Red Teaming - Realistic Attack Simulations
You never really know how good your defense is until someone attacks it. Our Red Team simulates a real, targeted attack and measures whether your people, processes, and technology detect and stop it. For the financial sector, we run threat-led tests (TLPT) based on the TIBER-EU framework, as required by DORA.
Advanced Persistent Threat
What is Red Teaming?
Red Teaming tests the detection and response capabilities of an entire organization. Instead of listing as many vulnerabilities as possible, a Red Team pursues a specific attack objective and emulates a real attacker who acts actively and tries to evade detection, comparable to an Advanced Persistent Threat (APT).
The approach originated in the military sector, where defense strategies were examined through realistic adversary simulations. Applied to cybersecurity, this means we take the attacker's perspective to test and specifically improve the effectiveness of your security measures under real-world conditions.
Levels of Abstraction
Red Teaming and Penetration Testing Compared
Whether a penetration test or a Red Team assessment is the right choice depends on the objective. A pentest uncovers as many vulnerabilities as possible within a defined scope. A Red Team instead pursues a realistic attack objective and, in doing so, tests the entire defense apparatus, including people and processes.
- Goal-Oriented Instead of Exhaustive
A Red Team does not look for every vulnerability, but for the path that reaches the defined objective. A pentest aims for the most complete coverage of a scope.
- Detection Is Tested Too
The Red Team operates as covertly as possible. Whether and when your Blue Team notices the attack is itself a key result. In a pentest, stealth is usually not an objective.
- People, Processes, and Physical Access
Beyond technology, this includes social engineering, physical access attempts, and process weaknesses. A classic pentest usually stays technical.
- Longer Duration and Preparation
Red Team operations go deep and require more time, more people, and thorough threat intelligence preparation.
Also called attack simulation
When Should Red Teaming Be Used?
An attack simulation realistically recreates a real attack and explicitly includes the human factor that conventional pentests leave out. All digital and analog processes of your IT security management are put to the test. This gives you reliable insights from prevention through detection to response, while also raising the awareness of your employees.
- Measurable Detection and Response Capability
You get reliable data on whether and how quickly your SOC notices and contains a real attack.
- Realistic Understanding of Risk
Instead of a list of theoretical findings, you see what an attacker can actually achieve in your environment.
- Remediation of Concrete Attack Vectors
We reveal the paths used and support their targeted closure, not just individual vulnerabilities.
- Insights Into Attack Methods
Your team learns real tactics, techniques, and procedures and can tune detections specifically to them.
- Testing the Response of Your Processes
Alerting, escalation, and incident response are tested under real-world conditions.
How a Red Team Assessment Works
A Red Team assessment follows a structured approach aligned with MITRE ATT&CK and TIBER-EU:
Threat Intelligence and Scoping
Together we define objectives, scope, and test windows and build a threat-based adversary profile for your industry.
Reconnaissance
Passive and active reconnaissance of your attack surface, employees, and exposed services.
Initial Access
Gaining a foothold via the most promising path, such as spear phishing, exposed services, or physical access.
Foothold and Command and Control
Establishing stable, as inconspicuous as possible access and a C2 connection.
Privilege Escalation and Lateral Movement
Expanding privileges and moving through the network toward the agreed objectives.
Objective and Exfiltration
A controlled demonstration of compromising your crown jewels, without causing real damage.
Purple Teaming and Reporting
Joint review with your Blue Team, a documented attack narrative, and prioritized measures.
From Phishing to Physical Access
Scenarios and Attack Vectors
A realistic attack uses every path that leads to the objective. We tailor the scenarios to your threat landscape and combine technical, human, and physical vectors, up to the assumed-breach approach, in which we assume an initial access has already happened and test the detection of the follow-on activity.
- Assumed Breach
We assume an existing foothold and test whether your SOC detects and stops the post-exploitation.
- External Perimeter
Attack from the outside via internet-exposed services, VPN gateways, and web applications.
- Social Engineering and Phishing
Targeted spear phishing and vishing campaigns against your employees as the most common initial access.
- Physical Access
Attempting to gain on-site access to buildings, workstations, or network sockets.
- Purple Teaming
On request, Red and Blue Team work together openly to build detections directly and retest them.
DORA, TIBER-EU, and NIS2
Red Teaming as Regulatory Proof of Effectiveness
Supervisors and regulators no longer only ask whether systems are patched, but whether an organization detects and stops an ongoing attack. That is exactly what Red Teaming demonstrates. For the financial sector, DORA (Regulation (EU) 2022/2554, applicable since 17 January 2025) makes threat-led testing mandatory: Articles 26 and 27 require significant financial entities to perform Threat-Led Penetration Testing (TLPT), methodologically based on the ECB's TIBER-EU framework and at least every three years. NIS2 requires, in Article 21, proof of the effectiveness of security measures. A Red Team assessment provides exactly this proof, even where no TLPT is mandated.
- DORA and TLPT for the Financial Sector
Articles 26 and 27 of DORA require significant financial entities to perform Threat-Led Penetration Testing. We conduct TLPT as a qualified, independent tester.
- TIBER-EU Framework
TIBER-EU is the European framework for Threat Intelligence-based Ethical Red Teaming. It structures TLPT from the threat intelligence phase through the red team phase to joint purple teaming with your Blue Team.
- NIS2: Proof of Effectiveness
NIS2 (Article 21) requires policies and procedures to assess the effectiveness of security measures. A Red Team assessment proves that detection and response actually work, even without mandatory TLPT.
- Evidence for Supervisors
BaFin and the ECB monitor compliance with DORA requirements. A documented Red Team assessment is the solid evidence that your defense works.
Which Tools and Techniques Are Used?
Our operations are aligned with the MITRE ATT&CK Framework, the common language for adversary tactics and techniques. Among the most important tools are AptSimulator, Atomic Red Team, and Caldera. In addition, we use Metasploit for exploits, Cobalt Strike for post-exploitation, BloodHound for Active Directory analysis, Burp Suite for web applications, and the Social-Engineer Toolkit for targeted social engineering attacks.
Where established tools are not enough, our specialists develop their own exploits during the assessment, up to previously unknown zero-day vulnerabilities. We publish responsibly disclosed findings as Security Advisories.
- AptSimulator
The Windows-based tool simulates typical traces and activities of advanced attackers (APT). It deliberately creates artifacts and system changes to test the detection and response capabilities of IT security teams. AptSimulator is particularly suitable for testing the effectiveness of forensic and monitoring solutions against known attack patterns.
- Atomic Red Team
The framework provides small, targeted tests ("atomic tests") that simulate individual tactics, techniques, and procedures (TTPs) from the MITRE ATT&CK Framework. Companies can use this to specifically check whether their security controls detect and defend against certain attack paths. Atomic Red Team allows for the customization of tests to industry-specific threats and supports regular, continuous reviews of their own defense measures.
- MITRE Caldera
The automated platform emulates attackers and supports manual Red-Team operations. Caldera is based on the MITRE ATT&CK Framework and allows orchestrating complex attack scenarios with various plugins and agents. The platform is suitable for automating Adversary Emulation, supporting Incident Response exercises, and visualizing attack paths.
- In-House Exploit and Zero-Day Development
Where off-the-shelf tools reach their limits, we do our own research and develop tailored exploits, up to new zero-day vulnerabilities. We document our responsibly disclosed findings publicly in our Security Advisories.
Outcome and Evidence
What You Receive
After the assessment, you receive more than a list of findings. We deliver a comprehensible attack narrative, a summary that management can understand, and a prioritized remediation plan. Critical findings are reported immediately during the test.
- Management Summary
An understandable classification of risk and impact, even without technical background.
- Documented Attack Narrative
The full path from initial access to objective, with evidence and reference to MITRE ATT&CK.
- Prioritized Measures
Concrete recommendations sorted by impact, instead of a mere list of findings.
- Free Retest
After remediation, in most cases we retest free of charge to confirm that your fixes actually close the attack paths used.
Range of Services for Cyber Security
Additional meaningful services within the scope of an IT security audit
- Penetration Test
Penetration tests are simulated attacks from external or internal sources to determine the security of web applications, apps, networks, and infrastructures and to reveal any vulnerabilities.
- Cloud Security
Due to the increasing complexity of cloud infrastructures, many services are incorrectly configured. We help you identify and eliminate misconfigurations and their effects.
- Phishing Simulation
A spear-phishing simulation is used to enhance the detection capabilities of your employees. We help you sensitize your staff, thereby strengthening the last line of defense.
- Static Code Analysis
Static code analysis, also known as source code analysis, is typically conducted as part of a code review and takes place during the implementation phase of a Security Development Lifecycle (SDL).
How Far Would a Real Attacker Get in Your Organization?
Find out before someone else does. Our BSI-certified experts simulate a real, targeted attack on your organization.
Frequently Asked Questions About Red Teaming
Red Teaming: Frequently Asked Questions
Answers to the questions clients ask us most often before a Red Team assessment.
- How Does Red Teaming Differ From a Penetration Test?
A pentest uncovers as many vulnerabilities as possible within a defined scope. A Red Team assessment pursues a realistic attack objective and, in doing so, also tests whether your defenders detect and stop the attack. Technology, people, and processes are tested.
- How Long Does a Red Team Assessment Take?
Depending on scope and objective, typically several weeks. A threat-led TLPT to TIBER-EU, including threat intelligence and reporting, usually takes eight to twelve weeks. We define the exact scope in advance together.
- Is Our Blue Team Informed in Advance?
Usually not. That is precisely where the value lies: only a Blue Team that has not been warned reveals the true detection and response capability. A small, informed group steers the test in the background and ensures a safe process.
- Is My Company Required to Perform a TLPT?
Threat-Led Penetration Testing is mandatory under DORA for significant financial entities. NIS2 requires proof of the effectiveness of security measures, but no mandatory TLPT. We clarify your specific obligation in an initial consultation.
- Is the Test Legally Safeguarded?
Yes. Before starting, we agree the scope, test window, and attack depth in writing. This makes the test authorized and legally sound, on request with an additional non-disclosure agreement (NDA).
- Who Carries Out the Test?
OSCP-certified security engineers of a BSI-certified service provider that is ISO 27001 certified on the basis of IT-Grundschutz.
- Is a Retest Included?
In most cases yes, and free of charge. After remediation, we check whether your measures actually close the attack paths used.
Current Information
Recent Blog Articles
Our employees regularly publish articles on the subject of IT security
Contact













