What it is
Our red team runs an agreed attack plan inside an isolated range built from your architecture. Your blue team defends with the same SIEM, EDR and procedures it uses at work. Both sides work in one environment, and every attack step is logged.
It suits SOC managers and security leads who want to see how detection and response perform across a full intrusion, and organizations with an internal red team that needs a place to run techniques not permitted in production. Facilitated programs are described under red team and blue team exercises.
Scenarios
Phishing to domain compromise
Initial access through a phishing payload, privilege escalation, credential dumping, and movement to a domain controller.
Ransomware staging
Discovery, disabling of backups and security tools, data staging, and encryption of selected hosts.
Help desk social engineering
A deepfake voice call to the help desk leads to an MFA reset, account takeover and mailbox access.
Cloud control-plane attack
A leaked access key or an over-permissive role is used to create persistence and reach storage in a cloud account.
Insider data theft
A trusted account collects sensitive files and sends them out over approved channels.
Misused AI agent
An internal AI agent with tool access is manipulated into running commands or retrieving data outside its purpose.
How an exercise runs
We agree objectives, what the blue team knows in advance, and the rules of engagement: permitted techniques, time window, prohibited actions and stop conditions. The attack plan is mapped to MITRE ATT&CK techniques so it can be scored.
We build the hosts, identities, services and logging the scenario needs, in your cloud, on-premises or on our hosting. Your detection rules and playbooks are loaded into the range tools. We test isolation and dry-run the attack plan before the exercise.
The red team executes the plan and logs each action with a timestamp. The blue team monitors, investigates, escalates and contains. A white cell controls pace, answers questions and can pause the exercise.
We place the red team log next to the blue team's alerts, tickets and actions. For each technique we record whether it was detected, when, and how the team responded. The session closes with an agreed list of improvements.
What the range includes
Target environment
Domain, endpoints, servers, email and cloud resources built from your architecture, with test identities and synthetic data.
Defensive tooling
Your SIEM and EDR where licensing allows, or Wazuh, Security Onion and OpenSearch, set up with your log sources and rules.
Attack infrastructure
Command-and-control servers, phishing infrastructure and red team tooling, all contained inside the range.
White cell and scoring
Exercise control, the red team activity log, and a scoring sheet built from the ATT&CK techniques in the plan.
Exercise formats
| Format | How it works | When it fits |
|---|---|---|
| Tabletop | Teams talk through the scenario step by step using range logs and screenshots, without live attack activity. | Early in a program, or for leadership and cross-team coordination. |
| Live-fire | The red team attacks and the blue team defends live, without sight of the attack plan. | Measuring detection and response across a full intrusion. |
| Purple team | Red and blue work together and pause after each technique to check telemetry and tune detection. | Building or tuning detection rules, or following up a live-fire run that showed gaps. |
MITRE ATT&CK mapping
Every step in the attack plan carries a MITRE ATT&CK technique ID. This gives both teams a shared vocabulary in the debrief and lets you compare results between runs.
The mapping shows which techniques the exercise covered and which of them your team detected. It describes the exercise only. It does not measure coverage in your production environment.
What you receive
Each exercise ends with a joint debrief for both teams. The findings are written up afterward and shared with the people you name.
Debrief session
- Red team timeline alongside blue team actions
- Discussion of decisions on both sides
- Questions and observations from participants
Detection findings
- Result for each technique: detected, late or missed
- Missing log sources and rule gaps
- Alert noise that slowed triage
Response findings
- Timing and quality of escalation and containment
- Handoffs between SOC, IT and management
- Playbook steps that were unclear or skipped
Next steps
- Recommended detection and process changes
- ATT&CK view of the techniques exercised
- Scenario saved for a rerun after changes
Questions
Does the red team touch production?
No. All attack activity stays inside the isolated range. The rules of engagement list the hosts in scope, and no production or external asset is ever on that list.
How close is the range to our environment?
We build it from your architecture, security tools and log sources, as far as the scenario needs. The brief records any differences that could affect detection results.
Who plays the red team?
Our operators, by default. Your internal red team can run the attack side with our support, or join ours.
Should the blue team know the scenario in advance?
That is your choice. For a live-fire run the plan is usually kept from the blue team. In a purple team session both sides see it.
Can we rerun the same scenario?
Yes. Each scenario is kept in a library for your range, with its configuration and scoring sheet. You can rerun it with a new group, or after changing a rule or procedure to compare results.
How is exercise data handled?
Range data, recordings and findings stay in the deployment you choose. We agree retention and deletion rules before the first session and sign an NDA on request. Synthetic data is the default, and production data is used only with your written approval.
How to prepare
Decide who sits on the blue team and who acts as escalation contacts outside the SOC. Share your detection rules, playbooks and log source list so we can set up the range tools to match.
Pick one or two outcomes you want to measure, such as detection of credential theft or time to isolate a host. Agree the format and whether the blue team will see the scenario beforehand.

