Penetration Testing

Red team assessments that think like the adversary.

Real attackers do not follow a checklist. SubRosa runs full-spectrum adversary simulations, digital, social, and physical at once, to test whether your detection and response actually hold up against a determined threat.

Adversary simulation · Assumed breach · Purple team · Objective-based

Red team assessment, defined

What is a red team assessment?

A red team assessment is a goal-oriented adversary simulation that mimics a real, advanced attacker across every vector at once, digital exploitation, social engineering, and physical intrusion, over an extended engagement. Unlike a scoped penetration test, it has few restrictions and a defined objective, such as reaching specific crown-jewel data, so it measures not just your vulnerabilities but whether your team detects and responds to a genuine, sustained attack.

How we engage

Tailored to your threat landscape.

We customize each engagement to your organization's threats and security maturity.

Full-scope red team

Comprehensive adversary simulation with no artificial restrictions, targeting every vector: physical, social, and digital, simultaneously.

Assumed breach

Starting from inside your network to test lateral movement, privilege escalation, and how well you detect data exfiltration.

Objective-based

A goal-oriented operation targeting specific crown jewels such as customer data, intellectual property, or financial systems.

Purple team

A collaborative red and blue team exercise focused on improving detection and response in real time as the attack unfolds.

How the engagement runs

A campaign, not a checklist.

A red team assessment tests your detection and response, not just your vulnerabilities. The engagement is structured accordingly.

  1. 01

    Objective setting and rules

    We agree what 'success' means in concrete terms — reach this data, reach this system, achieve this transaction — and who inside your organisation knows the test is happening. Usually a very small group, because the point is to test the response of people who do not know.

  2. 02

    Threat profile selection

    We select a threat profile that reflects who realistically targets your sector, and emulate that adversary's known tradecraft rather than running an undifferentiated toolkit. Emulating a group that would never target you produces findings you cannot act on.

  3. 03

    Reconnaissance and initial access

    Initial access is earned the way it would be in reality — phishing, exposed service, physical entry, or supplier path — rather than granted. Where a client prefers to skip this, we start from an assumed-breach position instead, which is a legitimate and often more efficient choice.

  4. 04

    Establishing and maintaining access

    This is where detection is genuinely tested: persistence, command and control, credential theft and defence evasion. Every action is logged with a timestamp so your team can later reconstruct exactly what they did and did not see.

  5. 05

    Working toward the objective

    Lateral movement and privilege escalation toward the agreed objective, taking the quietest path rather than the fastest, because the question is what your controls notice rather than how quickly a determined attacker can finish.

  6. 06

    Purple team debrief

    The engagement ends with your blue team in the room. We walk the full timeline against their logs and alerts, establishing exactly where detection existed, where it fired but was not actioned, and where nothing saw anything. That session is where most of the value lands.

Why SubRosa

No checklists, real adversaries.

Threat emulation

We emulate the specific threat actors that target your industry, APT groups and ransomware crews, using their real tactics, techniques, and procedures.

Detection & response

The engagement measures how your people, process, and tooling detect and respond to a sustained attack, not just whether a vulnerability exists.

Purple team uplift

We can run collaboratively with your blue team so every finding immediately sharpens your detection and response, not just your patch list.

Every objective, path, and detection.

From operation to defense uplift.

Your red team engagement lives in Sable: objectives, attack paths, what was detected and what was missed, and the prioritized actions, tracked over time so each exercise measurably improves your defenses.

Engagement in Sable
Objective: exfiltrate PII3 of 4 undetected
  1. 1
    Initial accessMissed
    Spear-phish to a finance user
  2. 2
    FootholdMissed
    Beacon on the workstation
  3. 3
    EscalationDetected
    Kerberoast to domain admin
  4. 4
    ObjectiveMissed
    Reached customer PII store
Full kill chainDetection gaps mapped

Common questions

What is a red team assessment?
A red team assessment is a goal-oriented adversary simulation that mimics a real, advanced attacker across every vector at once, digital exploitation, social engineering, and physical intrusion, over an extended engagement. Unlike a scoped penetration test, it has few restrictions and a defined objective, so it measures whether your team detects and responds to a genuine, sustained attack.
How is a red team assessment different from a penetration test?
A penetration test finds and validates vulnerabilities within a defined scope. A red team assessment is broader and objective-driven: it combines digital, social, and physical attack paths with minimal restrictions to test not just whether vulnerabilities exist, but whether your people, process, and tooling detect and stop a determined adversary.
What is the difference between a red team assessment and a penetration test?
A penetration test asks what is vulnerable, works to a defined scope, and aims for coverage. A red team assessment asks whether your detection and response actually work, pursues a specific objective, and deliberately takes the quiet path rather than the fast one. If you have not yet run penetration tests, start there — a red team engagement against an environment with known unpatched systems mostly confirms what a cheaper test would have told you.
Should our security team know it is happening?
No, beyond a very small authorised group. The engagement is testing their detection and response, and that measurement is meaningless if they are watching for it. We agree in advance who knows, and who can confirm the activity is authorised if an incident is declared.
What is an assumed breach engagement?
One that starts with the attacker already inside — a compromised workstation or a set of valid credentials — instead of spending the first stretch of the engagement earning access. It is a legitimate and often more efficient choice, because it concentrates the time on lateral movement and detection, which is usually where the real questions are.
What do we get at the end?
A full timeline of the operation walked through with your blue team in the room, matched against their own logs and alerts. That session establishes exactly where detection existed, where an alert fired but was not actioned, and where nothing saw anything — and it is where most of the engagement's value lands.

See how you hold up against a real attack.

Book a red team assessment and find out whether your detection and response can stop a sophisticated, determined adversary.