Full-Scope Red Team
A covert, objective-based operation with no prior access, running the complete kill chain against agreed crown jewels.
Intelligence-led red and purple team operations that test whether your people, processes and technology actually detect and respond to a determined attacker.
Powered by Mirage AdversaryPenetration testing asks whether vulnerabilities exist. Red and purple teaming asks a harder question: if a capable adversary targeted you today, would you notice, and could you stop them before they reached what matters?
Our operators run objective-based engagements against agreed crown-jewel targets, emulating a specific threat profile relevant to your sector. Every technique is mapped to MITRE ATT&CK so the output becomes a detection engineering backlog, not just a narrative.
From a focused assumed-breach exercise to a full intelligence-led operation — we scope the scenario that will teach your defenders the most.
A covert, objective-based operation with no prior access, running the complete kill chain against agreed crown jewels.
We start from a foothold on the internal network or a compromised identity, focusing effort on lateral movement and detection.
Operators and defenders work side by side, executing techniques and tuning detections live in a single collaborative session.
Emulation of a modern ransomware operator up to — but never including — encryption, testing containment and recovery decision-making.
A malicious or compromised employee scenario testing data exfiltration paths, DLP controls and privileged access monitoring.
Focused assessment of AD and Entra ID misconfiguration, delegation abuse and privilege escalation routes to Domain Admin.
Targeted phishing, vishing and pretexting designed to obtain access, measuring both human response and technical controls.
Tailgating, badge cloning and on-site network access attempts where physical security forms part of your threat model.
Atomic execution of chosen ATT&CK techniques to confirm which of your existing detection rules actually fire.
Intelligence-led engagements structured to meet regulated-sector frameworks, with threat intelligence providers and white cell governance.
Everything below is delivered and tracked through the Mirage Portal.
Scenarios built around threat actors that realistically target your sector, from opportunistic ransomware crews to targeted intrusion sets.
Reconnaissance, initial access, execution, persistence, privilege escalation, lateral movement and objective completion.
Every technique executed is recorded against ATT&CK, producing a coverage heatmap of what was and was not detected.
Mean Time to Detect and Mean Time to Respond measured per phase, giving your SOC hard numbers to improve against.
Optional collaborative replay where operators and defenders work through techniques together to tune detections immediately.
Phishing, vishing, pretexting and physical access testing where in scope, reflecting how real intrusions begin.
A consistent, transparent methodology from first conversation to verified remediation.
We agree crown jewels, threat profile, rules of engagement, deconfliction and a white-cell contact.
Open-source reconnaissance builds a target picture and identifies realistic entry vectors.
Operators pursue the objective across the kill chain, logging every technique and timestamp.
We compare our activity log against your telemetry to establish exactly what was seen and when.
Joint debrief, detection recommendations and an optional purple team replay to close the gaps.
No. Rules of engagement, deconfliction procedures and a white-cell contact are agreed up front, and destructive actions are always out of scope unless explicitly authorised.
After. Red and purple teaming assumes a reasonable security baseline — if basic vulnerabilities are unaddressed, penetration testing gives better value first.
Yes. We can structure engagements to align with intelligence-led testing frameworks used in regulated sectors.
CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.