Red Teaming Operations
Red teaming operations are authorized attacks reflecting real capabilities of adversaries. Red teaming covers various aspects such as network, social engineering and physical security.
Get a quoteRed teaming operations are authorized attacks reflecting real capabilities of adversaries. Red teaming covers various aspects such as network, social engineering and physical security.
Get a quoteClients choose REDTEAM.PL primarily because of our recognizable consultants and their documented track record. We have worked in cybersecurity since the late 1990s – over 25 years. We hold dozens of acknowledgements for responsibly disclosed vulnerabilities in widely used software and over 50 written client references. Adam Ziaja of REDTEAM.PL co-authored handbooks for the European Union Agency for Cybersecurity (ENISA) and wrote a book published by Polish Scientific Publishers PWN, while our research has been cited by the SANS Institute, Forbes magazine, CERT Polska and CERT Orange. All services are performed exclusively by experienced consultants – we never staff engagements with people lacking years of hands-on practice. We have also held Polish court-appointed expert witness status for well over a decade.
Our team identified and responsibly disclosed multiple critical and high rated vulnerabilities in widely used global products. Acknowledgements for reported vulnerabilities have come from Adobe, Apple, BlackBerry, Deutsche Telekom, eBay, GitLab, Google, Harvard University, LastPass, Microsoft, Netflix, Nokia, Oracle, SoundCloud, VMware, Yahoo, Yandex and Zynga, among others:
Bringing together broad cybersecurity expertise, we are able to carry out profiled tests and simulated APT (Advanced Persistent Threat) attacks, that is CPH (Cyber-Physical-Human) red teaming. Red teaming operations are meant to reflect realistic hacking scenarios that could threaten the given organisation. Red team exercises are used to assess the current security posture of the whole organisation, the awareness of office staff, and the speed and quality of response from security teams – a SOC (Security Operations Center) or a CERT (Computer Emergency Response Team), also known as a CSIRT (Computer Security Incident Response Team).
The starting assumption is that the defences have already been breached (assumed breach) and the attacker holds access to the organisation’s internal infrastructure. Simulating the threat from inside the network may, for example, involve attempts to escalate privileges on the organisation’s LAN by simulating an insider threat or a disloyal employee. The objective of such an internal attack may be to take over the Windows domain controller (AD, Active Directory), that is to obtain system administrator privileges on it. The exercise can also serve to test the competence and detection capability of the Security Operations Center (SOC) team.
We deliver red teaming for well-known international organisations and have many years of experience in penetration testing, backed by the most widely recognised certification in attack simulation, OSCP (Offensive Security Certified Professional), which each of us has held for several years. We also have equally extensive experience in digital forensics and incident response and in threat hunting. Combining expert knowledge of attack and of defence gives us an unusual perspective: we know how hacking attacks are carried out, and we also know how incidents are handled. On top of that we have repeatedly found 0-day vulnerabilities in widely used software – previously unknown flaws for which no security patch yet existed. It is these competences together that let us deliver attack simulations reflecting what real attackers can actually do.
“Cybersecurity researchers at Warsaw-based RED TEAM discovered a flaw in the way Safari handles sharing actions. Click in Safari to share a cute kitten picture with a friend and you could unknowingly pass critical information about your system to an attacker”
A Bug In Apple’s Safari Browser Could Let Hackers Steal Your Files
— Forbes Magazine
Examples of red teaming exercises we can offer cover network security (much as penetration testing does), social engineering and the physical security of the organisation:
Red teaming differs from penetration testing in several respects:
Where a traditional penetration test is better at producing a precise list of weak points and improvements to make, red teaming is a more accurate measure of an organisation’s readiness for attack.
We carry out authorised social engineering attacks, most often a phishing campaign against the organisation’s employees (staff awareness testing). The objective is agreed individually with the client and may be, for example, harvesting credentials to corporate resources followed by attempts to escalate into the internal network and simulate a real attack – such as gaining access to important data – or simply gathering statistics on how effective the campaign was.
Another kind of social engineering attack is standing up a rogue AP (rogue wireless Access Point) made to look deceptively like the organisation’s Wi-Fi. The scenario here may involve attempts to obtain confidential information by intercepting network traffic or modifying it – substituting executable files downloaded by the victim, for instance.
We carry out advanced simulations of the attacks organisations face today. Scenarios we have delivered include successful attacks on NAC (Network Access Control) 802.1X and an internal domain name collision:
Our experts simulate the actions of a real attacker, exploiting any weakness in the organisation – networks, applications, people and the physical security of premises.
A red teaming security assessment has a far broader scope than a traditional pentest, and the red teamer works to compromise the target while remaining undetected.
A red team assessment is above all:
At the invitation of the Singapore Ministry of Defence we took part as an offensive team (red team) in the international exercise Critical Infrastructure Security Showdown 2020 (CISS2020-OL) organised by the Singapore University of Technology and Design (iTrust SUTD). The objective was to attack critical infrastructure in the form of a water treatment plant (SWaT). During the exercise we successfully broke through the IT defences and took direct control of the SCADA HMI system.
As part of a red teaming engagement, the DLP (Data Leak Prevention) systems in place at the organisation can also be put to the test. We verify whether information can be sent out of the corporate network unnoticed. We use advanced data exfiltration techniques, exactly as attackers moving important data out of an organisation do. Such data may include personal data, sensitive data, trade secrets or the company’s business plans.
We deliver threat-led penetration testing (TLPT), working from the question »what could an attacker do« and exposing genuine weaknesses rather than executing predetermined scenarios that do not follow from knowledge of the tested environment. This approach reflects the capabilities a real attacker would have, and makes the security testing both targeted and realistic.
Network attacks can form part of a red teaming operation, and here the main objective is access to the organisation’s important resources. This is usually an escalation step following social engineering attacks, or follows access to the internal network obtained by physically connecting to the organisation’s infrastructure.
The main objective of physical security testing within red teaming is to obtain access to the organisation’s internal network (building hacking). The means to that end may be social engineering – persuading employees to take actions that should not happen, such as plugging a storage device into a company computer.
We deliver advanced technical consulting services covering multiple aspects of cybersecurity from red team to blue team. Thanks to a diverse experience in IT security we are able to look at a wider perspective during engagements. Our abilities come from many years of work experience in cybersecurity and are confirmed with certificates, publications, advisories and references from our customers.
Security testing of IT/OT/IoT/SCADA. Verification of security for both infrastructure and applications including web, mobile and client-server.
Real-life attack simulations starting from technical aspects, social engineering to physical security. We perform Advanced Persistent Threat (APT) simulations.
Audits covering broad scope, including procedures, software architecture, cloud security, smart contracts audits, source code audits and vulnerability assessment.
Searching for active cyber threats, proactive digital forensics aimed for detecting attackers in the organisation. Service delivered as a form of constant monitoring and as a last line of SOC.
Criminal forensics: securing digital evidence, analysing traces of activity, digital forensics, log analysis, events, RAM analysis. Additionally secure data removal.
Smart contract security assessment. Security testing of decentralized Web3 applications, wallets, exchanges, trading platforms and infrastructure. On-chain attacks and funds flow analysis