Authorised attack scenario
The scenario is built from techniques actually seen in your sector, and how far each step goes is written in advance. Steps that could harm production data are simulated, not carried out.
We replay the path a real attacker would take, step by step, in an authorised and controlled scenario. The aim is not to break in but to measure together which steps your defence sees and which it misses.
The scenario is built from techniques actually seen in your sector, and how far each step goes is written in advance. Steps that could harm production data are simulated, not carried out.
After each attack step we look at the logs with your defence team: did it leave a trace, raise an alert, did anyone notice? The result is an observation, not an estimate.
At the end, missing log sources, rules that need writing and response steps to update are delivered in order of priority.
Rows show attack phases, columns the four functions of defence. Strong cells mark strengths, faint ones the weak spots.
We clarify the scope, deliverables and acceptance criteria together in the first meeting. The written quote lists that scope item by item; if the scope changes, the quote is updated as a new version.
Each step ends with something concrete in your hands; we move on with your approval.
Together we put the goal, the boundaries and the acceptance criteria in writing.
Within the authorised scope, we run the agreed scenarios in a controlled way.
We examine the current state with data and find the real source of the problem.
We share what was done, the result and the next step in a plain report.
What is included, what we need from you, timing and payment, all in one place. The exact scope and price are set in the written quote.
Tell us what you need; we will define the scope together.
Tell us about your projectA security test finds vulnerabilities; an attack simulation measures whether your defence notices an attack. They complement each other: first the holes are closed, then detection and response are exercised.
Yes. Only systems you are authorised for and have approved in writing are assessed.
Scope, time window and methods are agreed in advance; risky steps require your separate approval.
Tell us what you need; we will define the scope together.