Skip to content
GlabIT
GlabIT

Adversary simulation · objective-based

Red team operations

Red team services in Romania: objective-led adversary simulation under signed rules of engagement, mapped to MITRE ATT&CK, with evidence-led reporting.

In one sentence

An objective-based simulation of a real adversary — phishing, external compromise, lateral movement — run under strict rules of engagement to test whether your people, processes and detections actually work.

Who it is for

  • Organisations that already run regular pentests and want to know whether anyone would notice a real attack
  • Companies with a SOC or MDR provider whose detection coverage has never been tested end-to-end
  • Boards and CISOs preparing for DORA threat-led penetration testing (TLPT) expectations
  • Teams that want a controlled rehearsal of an incident before a real one

What an operation looks like

Adversary simulation is planned around a realistic threat to your sector and geography, mapped to MITRE ATT&CK, and executed quietly. Typical phases:

  1. Reconnaissance — open-source intelligence on your organisation, staff, suppliers and technology; identification of plausible initial-access routes.
  2. Initial access — phishing or other social-engineering pretexts, exposed services, credential exposure, supplier trust — whichever is realistic and in scope.
  3. Foothold and escalation — persistence, privilege escalation and lateral movement, with attention to what your controls log and alert on.
  4. Objective — proof of reaching the agreed target: a marker file, a screenshot, a controlled action — never real damage.
  5. Debrief — replay of the key steps with your defenders and a joint list of detection and process improvements.

Rules of engagement

Every operation is governed by signed rules of engagement stating the objectives, scope, permitted techniques, deconfliction procedure, safety and stop conditions and named contacts on both sides, supported by documented authority from the relevant asset, premises, system, data and employer owners. Techniques are non-destructive and impact is simulated with agreed methods; personal data is minimised, and reporting about individuals follows the rules of engagement and applicable employment and privacy safeguards — by default we report patterns, not names.

Discretion

Red-team buyers expect it and we work that way: a small trusted contact group, no public case studies, and evidence handled under agreed data-handling terms and deleted after the engagement, subject to any legal, contractual or legal-hold retention exceptions stated in the agreement. A standard red-team exercise is not automatically DORA threat-led penetration testing (TLPT).

Deliverables

What you receive

  • Rules of engagement and authority

    Objectives, scope, permitted techniques, deconfliction procedure, safety and stop conditions and named contacts — signed by both sides, together with documented authority from the owners of the assets, premises, systems, data and — for activities involving staff — the employer, before anything starts.

  • Attack narrative

    The full timeline of what we did, when, and how, mapped step by step to MITRE ATT&CK techniques.

  • Detection and response assessment

    For each step, whether it was logged, alerted, triaged and responded to — and how long each took. This is the part your SOC will read twice.

  • Findings and recommendations

    Technical and procedural weaknesses ranked by how much they contributed to reaching the objective, each with a specific fix.

  • Purple-team debrief

    A joint session with your defenders replaying the key steps so detections are improved on the day, not in a backlog.

  • Evidence and data handling

    OSINT notes, phishing results, captured credentials and access evidence are handled strictly under the rules of engagement — minimised during the exercise, shared only with the white team, and returned or securely deleted at the end.

Engagement model

How it runs

Model
Fixed-price per objective set; a single trusted contact on your side ("white team") knows the schedule.
Typical timeline
Set by the objectives and scope and agreed in the proposal; multi-objective operations take longer.
  1. 01

    Objectives and rules

    We agree what "success" means for the adversary — access to a specific system, data set or process — and what is off-limits.

  2. 02

    Reconnaissance

    What an outsider can learn about your organisation, people and technology, and the initial-access paths that suggests.

  3. 03

    Execution

    Initial access, persistence, privilege escalation and lateral movement towards the objective, quietly, with deconfliction available at all times.

  4. 04

    Report and debrief

    Narrative, detection assessment, purple-team session and a remediation plan.

FAQ

Questions a sceptical CISO asks

How is a red team different from a penetration test?

A pentest looks for as many vulnerabilities as it can within a scope. A red team pursues one objective by whatever realistic route works, and measures your detection and response along the way. Pentests find weaknesses; red teams test whether you would notice and stop an attacker using them.

Do you do phishing, physical intrusion or social engineering?

Yes — phishing and other social-engineering techniques, and physical intrusion or on-site social engineering, are offered where the objectives call for them and where the appropriate authority exists. Each such scenario — including research on staff, use of credentials and supplier impersonation — is explicitly scoped, depends on the contract and the jurisdiction, and is covered by the signed rules of engagement, employment and privacy safeguards, and a duty-of-care clause.

Who in our organisation knows it is happening?

As few people as possible — usually one or two in a "white team" who can deconflict with real incidents and stop the exercise. The SOC and IT are normally not told, otherwise the test measures nothing.

Can this hurt production?

Techniques are chosen to be non-destructive and impact is simulated — marker files instead of real encryption, deletion or exfiltration — under the data-handling terms of the rules of engagement. Deconfliction is available at all times, safety and stop rules apply, and the operation stops immediately on request. Residual risk is discussed and accepted in writing before execution.

Does this satisfy DORA TLPT?

DORA's threat-led penetration testing follows the TIBER-EU framework and has specific requirements for scope, threat intelligence and tester independence. We will tell you plainly whether a given engagement meets them or whether it is a preparatory exercise.

Find out whether anyone would notice

Red-team engagements are scoped in a confidential call. Tell us what would hurt most, and we design an operation around it.