Red Team
One objective. Full path. Detection evaluated.
We attempt a stated objective (tenant control, crown-jewel data, or domain admin) and measure whether you detect and contain it.
Default length is about three weeks. Phishing and wireless are add-ons, not separate products. Pickle is the C2 we run on the engagement when the path calls for it.
You get
- Written Statement of Work: objective, rules of engagement, out of scope
- Operator log and attack-path narrative
- Detection timeline: what you saw, what you missed, when
- 90-minute readout with detections your team can write
MITRE ATT&CK Enterprise
Findings land in the language your blue team already uses.
01Reconnaissance
Active ScanningT1595Victim Org InfoT1591Search Open SourcesT1593Phishing for InfoT159803Initial Access
Spearphishing AttachmentT1566.001Spearphishing LinkT1566.002Valid AccountsT1078External Remote ServicesT113306Privilege Escalation
Token ManipulationT1134Bypass UACT1548.002Service PermissionsT1543.003Process InjectionT105507Defense Evasion
Obfuscated FilesT1027Alternate Data StreamsT1564.004Impair DefensesT1562MasqueradingT103608Credential Access
OS Credential DumpingT1003KerberoastingT1558.003Brute ForceT1110Unsecured CredentialsT155209Discovery
Domain Trust DiscoveryT1482Account DiscoveryT1087Network Share DiscoveryT1135System InfoT1082Contact
Written scope. Then the work.
Tell us what you want tested. A 20-minute call, then a written Statement of Work covering targets, rules of engagement, and out of scope.