Red team assumed-breach engagement
Anonymised pattern: assumed-breach red team with multi-surface objectives — detection gaps and a board-ready story without TTP theatre.
At a glance
Context / challenge
An enterprise wanted to know what an operator could achieve from an agreed foothold, and whether detections would notice. Objectives spanned identity, endpoint and a scoped application or cloud surface. The buyer needed a narrative leadership could act on — not a dump of tool output or a catalogue of every technique used.
Rules of engagement, out-of-bounds systems and communication paths were fixed before start. This sits under our red teaming / adversarial simulation offering within security assessments.
Engagement shape
Typical shape: assumed-breach start, time-boxed objectives, dual reporting track (technical for defenders, executive for decision-makers). Purple-team moments may be scheduled if the buyer wants detection validation during the window rather than only at the end.
Success is objective progress plus honest detection coverage notes — not “we got domain admin” as a vanity metric.
Approach
Discover
Confirm foothold assumptions, objectives and out-of-bounds with the buyer.
Validate
Pursue objectives across agreed surfaces; note where controls stop progress.
Prove
Capture evidence for objective outcomes and detection gaps — no unnecessary blast radius.
Remediate
Translate into detection engineering and hardening priorities.
Retest
Optional replay of agreed classes to validate new detections.
Interactive steps — content remains fully readable without JavaScript.
Finding classes (illustrative)
Illustrative outcome classes: objectives reached or blocked; detection gaps along the path; control strengths that stopped progression; process or handoff delays that mattered more than any single technical flaw. We describe classes of technique at a level useful for defence — we do not publish step-by-step exploit payloads or a TTP dump on marketing pages.
Outcomes and remediation pattern
Defenders usually leave with prioritised detection engineering work, identity and endpoint hardening themes, and a board summary that explains residual risk without invented percentages. A follow-up window can validate that agreed detections now fire on the replayed classes.
Lessons for buyers
- Write objectives and out-of-bounds before kick-off.
- Demand an executive narrative and a defender narrative — one report rarely serves both.
- Measure detection, not only “did they get in.”
- Avoid vendors who lead with CVE theatre or fake risk-reduction percentages.
Related patterns & research
Want this engagement shape scoped for you?
Share constraints and success criteria — PocForge will propose a human-led plan with proof and retest.
