Methodology

A Kill Chain Built on Intelligence

Our engagement methodology mirrors the actual lifecycle of advanced persistent threat actors — from initial reconnaissance through to objective achievement. Every phase is documented, repeatable, and transparent.

  1. 01

    Threat Intelligence & Scoping

    We begin by profiling threat actors relevant to your sector, mapping your external attack surface, and defining engagement objectives aligned to your security program.

  2. 02

    Initial Access

    Using intelligence-driven approaches, we attempt to gain initial foothold through the same vectors an adversary would — phishing, exposed services, supply chain, or physical access.

  3. 03

    Execution & Persistence

    Once inside, we establish persistence using techniques designed to evade modern detection. Every action is logged to the second for evidence and deconfliction.

  4. 04

    Lateral Movement & Escalation

    We navigate your internal environment — escalating privileges, moving laterally, compromising identity infrastructure, and expanding access toward defined objectives.

  5. 05

    Objective Achievement

    We demonstrate impact against pre-agreed objectives: data exfiltration, access to critical systems, ransomware simulation, or business process compromise.

  6. 06

    Reporting & Purple Team

    Every finding is documented with full attack chain evidence. We conduct purple team sessions to walk your defenders through each technique and validate detection capability.

Frameworks

Standards Alignment

MITRE ATT&CK

All TTPs mapped to ATT&CK enterprise framework

TIBER-EU

Compliant with TIBER threat-led testing standards

CBEST

Aligned to UK financial sector red team framework

PTES

Penetration Testing Execution Standard compliance

See it in action

Review our case studies to see how this methodology is applied.

Case Studies