Red Teaming
Quoted on scope, fixed price. Includes the Vexil platform and a hand-verified retest.
Teams who have had us test their systems
What this covers
Unlike a penetration test that finds vulnerabilities, a red team engagement simulates a real adversary - testing your people, processes, and technology under realistic attack conditions. We model threat actors relevant to your industry, conduct reconnaissance, attempt initial access (including phishing if in scope), escalate privileges, move laterally, and demonstrate business impact - all while testing whether your SOC detects and responds. You get a full attack narrative showing exactly how an adversary would compromise your organization, where detection failed, and what to fix first.
- Know exactly whether your SOC would detect a real attack
- Close detection gaps before an actual adversary exploits them
- Get a full attack narrative your board and security team can act on
- See how your team responds under a live incident, not a tabletop exercise
Methodology
How the work is done
Repeatable, documented, and tracked as coverage inside the platform so you can see what has been looked at.
- 01
Engagement Planning
Define objectives, threat model, attack surface, rules of engagement, and success criteria.
- 02
Reconnaissance & Initial Access
OSINT gathering, exposed asset discovery, and initial compromise via perimeter vulnerabilities or phishing.
- 03
Post-Exploitation & Lateral Movement
Privilege escalation, credential harvesting, persistence, and lateral movement within permitted scope.
- 04
Reporting & Executive Debrief
Full attack chain documented, detection gaps identified, and strategic improvement roadmap presented to leadership.
Why it matters
What you get out of it
Realistic adversary simulation
Modeled on real threat actors relevant to your industry and geography.
Full attack chain testing
From initial access to data exfiltration - every stage tested against live defenses.
Detection gap analysis
We test whether your SOC, SIEM, and EDR actually detect and respond to attacks.
Executive & technical reporting
Attack narrative for leadership, detection gaps for security team, remediation roadmap for both.
What you receive
Delivered in the platform as the work happens, and exportable as a document whenever you need one.
- Full attack chain narrative - step-by-step account of how the objective was achieved
- Detection gap analysis - where your SOC/EDR/SIEM missed or caught activity
- Executive debrief presentation - findings and strategic recommendations for leadership
- Remediation roadmap - prioritized by risk and detection impact
Pricing
What changes the price
Every engagement is quoted on scope rather than hours. These are the four things that move it, and they are what we work through on the call.
Objective
What counts as success
Duration
How long we stay in
Starting point
External, or assumed breach
Detection
Whether your team is told
Delivered on the Vexil platform
The narrative and every step in it are published as we go, so your blue team can replay the whole path afterwards against their own detection.
See the platformFAQ
Questions about red teaming
How is red teaming different from penetration testing?
A penetration test finds as many vulnerabilities as possible in a given scope. A red team engagement simulates a specific adversary with a specific objective - it tests whether your entire security program (people, processes, technology) can detect and stop a real attack. Red teaming is stealthier, broader in scope, and focused on detection gaps rather than vulnerability counts.
Do you use phishing in red team engagements?
Phishing is optional and only conducted with explicit client approval during scoping. When included, we design realistic but safe campaigns that test user awareness without risk of actual compromise. We never retain credentials or sensitive data.
Scope your red teaming engagement.
Thirty minutes on a call and you have a fixed price, a testing date and a walkthrough of the platform against your own scope.





