Red Teaming Operations

Red Teaming Operations

Red teaming operations are authorized attacks reflecting real capabilities of adversaries. Red teaming covers various aspects such as network, social engineering and physical security.

Get a quote

Why REDTEAM.PL services?

Clients choose REDTEAM.PL primarily because of our recognizable consultants and their documented track record. We have worked in cybersecurity since the late 1990s – over 25 years. We hold dozens of acknowledgements for responsibly disclosed vulnerabilities in widely used software and over 50 written client references. Adam Ziaja of REDTEAM.PL co-authored handbooks for the European Union Agency for Cybersecurity (ENISA) and wrote a book published by Polish Scientific Publishers PWN, while our research has been cited by the SANS Institute, Forbes magazine, CERT Polska and CERT Orange. All services are performed exclusively by experienced consultants – we never staff engagements with people lacking years of hands-on practice. We have also held Polish court-appointed expert witness status for well over a decade.

See the Competencies of Our Team

Our team identified and responsibly disclosed multiple critical and high rated vulnerabilities in widely used global products. Acknowledgements for reported vulnerabilities have come from Adobe, Apple, BlackBerry, Deutsche Telekom, eBay, GitLab, Google, Harvard University, LastPass, Microsoft, Netflix, Nokia, Oracle, SoundCloud, VMware, Yahoo, Yandex and Zynga, among others:

Acknowledgement from Microsoft for REDTEAM.PL vulnerability reports
Acknowledgement from Netflix for REDTEAM.PL vulnerability reports
Acknowledgement from Mozilla for REDTEAM.PL vulnerability reports
Acknowledgement from Adobe for REDTEAM.PL vulnerability reports
Acknowledgement from Google for REDTEAM.PL vulnerability reports
Acknowledgement from Apple for REDTEAM.PL vulnerability reports

APT attack simulation

Bringing together broad cybersecurity expertise, we are able to carry out profiled tests and simulated APT (Advanced Persistent Threat) attacks, that is CPH (Cyber-Physical-Human) red teaming. Red teaming operations are meant to reflect realistic hacking scenarios that could threaten the given organisation. Red team exercises are used to assess the current security posture of the whole organisation, the awareness of office staff, and the speed and quality of response from security teams – a SOC (Security Operations Center) or a CERT (Computer Emergency Response Team), also known as a CSIRT (Computer Security Incident Response Team).

Simulation of internal attacks

The starting assumption is that the defences have already been breached (assumed breach) and the attacker holds access to the organisation’s internal infrastructure. Simulating the threat from inside the network may, for example, involve attempts to escalate privileges on the organisation’s LAN by simulating an insider threat or a disloyal employee. The objective of such an internal attack may be to take over the Windows domain controller (AD, Active Directory), that is to obtain system administrator privileges on it. The exercise can also serve to test the competence and detection capability of the Security Operations Center (SOC) team.

Diagram of a REDTEAM.PL red teaming operation

Why us? Knowledge and experience

We deliver red teaming for well-known international organisations and have many years of experience in penetration testing, backed by the most widely recognised certification in attack simulation, OSCP (Offensive Security Certified Professional), which each of us has held for several years. We also have equally extensive experience in digital forensics and incident response and in threat hunting. Combining expert knowledge of attack and of defence gives us an unusual perspective: we know how hacking attacks are carried out, and we also know how incidents are handled. On top of that we have repeatedly found 0-day vulnerabilities in widely used software – previously unknown flaws for which no security patch yet existed. It is these competences together that let us deliver attack simulations reflecting what real attackers can actually do.

“Cybersecurity researchers at Warsaw-based RED TEAM discovered a flaw in the way Safari handles sharing actions. Click in Safari to share a cute kitten picture with a friend and you could unknowingly pass critical information about your system to an attacker”

A Bug In Apple’s Safari Browser Could Let Hackers Steal Your Files
Forbes Magazine

Red teaming

Examples of red teaming exercises we can offer cover network security (much as penetration testing does), social engineering and the physical security of the organisation:

  • social engineering attacks, principally phishing campaigns against office staff, which can also be concluded with training for non-technical employees;
  • simulations of network-based hacking attacks, both external (internet) and internal (LAN), the latter simulating the case where an attacker has obtained access to the organisation’s internal network;
  • simulations of a disloyal employee acting against the company, with access to a computer in a Windows domain or simply access to the local network;
  • broad-spectrum attacks: attempts at physical access to the organisation’s IT resources, both through social engineering and by identifying weaknesses in physical security. The goal of such a red teaming operation may be to plant an unauthorised device on the internal network, whose purpose is to allow unauthorised people to reach that network from outside.

Red teaming versus penetration testing

Red teaming differs from penetration testing in several respects:

  • it is not confined to a rigorous scope (to a single web application, for example),
  • it is not about finding as many vulnerabilities as possible, but about finding the most effective way through the defences,
  • it is not limited to technology – it covers the human factor (social engineering) and physical security as well,
  • it cannot be too noisy, so as to avoid detection by the blue team, for instance the SOC.

Where a traditional penetration test is better at producing a precise list of weak points and improvements to make, red teaming is a more accurate measure of an organisation’s readiness for attack.

Social engineering testing and phishing

We carry out authorised social engineering attacks, most often a phishing campaign against the organisation’s employees (staff awareness testing). The objective is agreed individually with the client and may be, for example, harvesting credentials to corporate resources followed by attempts to escalate into the internal network and simulate a real attack – such as gaining access to important data – or simply gathering statistics on how effective the campaign was.

Another kind of social engineering attack is standing up a rogue AP (rogue wireless Access Point) made to look deceptively like the organisation’s Wi-Fi. The scenario here may involve attempts to obtain confidential information by intercepting network traffic or modifying it – substituting executable files downloaded by the victim, for instance.

Advanced attack simulations

We carry out advanced simulations of the attacks organisations face today. Scenarios we have delivered include successful attacks on NAC (Network Access Control) 802.1X and an internal domain name collision:

The main benefits of red teaming

Our experts simulate the actions of a real attacker, exploiting any weakness in the organisation – networks, applications, people and the physical security of premises.

A red teaming security assessment has a far broader scope than a traditional pentest, and the red teamer works to compromise the target while remaining undetected.

A red team assessment is above all:

  • the most advanced form of security testing,
  • a simulation of realistic threats,
  • verification of the organisation’s defences,
  • an assessment of the ability to detect, protect and respond to incidents.

Attacks on SCADA systems

At the invitation of the Singapore Ministry of Defence we took part as an offensive team (red team) in the international exercise Critical Infrastructure Security Showdown 2020 (CISS2020-OL) organised by the Singapore University of Technology and Design (iTrust SUTD). The objective was to attack critical infrastructure in the form of a water treatment plant (SWaT). During the exercise we successfully broke through the IT defences and took direct control of the SCADA HMI system.

DLP security testing

As part of a red teaming engagement, the DLP (Data Leak Prevention) systems in place at the organisation can also be put to the test. We verify whether information can be sent out of the corporate network unnoticed. We use advanced data exfiltration techniques, exactly as attackers moving important data out of an organisation do. Such data may include personal data, sensitive data, trade secrets or the company’s business plans.

Threat-Led Penetration Testing (TLPT)

We deliver threat-led penetration testing (TLPT), working from the question »what could an attacker do« and exposing genuine weaknesses rather than executing predetermined scenarios that do not follow from knowledge of the tested environment. This approach reflects the capabilities a real attacker would have, and makes the security testing both targeted and realistic.

Network attacks

Network attacks can form part of a red teaming operation, and here the main objective is access to the organisation’s important resources. This is usually an escalation step following social engineering attacks, or follows access to the internal network obtained by physically connecting to the organisation’s infrastructure.

Physical security

The main objective of physical security testing within red teaming is to obtain access to the organisation’s internal network (building hacking). The means to that end may be social engineering – persuading employees to take actions that should not happen, such as plugging a storage device into a company computer.

Explore Our Offer

We deliver advanced technical consulting services covering multiple aspects of cybersecurity from red team to blue team. Thanks to a diverse experience in IT security we are able to look at a wider perspective during engagements. Our abilities come from many years of work experience in cybersecurity and are confirmed with certificates, publications, advisories and references from our customers.

REDTEAM.PL client references