Bug’s Life — Field Guide to Vulnerabilities
← Field Guide Index
SPC-05ADVERSARY

Red Team Operations

Classification
ADVERSARY
Method
By hand
Standards
OWASP · PTES
Duration
1–4 weeks
01 · Field Notes
Overview

What this engagement covers

A red team engagement measures how your organization stands up to a determined, realistic attacker pursuing a specific objective — not just whether individual systems have bugs. We test the full picture: technology, people and your ability to detect and respond.

02 · Test Coverage
What we test
Initial access
  • External exploitation of internet-facing systems
  • Phishing and payload delivery to reach a foothold
  • Exposed and leaked credentials
Foothold & evasion
  • Endpoint execution and command-and-control
  • Evading EDR/AV and security monitoring
  • Establishing persistence
Lateral movement & escalation
  • Credential access — dumping, Kerberoasting, token theft
  • Privilege escalation and Active Directory attack paths
  • Pivoting toward the agreed objective
Objective, impact & response
  • Reaching the agreed "crown-jewel" targets and proving impact safely
  • What your SOC / EDR detected — and what it missed
  • Time-to-detect and response effectiveness (purple-team option)
Vectors (as scoped)
  • Technical, human (social engineering) and physical
03 · Specimen Range
Scope of work
  • a.Objective-driven scenarios agreed with you up front
  • b.Full-scope testing across technical, human and physical vectors (as scoped)
  • c.Initial access, lateral movement and objective completion
  • d.Detection and response assessment (purple-team option available)
  • e.Stealth and rules-of-engagement tailored to your risk appetite
04 · Field Method
How we work
01

Scope & rules of engagement

We agree targets, timing, depth and constraints in writing before anything starts — so testing is safe, authorized and focused on what matters to you.

02

Manual testing

Certified testers work by hand — following recognised methodologies like OWASP and PTES, not just automated scanners — chaining findings the way a real attacker would to prove genuine impact.

03

Reporting

You get a prioritized report with clear proof-of-concept, business impact and step-by-step remediation your engineers can act on immediately.

04

Retest

After you fix, we re-test the findings to confirm they are resolved and issue an updated report you can share with customers or auditors.

05 · What you keep
Deliverables
  • A narrative of the full attack path, end to end
  • Where detection worked — and where it did not
  • Prioritized improvements for prevention and response
  • An executive-ready summary alongside technical detail
06 · Field Q&A
Common questions
How is this different from a penetration test?

A pentest aims to find as many vulnerabilities as possible in a defined scope. A red team is quieter and goal-focused — it asks “can a real attacker reach this objective, and would we notice?” It is best once you already run regular pentests.

Can we test our defenders too?

Yes. We can run it as a purple team, working alongside your defenders to tune detection and response in real time.

Specimen request

Ready to get started with Red Team Operations?