Skip to content
Menu

// Offensive Security Practice

Red Team
Exercise

We attack your organisation the way a real adversary would — under written authorisation, mapped to MITRE ATT&CK, and with every step documented — so you find out what actually breaks before someone else does.

Categories
5
Scenarios
40
ATT&CK tactics
14
Phases
8
Engagement Console
ENGAGEMENT
AUTHORIZED
SCOPE
5 CATEGORIES / 40 SCENARIOS
FRAMEWORK
MITRE ATT&CK · PTES · NIST
RULES OF ENGAGEMENT
SIGNED
STATUS
READY

ISO 27001 · ISO 9001:2015 certified
Every engagement runs under written authorisation and an agreed Rules of Engagement document.

// 01 — Why run one

A scan tells you what is open.
A red team tells you what is reachable.

Cyberattacks and data breaches are not prevented by a once-a-year checklist. They are prevented by regular testing, continuous reinforcement, and monitoring that reflects how attackers actually operate.

Red teaming simulates real-world attacks to test technology, people, and process defences together — because a real adversary does not respect the boundary between them.

A Red Team Assessment is a goal-based activity designed to test the effectiveness of an organisation's security controls — and to understand how resilient the organisation is to real-world attack.

  • 01

    Assess preventive controls

    Measure how effective your defences really are across email, perimeter, internal network, and wireless surfaces.

  • 02

    Measure response capability

    Find out whether your team detects the activity, how quickly they escalate, and what they do once they know.

  • 03

    Identify weaknesses first

    Analyse technology, configuration, and human behaviour before a real adversary gets the chance to.

  • 04

    Remediation roadmap

    Receive a prioritised, risk-based plan that improves overall security posture — not a raw tool export.

  • 05

    Authorisation & assurance

    Every active scenario is executed under written authorisation and an agreed Rules of Engagement document, with clear scope, deconfliction contacts, and emergency stop procedures.

// 02 — The practice

Who we are, and how we work

PT. Alnair Inovasi Solusindo (ALINDO), founded in 2017, is an Indonesian technology company delivering advanced IT and cybersecurity solutions. Our offensive security practice brings together penetration testers, red team operators, and security analysts who combine deep technical expertise with a disciplined, ethics-first approach.

Our mission

To be a leading cybersecurity partner that empowers organisations to operate with confidence — anticipating adversaries, hardening defences, and turning security into a business enabler rather than an afterthought.

  1. 01

    Delivering realistic, threat-informed security assessments.

  2. 02

    Strengthening our clients' ability to prevent, detect, and respond to attacks.

  3. 03

    Translating technical findings into prioritised, actionable remediation.

  4. 04

    Building long-term security partnerships, not one-off transactions.

  5. 05

    Upholding the highest ethical and legal standards in every engagement.

Core values

The same four values have governed how ALINDO works since 2017.

Innovation
We continuously adopt new approaches and technologies.
Integrity
We act ethically, transparently, and responsibly.
Quality
We deliver reliable, thorough, and actionable results.
Customer-centricity
We put our clients' success and security at the centre.

// 03 — Engagement modes

Three ways in

Which one you need depends on the question you are trying to answer. Most mature programmes eventually run all three.

Mode 01

Internal Red Team

Objective
Assess the effectiveness of internal security measures and controls, focusing on the organisation's network and systems from within.
Scope
An insider's perspective — testing resilience against insider threats or attackers who have already breached the perimeter.
Approach
Simulating attacks and exploitation techniques that mimic the behaviour of an insider threat.
Mode 02

External Red Team

Objective
Assess the organisation's external-facing security measures and defences against potential external threats.
Scope
Evaluates security posture from an external perspective, focusing on the organisation's internet-facing assets.
Approach
Simulating real-world attack scenarios that external threat actors might employ to breach defences.
Mode 03

Assume Breach

Objective
Assess readiness to detect, respond to, and recover from an incident, assuming defences have already been breached.
Scope
Simulate a post-breach environment, focused on incident detection, containment, response, and recovery.
Approach
Operating on the assumption that an attacker has already compromised defences, requiring rapid detection and response.
Shared methodology

Tactics, Techniques & Procedures (TTPs) — every mode is executed against the same threat-informed methodology.

// 04 — Attack lifecycle

Six stages, start to debrief

Red team engagements follow a structured attack lifecycle to simulate real adversary behaviour, identify security gaps, and deliver actionable insight. Stages 3 to 5 are the post-compromise phase — the part that tells you how far an attacker could actually get.

  1. 01

    Initiation

    Initiate and align on engagement objectives, scope, and the Rules of Engagement.

  2. 02

    Initial Access

    Gain a controlled foothold through social engineering or exploitation of an exposed service.

    Recon · Phishing · Exploit

  3. 03

    Lateral Movement & Escalation

    Move across the environment and elevate privileges toward the engagement objective.

    Post-compromise

  4. 04

    Execution & Persistence

    Establish a foothold and maintain presence across reboots and credential changes.

    Post-compromise

  5. 05

    Exfiltration

    Demonstrate extraction of targeted data or files — evidence is minimised and masked.

    Post-compromise

  6. 06

    Evaluation

    Evaluate results, map findings to ATT&CK, and deliver reporting and debrief.

External reconnaissance

  • External footprint profiling
  • Social engineering (phishing, pretexting)
  • Exploiting exposed service vulnerabilities

Internal reconnaissance

  • People assessment — targets & departments
  • Building organisational context
  • Reviewing internal network & Active Directory structure

Privilege levels movement

  • Lateral movement across systems
  • Credential access — obtaining valid credentials
  • Internal enumeration

// 05 — Framework

Mapped to MITRE ATT&CK

ATT&CK is the common standard for globally observed cyberattack patterns. Every finding we report is mapped back to a tactic and technique, so your team can act on it with the same vocabulary your detection tooling already uses.

  • Primary coverage
  • Secondary
  • Contextual
    • TA0043Reconnaissance — contextual coverage
    • TA0042Resource Development — contextual coverage
    • TA0001Initial Access — contextual coverage
    • TA0002Execution — primary coverage
    • TA0003Persistence — primary coverage
    • TA0004Privilege Escalation — secondary coverage
    • TA0005Defense Evasion — secondary coverage
    • TA0006Credential Access — secondary coverage
    • TA0007Discovery — primary coverage
    • TA0008Lateral Movement — contextual coverage
    • TA0009Collection — contextual coverage
    • TA0011Command & Control — contextual coverage
    • TA0010Exfiltration — primary coverage
    • TA0040Impact — primary coverage

Representative techniques we exercise

  • T1595 Active Scanning
  • T1589 Gather Victim Identity Information
  • T1190 Exploit Public-Facing Application
  • T1566 Phishing
  • T1059 Command & Scripting Interpreter
  • T1548 Abuse Elevation Control Mechanism
  • T1543 Create or Modify System Process
  • T1068 Exploitation for Privilege Escalation
  • T1098 Account Manipulation
  • T1547 Boot or Logon Autostart Execution
  • T1003 OS Credential Dumping
  • T1550 Use Alternate Authentication Material
  • T1021 Remote Services
  • T1210 Exploitation of Remote Services
  • T1486 Data Encrypted for Impact

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. Reference: attack.mitre.org. The Cyber Kill Chain® is a registered trademark of Lockheed Martin.

// 06 — Scope of work

40 scenarios across 5 categories

We test the human layer, the technology, and the processes that connect them — so you can strengthen what actually matters. Every scenario below states what is being tested and which control it exercises.

Real-world approach
Simulating genuine attacker behaviours and tactics.
Comprehensive coverage
People, process, and technology all in scope.
Actionable insights
Clear findings and prioritised recommendations.
Stronger resilience
Improve defences and reduce risk exposure.

Showing all 40 scenarios

Cat 01Social Engineering — Phishing

8 scenarios

Tests the human factor and your email and communication controls across multiple remote social-engineering channels.

  • 01

    Mass email phishing (credential harvesting)

    Spoofed IT or HR notification carrying a link to a fake login page, to harvest employee credentials.

    Tests: Employee awareness · Email gateway

  • 02

    Spear phishing & whaling

    Highly personalised email targeting executives or finance managers, impersonating vendors or partners.

    Tests: Executive awareness

  • 03

    Malicious attachment phishing

    Office macro, PDF, or HTM attachment simulating a payroll or compliance document.

    Tests: Anti-malware · EDR / sandbox

  • 04

    Vishing (voice phishing)

    Calling employees while posing as IT helpdesk or a vendor, to request credentials or an MFA bypass.

    Tests: Helpdesk procedure · Awareness

  • 05

    Smishing (SMS phishing)

    SMS carrying malicious links — bank, SaaS, or OTP themed — sent to employee smartphones.

    Tests: Mobile awareness

  • 06

    Quishing (QR code phishing)

    QR codes embedded in emails or printed posters that lead to a malicious page.

    Tests: Awareness · Mobile security

  • 07

    MFA fatigue & adversary-in-the-middle

    Push-prompt bombing, or an AiTM proxy used to capture MFA tokens and live sessions.

    Tests: MFA configuration · Conditional access

  • 08

    Password reset social attack

    Impersonating a locked-out employee to convince the helpdesk to trigger a password reset.

    Tests: Helpdesk identity verification

Cat 02External Attack

8 scenarios

Tests the resilience of your perimeter and internet-accessible assets, approached as an external attacker with no initial access.

  • 01

    Focused OSINT & footprinting

    Gathering public information — domains, IPs, emails, technologies, leaked data — with no direct interaction with your systems.

    Tests: Digital footprint management

  • 02

    Enumeration & port scanning

    Mapping internet-facing assets and the services exposed on them.

    Tests: Attack surface management

  • 03

    Perimeter vulnerability scanning

    Scanning servers, gateways, and public services for known vulnerabilities.

    Tests: Patch management

  • 04

    Web application testing (OWASP Top 10)

    Testing public applications for SQL injection, XSS, IDOR, authentication bypass, and related classes.

    Tests: Secure coding · WAF

  • 05

    DNS & subdomain enumeration

    Discovering subdomains, misconfigurations, and subdomain-takeover conditions.

    Tests: DNS management

  • 06

    Credential & password spraying

    Trying common passwords across many accounts on OWA, VoIP, and VPN endpoints, while deliberately avoiding lockouts.

    Tests: Password policy · MFA

  • 07

    SSL/TLS configuration testing

    Reviewing weak ciphers, deprecated protocols, and expired or misissued certificates.

    Tests: Cryptography & certificate management

  • 08

    Exposed services & misconfigurations

    Finding open backups, exposed configuration files, and directory listings.

    Tests: Web server hardening

Cat 03Internal Attack

10 scenarios

An assumed-breach simulation. The attacker starts with an initial foothold — typically one employee account — and works to escalate access up to full domain control.

  • 01

    Internal network reconnaissance

    Mapping hosts, services, and topology after gaining an internal foothold — shares, firewalls, VPN, servers, and workstations.

    Tests: Segmentation · Monitoring

  • 02

    Active Directory enumeration

    Mapping users, groups, GPOs, trusts, and attack paths through the directory.

    Tests: AD hardening

  • 03

    LLMNR / NBT-NS / mDNS poisoning & NTLM relay

    Capturing credentials and hashes from broadcast name-resolution traffic on the local network.

    Tests: Network hardening

  • 04

    Kerberoasting & AS-REP roasting

    Extracting and cracking Kerberos service tickets offline to obtain usable credentials.

    Tests: Service account password strength

  • 05

    Credential dumping (SAM / LSASS)

    Recovering credentials and hashes from process memory or the registry.

    Tests: EDR · Credential Guard

  • 06

    Pass-the-Hash & Pass-the-Ticket

    Authenticating with captured hashes or tickets, without ever knowing the password.

    Tests: AD hardening · Admin tiering

  • 07

    Privilege escalation (local & domain)

    Exploiting misconfigurations or vulnerabilities to gain higher privileges on a host or across the domain.

    Tests: Hardening · Patching

  • 08

    Lateral movement

    Moving between hosts using discovered credentials and native tooling such as PsExec, WMI, and SMB.

    Tests: Segmentation · Detection

  • 09

    Network share enumeration & access

    Locating sensitive files — contracts, HR, finance — sitting on openly readable SMB and DFS shares.

    Tests: Access control · DLP

  • 10

    Domain Controller / Domain Admin compromise

    Achieving full domain control as the final objective of the simulation.

    Tests: Tiered admin model

Cat 04Wireless Attack

7 scenarios

Tests the security of your wireless infrastructure — corporate and guest WiFi, encryption strength, and segmentation between them.

  • 01

    Reconnaissance & SSID enumeration

    Mapping wireless networks, hidden SSIDs, and signal coverage beyond your premises.

    Tests: WLAN management

  • 02

    Handshake capture & offline cracking (WPA2/WPA3)

    Capturing handshakes, then testing passphrase strength offline without touching the network.

    Tests: Passphrase strength

  • 03

    Evil Twin & rogue access point

    Standing up a fake AP to capture credentials or redirect clients to a malicious page.

    Tests: Wireless IPS (WIPS)

  • 04

    Captive portal testing

    Bypassing the WiFi login page, and assessing whether it exposes user credentials.

    Tests: Awareness · Portal security

  • 05

    Deauthentication attack

    Forcing clients to disconnect and reconnect, in order to trigger handshake capture.

    Tests: 802.11w (PMF)

  • 06

    WPS attack

    Testing WPS PIN weaknesses that allow an attacker to join the network outright.

    Tests: AP configuration

  • 07

    Guest network segmentation testing

    Verifying that the guest WLAN is genuinely isolated from the corporate network.

    Tests: WLAN segmentation

Cat 05Social Engineering (Physical) — Awareness Session

7 topics

Awareness track — not executed against facilities

Category 5 is delivered as an awareness and education session. Physical intrusion techniques are explained and demonstrated conceptually — they are not performed against your buildings, staff, or access controls unless separately scoped and authorised in the Rules of Engagement.

Each topic is taught through real examples: the technique, the red flags to recognise, and the correct response — building lasting behavioural change rather than testing people without their knowledge.

  • 01

    Tailgating & piggybacking

    How attackers follow staff through controlled doors, and the polite refusal scripts that stop it.

    Reinforces: Access control · Staff confidence

  • 02

    Badge cloning & impersonation

    How proximity badges are copied and vendor or contractor identities are faked.

    Reinforces: Badge policy · Visitor verification

  • 03

    Malicious USB & dropped media

    Why a found drive is bait, what it does when plugged in, and what to do with one instead.

    Reinforces: Endpoint policy · USB controls

  • 04

    Pretexting & on-site vishing

    The in-person and telephone pretexts used to extract information, and how to verify identity safely.

    Reinforces: Identity verification procedure

  • 05

    Shoulder surfing & clean desk

    What screens, whiteboards, and left-out documents give away in shared and public spaces.

    Reinforces: Clean-desk policy · Privacy screens

  • 06

    Dumpster diving & document disposal

    How much an organisation reveals through discarded paper, and what secure disposal requires.

    Reinforces: Secure disposal · Shredding policy

  • 07

    Recognise · Respond · Report

    The three-step behavioural model, plus the escalation routes staff should actually use.

    Reinforces: Security culture · Reporting channel

// 07 — Advanced scenarios

When the core five aren't enough

Beyond the core categories, these scenarios are added according to your organisation's needs and security maturity.

  • Full-scope adversary simulation

    An integrated multi-vector campaign — phishing, physical, and internal combined into one continuous operation.

  • Purple teaming

    Red and blue team collaboration to improve detection in real time, tuning rules as the attack runs.

  • ATT&CK-based red teaming

    A campaign built directly from a chosen threat-actor profile, with full TTP mapping and coverage reporting.

  • Cloud security testing

    Azure, AWS, and GCP configuration and identity testing — including Entra ID and IAM privilege paths.

  • Mobile app & endpoint testing

    Employee endpoint and mobile application assessment, plus ransomware readiness and impact simulation — without any real encryption.

  • Insider threat simulation

    Modelling a malicious employee who already holds legitimate access, and what they could reach undetected.

Real-world simulation
Realistic attack behaviours and tactics.
Collaborative approach
Working across your teams and tools.
Improve detection
Validate controls and strengthen response.
Measure continuously
Actionable insight for ongoing improvement.

// 08 — Methodology

Eight phases, every engagement

Our red teaming methodology follows industry best practice to simulate real-world adversaries and deliver insight your team can act on.

  1. Phase 01

    Scoping & Rules of Engagement

    Define objectives, scope, and assumptions — and sign the authorisation.

  2. Phase 02

    Reconnaissance & OSINT

    Build target profiles and map the potential attack surface.

  3. Phase 03

    Initial Access

    Execute phishing or exploitation to gain a controlled foothold.

  4. Phase 04

    Post-Exploitation & Lateral Movement

    Perform internal recon and escalate privileges toward the objective.

  5. Phase 05

    Wireless & Additional Vectors

    Assess wireless and any secondary access scenarios in scope.

  6. Phase 06

    Actions on Objectives

    Demonstrate impact on the crown-jewel objectives agreed at scoping.

  7. Phase 07

    Analysis, Reporting & Debrief

    Consolidate findings, map them to MITRE ATT&CK, and brief both audiences.

  8. Phase 08 · Optional

    Remediation Support & Retest

    Provide guidance, then re-test the priority findings to confirm they are closed.

Best-practice frameworks

Our methodology is aligned with industry-recognised frameworks to ensure comprehensive coverage and measurable results.

  • MITRE ATT&CK
  • NIST SP 800-115
  • OWASP Testing Guide
  • PTES
  • OSSTMM
  • PCI DSS
  • SANS
  • CWE/SANS Top 25

Key principles

We emulate real attackers to uncover what matters most — so you can strengthen your defences with confidence.

  • 01 Adversary mindset
  • 02 Realistic simulation
  • 03 Evidence-driven results
  • 04 Confidential & professional
  • 05 Continuous improvement

// 09 — The team

Why our team is the right choice

Our red team brings a combination of adversarial mindset, technical depth, and disciplined execution — which is what turns an exercise into a security outcome.

  • 01

    Proven offensive security expertise

    Certified operators with hands-on experience across phishing, external, internal / Active Directory, and wireless attack paths.

  • 02

    Threat-informed methodology

    Engagements mapped to MITRE ATT&CK and aligned with PTES, OSSTMM, and NIST, so results reflect real adversary behaviour.

  • 03

    Safety and control first

    Every active scenario runs under a written Rules of Engagement with clear scope, deconfliction, and emergency stop procedures.

  • 04

    Actionable reporting

    Findings delivered with proof-of-concept evidence, business-risk context, and prioritised remediation — not raw tool output.

  • 05

    Partnership beyond the report

    Remediation guidance, retesting, and optional purple-team collaboration to measure and improve detection.

How the team is structured

A Red Team structure focused on real-world attack simulation, identification of critical vulnerabilities, and actionable insight that strengthens your security posture.

Reports to

CISO — Chief Information Security Officer

Engagement owner

Lead Red Team Consultant

  • Security Expert

    Offensive Security

    Runs offensive attack simulations to identify vulnerabilities and security gaps in systems and applications.

  • Security Expert

    Threat Research

    Conducts threat research, analyses emerging attack techniques, and supplies the intelligence behind each operation.

  • Security Expert

    Security Tools & Automation

    Develops and automates tooling and technique to improve the efficiency and consistency of security testing.

// 10 — Governance

Clear rules. Secure collaboration. Measurable outcomes.

These rules exist to reduce risk and protect your organisation throughout the engagement. They are agreed before any active testing begins.

  • 01

    Authorisations & legal

    Written authorisation is required before testing. Scope and exclusions are documented, including compliance with applicable law and the treatment of third-party assets.

  • 02

    Rules of Engagement

    Approved testing windows, prohibited actions, and deconfliction are defined up front — including off-limits systems, emergency procedures, and explicit approval for any destructive action.

  • 03

    Communication & reporting

    A kick-off meeting aligns stakeholders on objectives and governance. Regular status updates run throughout, with immediate escalation for critical findings.

  • 04

    Data handling

    All data is confidential and stored securely. Evidence collection is minimised, sensitive data is masked, and everything is destroyed per the agreed policy on completion.

Targets, domains & locations

Target ranges, domains, and physical exclusions are finalised during scoping and documented in the Rules of Engagement.

Testing windows & hands-off systems

Testing windows and any hands-off systems — production-critical or safety systems, for example — are agreed in advance.

Category 5 boundary

The physical social-engineering track is delivered as an awareness session and is not executed against facilities unless separately scoped and authorised.

Defined scope. Managed risk. Measurable value.

// 11 — Tooling

Tools & technology stack

Engagements are delivered using industry-standard offensive security tooling, operated from a controlled testing platform. Tools are selected per scenario and used only within the agreed scope.

Operating platform
Kali Linux · Parrot OS · specialised containers and virtualisation
Reconnaissance & OSINT
Shodan · Maltego · Google Dorks · theHarvester · Censys.io
Scanning & enumeration
Nmap · Masscan · OpenVAS · Netcat · SNMP tooling
Web application testing
Burp Suite · WPScan · OWASP ZAP
Phishing & social engineering
GoPhish · Evilginx · SMTP testing tools · custom payloads
Password attacks
Hashcat · John the Ripper · custom wordlist spraying
Active Directory & internal
BloodHound · Responder · Impacket · Mimikatz · Ncrack · CrackMapExec
Wireless
Aircrack-ng suite · Kismet · Wifite · Bettercap · Fluxion
C2 & post-exploitation
Metasploit Framework · Cobalt Strike (if authorised) · custom safe-payload beacons
Reporting & collaboration
Encrypted collaboration workspace · evidence vaults · ATT&CK Navigator

Testing is iterative and flexible by design, and all work performed adheres strictly to the agreed Rules of Engagement.

// 12 — Deliverables

What you actually receive

Comprehensive reporting designed for both executive and technical audiences, with clear remediation paths — because a finding nobody can act on is not a finding.

  1. 01

    Executive summary

    A concise, business-focused overview of the engagement, key risks, and overall posture.

  2. 02

    Detailed technical findings

    Each finding documented with description, affected assets, proof-of-concept evidence, and reproduction steps.

  3. 03

    Risk assessment

    Impact and likelihood ratings for every finding, prioritised for remediation.

  4. 04

    Attack narrative & ATT&CK mapping

    The end-to-end attack story, mapped to MITRE ATT&CK techniques.

  5. 05

    Remediation recommendations

    Actionable, prioritised guidance to close each finding and strengthen detection.

Illustrative sample — not client data

Sample red teaming report

Example figures shown to illustrate report structure only.

Findings
47
Critical
8
High
15
Medium
24

COVERAGE: 8 of 14 tactics · 22 techniques observed

These figures are an illustrative example used to show the structure of an Alindo red teaming report. They do not represent the results of any real engagement or client.

Every engagement includes

  • 01 Full Red Team Engagement Report (executive + technical)
  • 02 Attack narrative with MITRE ATT&CK technique mapping
  • 03 Prioritised remediation roadmap
  • 04 Executive and technical debrief sessions
  • 05 Optional retest report confirming remediation of priority findings

Awareness track (Category 5)

Each topic is explained through examples — the red flags to recognise and the correct response — building lasting behavioural change rather than testing facilities directly.

Recognise
Identify social-engineering red flags in daily interactions.
Respond
Apply the correct response to a potential threat.
Report
Escalate suspicious activity through the proper channels.
Build resilience
Strengthen security culture and reduce human risk.

// 13 — Questions

Frequently asked

What is the difference between a penetration test and a red team exercise?

A penetration test aims for breadth — it enumerates as many vulnerabilities as possible in a defined system within a defined window. A red team exercise aims for depth against a goal: reach a specific objective, such as domain control or access to a crown-jewel dataset, using whatever authorised path works. A pen test tells you what is vulnerable; a red team tells you what an adversary could actually achieve, and whether you would notice.

Do you need written authorisation before testing?

Yes, always. No active scenario runs without signed written authorisation and an agreed Rules of Engagement document covering scope, exclusions, testing windows, prohibited actions, deconfliction contacts, and emergency stop procedures. This is not a formality — it is what separates an authorised exercise from a criminal offence, and it protects both sides.

How long does a red team engagement take?

Duration depends on the categories in scope and the size of your estate. Scoping is where this gets settled — the eight-phase methodology runs from Rules of Engagement through to reporting and debrief, with an optional retest afterwards. Get in touch for a scoping call and we will give you a realistic window rather than a generic number.

Will testing disrupt our production systems?

Avoiding disruption is a design goal, not an afterthought. Testing windows and hands-off systems — production-critical and safety systems in particular — are agreed in advance and written into the Rules of Engagement. Destructive actions require explicit separate approval, and an emergency stop procedure is in place for the whole engagement. Ransomware readiness scenarios simulate impact without any real encryption.

What do we receive at the end?

A full engagement report with an executive summary and detailed technical findings, each carrying proof-of-concept evidence and reproduction steps; a risk assessment with impact and likelihood ratings; the end-to-end attack narrative mapped to MITRE ATT&CK; and a prioritised remediation roadmap. Executive and technical debrief sessions are included.

Do you offer purple teaming or retesting?

Both. Purple teaming runs our operators alongside your defenders so detection rules can be tuned while the attack is live — it typically produces more durable improvement than a blind exercise. Retesting is an optional eighth phase: once you have remediated the priority findings, we re-test them and issue a report confirming they are closed.

// Start here

Find out what breaks — before someone else does

Every engagement starts with a scoping call: your objectives, your constraints, and what is genuinely off-limits. No testing happens until that is written down and signed.

Head office
Grand Galaxy City, Jl. Rukan Sentra Niaga 3, Blok RSN 3 No. 12, Jakasetia, Bekasi Selatan 17147