Red Team & Social Engineering
Goal-based attack simulations that combine technical exploitation with phishing and pretexting — testing whether your people and your detection-and-response process would actually catch a real attacker.

Red Team vs. Penetration Test
Penetration Test
Broad, systematic coverage of a defined target — find and document as many exploitable flaws as possible within scope.
Red Team
Narrow, goal-based, and stealthy — achieve one specific objective (e.g. reach the finance database) using whatever combination of technical and human attack vectors gets there, while measuring whether your team detects and responds.
What's In Scope
Phishing Campaigns
Targeted email campaigns measuring click rates, credential submission, and reporting behavior.
Vishing
Phone-based pretexting to test whether staff verify identity before sharing information or access.
Physical & Badge (Optional)
On-site access attempts, tailgating, and badge cloning where explicitly authorized in scope.
Technical Exploitation
Combining a successful phish or vishing result with network and application attack techniques to reach the objective.
Detection & Response Testing
Measures whether your SOC or MDR provider actually detects and responds to the simulated attack.
Purple Team Debrief
A joint session walking your defenders through exactly what we did and what should have triggered an alert.
Fully Authorized, Every Time
Written authorization
Every red team and social engineering engagement runs under a signed scope document naming exactly who authorized it, what's in and out of scope, and a "get out of jail" contact your team can call to verify us in the moment.
No individual blame
Results are reported in aggregate to improve training and process — the goal is a stronger security culture, not naming individual employees who clicked a link.
Red Team Questions
Is phishing our own employees legal?
Yes, when authorized in writing by someone with the authority to approve it on behalf of the organization — which is a required part of every engagement before any simulation begins.
Will individual employees be named in the report?
By default, results are aggregated by team or department. Individual-level detail is only included if you specifically request it.
How is this different from standard pentesting?
See the comparison above — a red team engagement is objective-driven and tests detection and response, not just the existence of vulnerabilities.
Ready to Test Your Detection & Response?
Tell us your objective and we'll design a scoped simulation.