Let's talk about your project
DOKI / Cybersecurity

Cybersecurity · Simulation

We replay the path a real attacker would take, step by step, in an authorised and controlled scenario. The aim is not to break in but to measure together which steps your defence sees and which it misses.

  • Authorized scope
  • Authorized attack scenario
  • Defense review
  • Remediation plan
01 / What this service includes

Red and blue team at the same table.

01

Authorised attack scenario

The scenario is built from techniques actually seen in your sector, and how far each step goes is written in advance. Steps that could harm production data are simulated, not carried out.

02

Step-by-step defence measurement

After each attack step we look at the logs with your defence team: did it leave a trace, raise an alert, did anyone notice? The result is an observation, not an estimate.

03

A list of gaps to close

At the end, missing log sources, rules that need writing and response steps to update are delivered in order of priority.

02 / How it works

A sample coverage table

Rows show attack phases, columns the four functions of defence. Strong cells mark strengths, faint ones the weak spots.

03 / Scope

Let's define the scope together.

We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.

Only explicitly authorized assets and agreed scope are assessed.

Deliverables

  • 01Authorized scope
  • 02Authorized attack scenario
  • 03Defense review
  • 04Remediation plan
04 / Process

How we move forward, step by step.

Each step ends with something concrete in your hands; we move on with your approval.

  1. 01

    Scope

    Together we put the goal, the boundaries and the acceptance criteria in writing.

  2. 02

    Simulation

    Within the authorised scope, we run the agreed scenarios in a controlled way.

  3. 03

    Analysis

    We examine the current state with data and find the real source of the problem.

  4. 04

    Reporting

    We share what was done, the result and the next step in a plain report.

05 / Decision details

What to know before you ask for a quote.

What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.

Included

  • Real attacker techniques, run in a controlled way.
  • An assessment of which steps your defences caught, and an improvement roadmap.

Not included

  • Tests that could disrupt a service (only with separate written approval, in a controlled setting).
  • Fixing the findings (offered separately as Remediation).

What we need from you

  • A signed written authorisation.
  • Access to your logging and alerting tools (SIEM, EDR) if you have them.
  • Someone on the defence side during the exercise.

Timing and delivery

  • Tests run on weekdays between 09:00 and 18:00 (Türkiye time).

What sets the price

  • Number of scenarios and depth of the attack chains.

Payment and aftercare

  • For work agreed in person, the full fee is paid at the start.
  • For remote work, half is paid at the start and half on delivery.
  • We respond to every request within 12 hours.
  • Meetings are held in Turkish; correspondence and deliverables are handled in the language of your choice with translation support.
  • We work in person in Istanbul and remotely across Türkiye and worldwide.
06 / FAQ

The questions on your mind.

Tell us what you need; we will define the scope together.

Tell us about your project
How does this differ from a regular security test?

A security test finds vulnerabilities; an attack simulation measures whether your defence notices an attack. They complement each other: first the holes are closed, then detection and response are exercised.

Is permission needed before testing?

Yes. Only systems you are authorised for and have approved in writing are assessed.

Will testing affect my live system?

Scope, time window and methods are agreed in advance; risky steps require your separate approval.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.