does it take someone to see the intrusion? Baseline for tuning SIEM/EDR use cases and thresholds.
Time to containment (MTTR) How long between the alert and evicting the attacker? Measures triage, escalation and playbooks, not just technology.
Detection coverage by ATT&CK tactic Which attack stages are visible and which are blind spots? Heat map that prioritises where to invest in telemetry.
Objectives achieved How far does an adversary with this capability get? Translates technical risk into business impact for management.
Quality of escalation and communication Does information reach decision-makers on time and complete? Improves the response plan and coordination with third parties.

Deliverables

What you receive at the end

Executive report

What was attempted, what was achieved and what it means for the business, in board-level language.

Attack narrative and timeline

Every step with date and time, the associated ATT&CK technique and evidence, ready to compare against SOC logs.

Detection matrix

For each technique executed: detected, logged without an alert, or invisible. The document the Blue Team uses most.

Prioritised technical findings

Weaknesses exploited, with root cause and a realistic remediation recommendation.

Replay session with the Blue Team

We reconstruct the exercise alongside your defence team: what they saw, what they missed and why.

Detection and response improvement plan

Use cases, rules, telemetry sources and playbook adjustments, ordered by impact.

After the exercise it is common to follow up with a Purple Team and Threat Hunting on the techniques used, to confirm the new detections work and no persistence remains.

Financial sector

TLPT under DORA and TIBER-EU

The DORA Regulation (Articles 26 and 27) requires the financial entities designated by their competent authority to carry out, at least every three years, threat-led penetration testing (TLPT) on their critical or important functions, on live production systems.

Commission Delegated Regulation (EU) 2025/1190 sets out the methodology, aligned with the ECB's TIBER-EU framework, implemented in Spain as TIBER-ES. Hard2bit takes part in these exercises as an external Red Team provider.

Frequency
At least every 3 years, for designated entities.
Scope
Critical or important functions, on live production systems.
Roles
The entity's control team, threat intelligence provider and Red Team.
Active Red Team phase
At least 12 weeks.
Closure
Report, replay, mandatory Purple Team and remediation plan.
Testers
Specific requirements for external providers; limited use of internal testers.

Planning

How long a Red Team takes and what drives its cost

Indicative duration by engagement type

Purple Team
1–3 weeks
Assumed breach
3–6 weeks
Full-scope Red Team
8–12 weeks
TLPT under DORA
Active phase of at least 12 weeks, plus preparation and closure

Preparation —scope, threat intelligence and rules of engagement— and closure with report and replay come on top of these timeframes.

Factors that determine cost

  • Number and ambition of the agreed objectives.
  • Size and spread of the organisation: sites, subsidiaries, cloud environments.
  • Defence maturity: the better your SOC detects, the more effort staying stealthy requires.
  • Vectors in scope: digital only, or targeted social engineering as well.
  • Bespoke threat intelligence versus sector reference scenarios.
  • Regulatory and documentation requirements, such as those of a TLPT.
  • Purple Team or follow-up validation included in scope.
Request a fixed proposal

Comparison

Red Team versus pentesting, Purple Team and BAS

PentestingRed TeamPurple TeamBAS
Question it answersWhich vulnerabilities do I have?Do we detect and stop a real attack?How do we improve detection, technique by technique?Are my controls still working?
ScopeSpecific assetsThe organisation, objective-drivenSelected TTPsAutomated scenarios
StealthNot requiredEssentialNo: it is collaborativeNo
Does the Blue Team know?YesNo, only the control cellYes, it takes partYes
Typical duration1–3 weeks4–12 weeks1–3 weeksContinuous

Selection criteria, relative costs and use cases, in the full comparison: pentesting vs Red Team vs BAS.

Red Team frequently asked questions

What is the difference between a Red Team exercise and a pentest?
A pentest looks for as many vulnerabilities as possible in specific assets within a short time; stealth is not needed. A Red Team pursues agreed business objectives by simulating a real adversary, without warning the defence team, to measure whether the organisation detects and responds. We cover it in depth in our pentesting vs Red Team vs BAS comparison.
We are a mid-sized company with an outsourced SOC: does a Red Team make sense, or is it only for large corporations?
It makes sense whenever there is a detection capability to measure, whether your own or a provider's. For mid-sized companies an assumed-breach exercise usually fits best: in a few weeks it validates whether your SOC or MDR provider detects escalation and lateral movement. More in Red Team for mid-sized companies.
Can a Red Team exercise disrupt business operations?
The exercise is designed so that it does not. The rules of engagement rule out destructive actions and service degradation, impact is demonstrated rather than caused, and the control cell can pause or stop activity at any time through a direct 24×7 channel.
Who inside the company knows the exercise is taking place?
Only the control cell: a very small group —typically the CISO, a senior management sponsor and legal counsel— that authorises the exercise, knows the schedule and resolves contingencies. The SOC and the rest of the organisation are not told; otherwise the real response would not be measured.
How long does a Red Team exercise take and how much does it cost?
A Purple Team takes 1–3 weeks, an assumed breach 3–6 and a full-scope Red Team 8–12. Cost depends on the number of objectives, the size of the organisation, the maturity of its defence and the vectors in scope. After a no-obligation scoping session we deliver a fixed proposal.
Can a Red Team be used to validate our SOC or MDR provider?
It is the most common use. The report shows, technique by technique, what the SOC detected, what was logged without raising an alert and what went unnoticed, with detection and containment times. It is objective evidence to demand improvements from a provider or to justify investment. If you also use our managed SOC, the exercise is run by a separate team.
What is TLPT under DORA and which entities must perform it?
TLPT (Threat-Led Penetration Testing) is the threat-led test that Article 26 of the DORA Regulation requires, at least every three years, from the financial entities designated by their competent authority. It is carried out on critical functions in production and follows Commission Delegated Regulation (EU) 2025/1190 and the TIBER-EU framework. More detail in TLPT under DORA in Spain.
Are the scenarios based on real threats or on generic attacks?
On real threats. Scenarios are built from Threat Intelligence: we select actors with a demonstrated interest in your sector, replicate their techniques as documented in MITRE ATT&CK and set objectives that reflect what that adversary would try to achieve. In a TLPT this is mandatory; in any serious Red Team, essential.
What happens if the Blue Team detects the Red Team mid-exercise?
That is a good result and is documented as such. The control cell decides how to continue: let the SOC run the full response so it can be measured, or resume from a different point to keep assessing later stages. Either way, what triggered the detection and how long it took are recorded.
What do we receive at the end of the exercise?
An executive report, the full attack narrative and timeline, a detection matrix by ATT&CK technique, prioritised technical findings, a replay session with your Blue Team and a detection and response improvement plan ordered by impact.
After the Red Team, can you validate that the Blue Team has closed the gaps?
Yes. The usual follow-up is a Purple Team and Threat Hunting on the techniques used: we verify that the new detections fire, that playbooks are calibrated and that no persistence remains. The aim is a measurable operational improvement, not just a report.
Do you deliver Red Team services in Spain and across Europe?
Yes. The team works from Madrid and runs exercises for organisations across Spain, the rest of Europe and Latin America. Most of the work is remote by nature; scoping, replay and Purple Team sessions can be held on your premises.
Where does the Red Team sit within Hard2bit's services?
It belongs to the Pentesting and Red Team practice, alongside pentesting and social engineering. It is the most demanding tier: chosen when you want to measure detection and response, not only discover vulnerabilities.

Concepts from our cybersecurity glossary that connect directly with this service.

Find out whether your defence holds against a real adversary

In a 45-minute scoping session we define objectives, engagement type and rules of engagement, and deliver a fixed proposal.

Written by Adrián González · Reviewed by Thilina Manana, service owner

Last reviewed: