Skip to content
Pentesys
RTaaS

Objective-basedadversarysimulationagainstyourlivedefences

Intelligence-led red and purple team operations that test whether your people, processes and technology actually detect and respond to a determined attacker.

Mirage AdversaryPowered by Mirage Adversary

Penetration testing asks whether vulnerabilities exist. Red and purple teaming asks a harder question: if a capable adversary targeted you today, would you notice, and could you stop them before they reached what matters?

Our operators run objective-based engagements against agreed crown-jewel targets, emulating a specific threat profile relevant to your sector. Every technique is mapped to MITRE ATT&CK so the output becomes a detection engineering backlog, not just a narrative.

Operation types

Adversary simulation, scaled to your maturity

From a focused assumed-breach exercise to a full intelligence-led operation — we scope the scenario that will teach your defenders the most.

Full-Scope Red Team

A covert, objective-based operation with no prior access, running the complete kill chain against agreed crown jewels.

Assumed Breach

We start from a foothold on the internal network or a compromised identity, focusing effort on lateral movement and detection.

Purple Team Exercise

Operators and defenders work side by side, executing techniques and tuning detections live in a single collaborative session.

Ransomware Readiness

Emulation of a modern ransomware operator up to — but never including — encryption, testing containment and recovery decision-making.

Insider Threat Simulation

A malicious or compromised employee scenario testing data exfiltration paths, DLP controls and privileged access monitoring.

Active Directory Attack Path Review

Focused assessment of AD and Entra ID misconfiguration, delegation abuse and privilege escalation routes to Domain Admin.

Social Engineering Campaign

Targeted phishing, vishing and pretexting designed to obtain access, measuring both human response and technical controls.

Physical Intrusion Testing

Tailgating, badge cloning and on-site network access attempts where physical security forms part of your threat model.

Detection Engineering Validation

Atomic execution of chosen ATT&CK techniques to confirm which of your existing detection rules actually fire.

TIBER / CBEST Aligned Testing

Intelligence-led engagements structured to meet regulated-sector frameworks, with threat intelligence providers and white cell governance.

Capabilities

What's included in Red & Purple Teaming

Everything below is delivered and tracked through the Mirage Portal.

Threat-intelligence-led scenarios

Scenarios built around threat actors that realistically target your sector, from opportunistic ransomware crews to targeted intrusion sets.

Full kill-chain execution

Reconnaissance, initial access, execution, persistence, privilege escalation, lateral movement and objective completion.

MITRE ATT&CK mapping

Every technique executed is recorded against ATT&CK, producing a coverage heatmap of what was and was not detected.

Detection and response metrics

Mean Time to Detect and Mean Time to Respond measured per phase, giving your SOC hard numbers to improve against.

Purple team replay

Optional collaborative replay where operators and defenders work through techniques together to tune detections immediately.

Physical and social vectors

Phishing, vishing, pretexting and physical access testing where in scope, reflecting how real intrusions begin.

Coverage

Scope and depth

Engagement types

  • Full-scope red and purple team operations
  • Assumed-breach assessments
  • Ransomware readiness simulation
  • Insider threat scenarios
  • Collaborative purple team exercises
  • Targeted phishing and social engineering campaigns

What we measure

  • Detection coverage across the ATT&CK matrix
  • Mean Time to Detect and Mean Time to Respond
  • Alert quality, triage accuracy and escalation paths
  • Containment and eradication effectiveness
  • Resilience of segmentation and privilege boundaries
  • Human response under realistic pressure
How it works

Our delivery process

A consistent, transparent methodology from first conversation to verified remediation.

  1. 01

    Objectives

    We agree crown jewels, threat profile, rules of engagement, deconfliction and a white-cell contact.

  2. 02

    Intelligence

    Open-source reconnaissance builds a target picture and identifies realistic entry vectors.

  3. 03

    Execution

    Operators pursue the objective across the kill chain, logging every technique and timestamp.

  4. 04

    Detection review

    We compare our activity log against your telemetry to establish exactly what was seen and when.

  5. 05

    Debrief and uplift

    Joint debrief, detection recommendations and an optional purple team replay to close the gaps.

What you receive

  • Attack narrative with full timeline and evidence
  • ATT&CK coverage heatmap of detected vs missed techniques
  • MTTD and MTTR metrics per attack phase
  • Prioritised detection engineering recommendations
  • Executive debrief for leadership and risk committees

Business outcomes

  • Evidence-based understanding of real-world resilience
  • A concrete detection backlog for your SOC
  • Validated incident response processes and escalation paths
  • Board-level assurance grounded in tested reality
FAQs

Common questions

Will this disrupt production?

No. Rules of engagement, deconfliction procedures and a white-cell contact are agreed up front, and destructive actions are always out of scope unless explicitly authorised.

Should we do this before or after pentesting?

After. Red and purple teaming assumes a reasonable security baseline — if basic vulnerabilities are unaddressed, penetration testing gives better value first.

Can it support TIBER or CBEST style requirements?

Yes. We can structure engagements to align with intelligence-led testing frameworks used in regulated sectors.

Save time and book a call with us

Enterprise-grade penetration testing, built around your business

CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.