Red Teaming - Realistic Attack Simulations

You never really know how good your defense is until someone attacks it. Our Red Team simulates a real, targeted attack and measures whether your people, processes, and technology detect and stop it. For the financial sector, we run threat-led tests (TLPT) based on the TIBER-EU framework, as required by DORA.

References

Toyota
dkb
R+V BKK
State Bank of India
Clark
Metzler

Certificates

ISO 27001 Grundschutz
OSCP

Advanced Persistent Threat

What is Red Teaming?

Red Teaming tests the detection and response capabilities of an entire organization. Instead of listing as many vulnerabilities as possible, a Red Team pursues a specific attack objective and emulates a real attacker who acts actively and tries to evade detection, comparable to an Advanced Persistent Threat (APT).

The approach originated in the military sector, where defense strategies were examined through realistic adversary simulations. Applied to cybersecurity, this means we take the attacker's perspective to test and specifically improve the effectiveness of your security measures under real-world conditions.

Levels of Abstraction

Red Teaming and Penetration Testing Compared

Whether a penetration test or a Red Team assessment is the right choice depends on the objective. A pentest uncovers as many vulnerabilities as possible within a defined scope. A Red Team instead pursues a realistic attack objective and, in doing so, tests the entire defense apparatus, including people and processes.

  • Goal-Oriented Instead of Exhaustive

    A Red Team does not look for every vulnerability, but for the path that reaches the defined objective. A pentest aims for the most complete coverage of a scope.

  • Detection Is Tested Too

    The Red Team operates as covertly as possible. Whether and when your Blue Team notices the attack is itself a key result. In a pentest, stealth is usually not an objective.

  • People, Processes, and Physical Access

    Beyond technology, this includes social engineering, physical access attempts, and process weaknesses. A classic pentest usually stays technical.

  • Longer Duration and Preparation

    Red Team operations go deep and require more time, more people, and thorough threat intelligence preparation.

Illustration of a Red Team operation

Also called attack simulation

When Should Red Teaming Be Used?

An attack simulation realistically recreates a real attack and explicitly includes the human factor that conventional pentests leave out. All digital and analog processes of your IT security management are put to the test. This gives you reliable insights from prevention through detection to response, while also raising the awareness of your employees.

  • Measurable Detection and Response Capability

    You get reliable data on whether and how quickly your SOC notices and contains a real attack.

  • Realistic Understanding of Risk

    Instead of a list of theoretical findings, you see what an attacker can actually achieve in your environment.

  • Remediation of Concrete Attack Vectors

    We reveal the paths used and support their targeted closure, not just individual vulnerabilities.

  • Insights Into Attack Methods

    Your team learns real tactics, techniques, and procedures and can tune detections specifically to them.

  • Testing the Response of Your Processes

    Alerting, escalation, and incident response are tested under real-world conditions.

Illustration of an attack simulation

How a Red Team Assessment Works

A Red Team assessment follows a structured approach aligned with MITRE ATT&CK and TIBER-EU:

  • Threat Intelligence and Scoping

    Together we define objectives, scope, and test windows and build a threat-based adversary profile for your industry.

  • Reconnaissance

    Passive and active reconnaissance of your attack surface, employees, and exposed services.

  • Initial Access

    Gaining a foothold via the most promising path, such as spear phishing, exposed services, or physical access.

  • Foothold and Command and Control

    Establishing stable, as inconspicuous as possible access and a C2 connection.

  • Privilege Escalation and Lateral Movement

    Expanding privileges and moving through the network toward the agreed objectives.

  • Objective and Exfiltration

    A controlled demonstration of compromising your crown jewels, without causing real damage.

  • Purple Teaming and Reporting

    Joint review with your Blue Team, a documented attack narrative, and prioritized measures.

From Phishing to Physical Access

Scenarios and Attack Vectors

A realistic attack uses every path that leads to the objective. We tailor the scenarios to your threat landscape and combine technical, human, and physical vectors, up to the assumed-breach approach, in which we assume an initial access has already happened and test the detection of the follow-on activity.

  • Assumed Breach

    We assume an existing foothold and test whether your SOC detects and stops the post-exploitation.

  • External Perimeter

    Attack from the outside via internet-exposed services, VPN gateways, and web applications.

  • Social Engineering and Phishing

    Targeted spear phishing and vishing campaigns against your employees as the most common initial access.

  • Physical Access

    Attempting to gain on-site access to buildings, workstations, or network sockets.

  • Purple Teaming

    On request, Red and Blue Team work together openly to build detections directly and retest them.

Illustration of different Red Teaming attack vectors

DORA, TIBER-EU, and NIS2

Red Teaming as Regulatory Proof of Effectiveness

Supervisors and regulators no longer only ask whether systems are patched, but whether an organization detects and stops an ongoing attack. That is exactly what Red Teaming demonstrates. For the financial sector, DORA (Regulation (EU) 2022/2554, applicable since 17 January 2025) makes threat-led testing mandatory: Articles 26 and 27 require significant financial entities to perform Threat-Led Penetration Testing (TLPT), methodologically based on the ECB's TIBER-EU framework and at least every three years. NIS2 requires, in Article 21, proof of the effectiveness of security measures. A Red Team assessment provides exactly this proof, even where no TLPT is mandated.

  • DORA and TLPT for the Financial Sector

    Articles 26 and 27 of DORA require significant financial entities to perform Threat-Led Penetration Testing. We conduct TLPT as a qualified, independent tester.

  • TIBER-EU Framework

    TIBER-EU is the European framework for Threat Intelligence-based Ethical Red Teaming. It structures TLPT from the threat intelligence phase through the red team phase to joint purple teaming with your Blue Team.

  • NIS2: Proof of Effectiveness

    NIS2 (Article 21) requires policies and procedures to assess the effectiveness of security measures. A Red Team assessment proves that detection and response actually work, even without mandatory TLPT.

  • Evidence for Supervisors

    BaFin and the ECB monitor compliance with DORA requirements. A documented Red Team assessment is the solid evidence that your defense works.

Red Teaming in the context of DORA, TIBER-EU, and NIS2

Which Tools and Techniques Are Used?

Our operations are aligned with the MITRE ATT&CK Framework, the common language for adversary tactics and techniques. Among the most important tools are AptSimulator, Atomic Red Team, and Caldera. In addition, we use Metasploit for exploits, Cobalt Strike for post-exploitation, BloodHound for Active Directory analysis, Burp Suite for web applications, and the Social-Engineer Toolkit for targeted social engineering attacks.

Where established tools are not enough, our specialists develop their own exploits during the assessment, up to previously unknown zero-day vulnerabilities. We publish responsibly disclosed findings as Security Advisories.

  • AptSimulator

    The Windows-based tool simulates typical traces and activities of advanced attackers (APT). It deliberately creates artifacts and system changes to test the detection and response capabilities of IT security teams. AptSimulator is particularly suitable for testing the effectiveness of forensic and monitoring solutions against known attack patterns.

  • Atomic Red Team

    The framework provides small, targeted tests ("atomic tests") that simulate individual tactics, techniques, and procedures (TTPs) from the MITRE ATT&CK Framework. Companies can use this to specifically check whether their security controls detect and defend against certain attack paths. Atomic Red Team allows for the customization of tests to industry-specific threats and supports regular, continuous reviews of their own defense measures.

  • MITRE Caldera

    The automated platform emulates attackers and supports manual Red-Team operations. Caldera is based on the MITRE ATT&CK Framework and allows orchestrating complex attack scenarios with various plugins and agents. The platform is suitable for automating Adversary Emulation, supporting Incident Response exercises, and visualizing attack paths.

  • In-House Exploit and Zero-Day Development

    Where off-the-shelf tools reach their limits, we do our own research and develop tailored exploits, up to new zero-day vulnerabilities. We document our responsibly disclosed findings publicly in our Security Advisories.

Illustration of a safe representing security

Outcome and Evidence

What You Receive

After the assessment, you receive more than a list of findings. We deliver a comprehensible attack narrative, a summary that management can understand, and a prioritized remediation plan. Critical findings are reported immediately during the test.

  • Management Summary

    An understandable classification of risk and impact, even without technical background.

  • Documented Attack Narrative

    The full path from initial access to objective, with evidence and reference to MITRE ATT&CK.

  • Prioritized Measures

    Concrete recommendations sorted by impact, instead of a mere list of findings.

  • Free Retest

    After remediation, in most cases we retest free of charge to confirm that your fixes actually close the attack paths used.

Illustration of the report and outcome of a Red Team assessment

How Far Would a Real Attacker Get in Your Organization?

Find out before someone else does. Our BSI-certified experts simulate a real, targeted attack on your organization.

Frequently Asked Questions About Red Teaming

Red Teaming: Frequently Asked Questions

Answers to the questions clients ask us most often before a Red Team assessment.

How Does Red Teaming Differ From a Penetration Test?

A pentest uncovers as many vulnerabilities as possible within a defined scope. A Red Team assessment pursues a realistic attack objective and, in doing so, also tests whether your defenders detect and stop the attack. Technology, people, and processes are tested.

How Long Does a Red Team Assessment Take?

Depending on scope and objective, typically several weeks. A threat-led TLPT to TIBER-EU, including threat intelligence and reporting, usually takes eight to twelve weeks. We define the exact scope in advance together.

Is Our Blue Team Informed in Advance?

Usually not. That is precisely where the value lies: only a Blue Team that has not been warned reveals the true detection and response capability. A small, informed group steers the test in the background and ensures a safe process.

Is My Company Required to Perform a TLPT?

Threat-Led Penetration Testing is mandatory under DORA for significant financial entities. NIS2 requires proof of the effectiveness of security measures, but no mandatory TLPT. We clarify your specific obligation in an initial consultation.

Is the Test Legally Safeguarded?

Yes. Before starting, we agree the scope, test window, and attack depth in writing. This makes the test authorized and legally sound, on request with an additional non-disclosure agreement (NDA).

Who Carries Out the Test?

OSCP-certified security engineers of a BSI-certified service provider that is ISO 27001 certified on the basis of IT-Grundschutz.

Is a Retest Included?

In most cases yes, and free of charge. After remediation, we check whether your measures actually close the attack paths used.

Current Information

Recent Blog Articles

Our employees regularly publish articles on the subject of IT security

Contact

Curious? Convinced? Interested?

Schedule a no-obligation initial consultation with one of our sales representatives. Use the following link to select an appointment:
Please send me the free sample report.
Please send me more information.
I would like to subscribe to the newsletter and receive further information at the email address provided.
I consent to the use and processing of my personal data provided for the purpose of handling my inquiry.*
This form is processed via cloud services, as described in our privacy policy. A secure alternative is an email to [email protected]. For confidential communication, feel free to request our PGP key there. Our lab will also provide you with a key on request.