Red Teaming
How far can an attacker get inside your organisation?
Multi-vector. Weeks on end. Undetected. We simulate APT attacks - and show you exactly where your defences fail.
Trusted by organisations across industries
- of red teams achieve their objective
- 94%
- median dwell time (Mandiant)
- 11 days
- weeks engagement duration
- 4-8
- freelancers - in-house experts only
- 0
Why organisations need red teaming now
Automated scanners and annual pentests are no longer enough. Modern attackers think in campaigns - your defence should too.
DORA TLPT since January 2025
Articles 26-27 DORA mandate Threat-Led Penetration Testing (TLPT) for significant financial entities every 3 years. TIBER-EU is the approved methodology.
60% start with phishing
More than half of all ransomware incidents in 2024 started with phishing. 33% of employees click on phishing links. A pentest won't find that - a red team will.
74 days to patch
An attacker needs 4 days to move through a network. The median time to patch a critical vulnerability: 74 days. Red teaming shows how attackers exploit this window.
Multi-Vector Attack
Four attack vectors - just like a real APT
A real attacker is not limited to a single channel. Our red team strikes your organisation in a coordinated way across all relevant vectors.
Technical Exploitation
Network exploitation, Active Directory attacks (Kerberoasting, Pass-the-Hash), privilege escalation, custom C2 infrastructure. Fully documented according to MITRE ATT&CK.
Social Engineering
Spear-phishing with personalised pretexts, vishing (telephone attacks against helpdesk/IT), smishing, pretexting. We test whether your employees respond to targeted manipulation.
Physical Security
Attempts to access secured areas, badge cloning (RFID/HID), tailgating, USB drop attacks, dumpster diving. Photo and video documentation available on request.
OSINT & Reconnaissance
What can an attacker find out about you? Employee data, infrastructure leaks, exposed services, GitHub repositories, dark web entries, social media profiles.
Three Engagement Models
We select the right scenario based on your security maturity and objectives.
Full External Attack
Our team receives only the company name. Complete black-box simulation: OSINT, phishing, technical exploitation, physical access - everything an APT actor would do.
4-8 weeks - From EUR 25,000
Assumed Breach
We begin with a compromised foothold (employee account, infected device). Focus on lateral movement, detection capability, and incident response speed.
2-4 weeks - From EUR 15,000
TIBER-EU / DORA TLPT
For regulated financial entities: threat intelligence phase, red team test against live systems, mandatory purple team phase. Reporting to supervisory authorities.
3-6 months - From EUR 50,000
What does a red team engagement cost?
Transparent pricing. Fixed-price quote in 24 hours. No hidden costs.
Assumed Breach
from 15,000 EUR
2-3 weeks
Full External
from 25,000 EUR
4-6 weeks
Full-Scope + Physical
from 40,000 EUR
6-8 weeks
TIBER-EU / TLPT
from 50,000 EUR
3-6 months
Includes purple team debrief, MITRE ATT&CK documentation, and retest of identified vulnerabilities.
Continuous red teaming - quarterly, plannable
Retainer model for organisations that want to continuously test their defences. Includes purple team exercises and ATT&CK coverage tracking.
Cyber Kill Chain
Our red team process
Aligned with the Lockheed Martin Cyber Kill Chain and documented according to MITRE ATT&CK.
Threat Intelligence & Scoping
Analysis of your threat landscape together with the white team. Definition of attack objectives and Rules of Engagement. For TIBER-EU: engagement of a Threat Intelligence Service Provider (TISP).
Reconnaissance & OSINT
Comprehensive passive and active intelligence gathering: social media profiles, LinkedIn scraping, technical infrastructure, DNS enumeration, certificate transparency logs, dark web monitoring, supply chain analysis.
Initial Access
Coordinated attack via the most promising vector: spear-phishing, VPN exploitation, physical access, supply chain compromise. Establishment of a C2 connection.
Lateral Movement & Privilege Escalation
Movement through the network: AD enumeration, Kerberoasting, Pass-the-Hash, exploitation of trust relationships. Objective: Domain Admin or access to defined crown jewels.
Objective Achievement
Proof of access to defined targets: customer database, ERP system, SWIFT access, production control systems. Documented as proof-of-concept - no actual data exfiltration.
Purple Team Debrief & Report
Joint debrief with your blue team. Full disclosure of the attack chain with timestamps. Live replay of techniques in the SIEM. Prioritised recommendations and ATT&CK heatmap.
Red Teaming vs. Pentest vs. Vulnerability Scan
Three disciplines - a maturity ladder. Each has its place.
| Vulnerability Scan | Penetration Test | Red Teaming | |
|---|---|---|---|
| Objective | Find vulnerabilities | Prove exploitability | Test defences |
| Scope | Broad coverage | Defined systems | Entire organisation |
| Vectors | Technical (scanner) | Technical (manual) | Tech + People + Physical |
| Duration | 3-5 days | 1-3 weeks | 4-8 weeks |
| Blue team informed? | Yes | Yes | No |
| Best for | Compliance baseline | All organisations | Mature security teams |
| Regulatory | NIS-2, ISO 27001 | NIS-2, ISO, NIST | TIBER-EU, DORA, KRITIS |
Not sure what you need? We'll figure it out together in a free consultation.
TIBER-EU & DORA TLPT
Threat-Led Penetration Testing for the financial sector
Since January 2025, DORA (Articles 26-27) mandates TLPT for significant financial entities every 3 years. TIBER-EU - developed by the ECB and Deutsche Bundesbank - is the approved methodology. Supervisory authorities receive the closure report.
Threat Intelligence Phase: Targeted Threat Intelligence Report on sector-specific APT actors
Red Team Test Phase: Attack against live production systems based on the TTI report
Purple Team Phase: Joint remediation with the blue team - mandatory under TIBER-EU 2025
Closure Report: Submission to the competent supervisory authority
Red Team Report
See how we document the complete attack chain - with ATT&CK mapping and detection gap analysis.
Request a sample red team report
See an anonymised red team report showing how we document attack chains and identify detection gaps - free and without obligation.
By submitting you agree to our Privacy Policy. No spam - only the requested report.
How far would an attacker get inside your organisation?
Free 30-minute call with our red team. Fixed-price quote in 24 hours.
Kostenlos · 30 Minuten · Unverbindlich
Is red teaming right for you?
Red teaming is the pinnacle of offensive security - but it is not always the right starting point.
Red teaming is the right choice if you...
- +...already operate a SOC, SIEM, or EDR solution
- +...want to know whether your defences can withstand an APT
- +...need to comply with TIBER-EU, DORA, or KRITIS requirements
- +...already run regular pentests and want to take the next step
- +...want to test your incident response team under realistic conditions
Start with a pentest instead if...
- !...you do not yet have a dedicated security team
- !...you have never conducted a penetration test before
- !...your primary goal is a structured vulnerability list
- !...you want to test a single application or system
Legally compliant from the first minute
Red teaming operates at the intersection of IT security and criminal law. We ensure every step is legally authorised.
Signed Rules of Engagement
Before every engagement: written authorisation by a legally authorised representative with clearly defined scope, permitted techniques, and emergency contacts.
Authorised under GDPR & NIS-2
Our authorisation is legitimised as a technical and organisational measure under GDPR Article 32 and NIS-2. Written consents protect against criminal liability.
In-house experts only
No freelancers, no subcontractors. All testers are full-time AWARE7 employees bound by strict NDAs. Data is processed exclusively in Germany.
Why AWARE7 for your red team engagement
What sets us apart from other providers
Pure awareness platforms don't test systems. Pure consulting firms are too far removed. AWARE7 combines both: we hack your infrastructure and train your employees: tailored to mid-sized companies, personal, without enterprise overhead.
Research and teaching as our foundation
20 %Around 20% of our revenue comes from research projects for the BSI and the BMBF. Our studies, published at ACM and Springer conferences, analyse millions of websites and tens of thousands of phishing emails. Three of our executives are professors at German universities at the same time.
Digital sovereignty: no compromises
100 %All data is stored and processed exclusively in Germany, without US cloud providers. All staff are permanently employed, covered by social insurance and bound by uniform legal obligations.
Fixed price within 24h: predictable project timelines
24 hWithin 24 hours you receive a binding fixed-price quote without hourly rate risk. A well-practised team and standardised processes ensure a clear schedule with a defined start and end date.
Your dedicated contact
1:1A personal project manager accompanies you from the first meeting to the retest. You book appointments directly with your contact person and keep the same contact throughout the project.
Peer-reviewed publications
Different Seas, Different Phishes - Large-Scale Analysis of Phishing Simulations
ACM AsiaCCS 2025
Oskar Braun, Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
A Platform for Physiological and Behavioral Security
NSPW 2025
Jan Hörnemann
Privacy from 5 PM to 6 AM: Tracking and Transparency in the HbbTV Ecosystem
IEEE/IFIP DSN 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Understanding Regional Filter Lists: Efficacy and Impact
PoPETS 2025
Jan Hörnemann, Norbert Pohlmann, Matteo Große-Kampmann
Who is AWARE7 the right partner for?
Mid-sized companies with 50-2,000 employees
Companies that need real security, without paying for a DAX-corporation provider. Fixed price, clear scope, one point of contact.
IT managers & CISOs
Who have to argue convincingly in-house and need a report in boardroom language for that, not just technical findings.
Regulated industries
Critical infrastructure, healthcare, financial services: NIS-2, ISO 27001, DORA. We know the requirements and deliver evidence that auditors accept.
References
Client references
These case studies are available in German.
Security is also social responsibility
AWARE7 is committed beyond day-to-day business: as the founder of a scholarship at Ruhr University Bochum, we support the next generation of cybersecurity professionals. We are a member of the BSI Alliance for Cyber Security and train our own specialists. Our R&D certificate confirms our commitment to cybersecurity research and innovation.
Learn more about AWARE7Frequently asked questions about red teaming
How does red teaming differ from a penetration test?
How long does a red team engagement take?
Does our IT or security team know about the engagement?
Is red teaming relevant for mid-market companies?
What does a red team engagement cost?
Which frameworks do you use?
What is an assumed breach scenario?
What happens during the purple team debrief?
Is red teaming required for NIS-2 compliance?
How do you ensure legal compliance?
Do you offer TIBER-EU/TIBER-DE and DORA TLPT for the financial sector?
Three steps to a red team engagement
No lengthy procurement process. You speak with us - and we get started.
Initial consultation
30 minutes, free of charge. We define attack objectives, scope, and terms.
Fixed-price quote in 24h
Binding, transparent, no hidden costs. Includes Rules of Engagement.
Red team begins
Our team starts reconnaissance. Your blue team knows nothing.
Aus dem Blog
Weiterführende Artikel
Active Directory Red Team: Kerberoasting, Golden Ticket und DCSync
AD-Angriffe aus Pentester-Sicht: Kerberoasting, Golden Ticket, DCSync und BloodHound - mit Schutzmaßnahmen für jeden Angriffsvektor.
LLM Security: Prompt Injection, Jailbreaking und KI-Red-Teaming
LLM Red Teaming: Prompt Injection, Jailbreaking, Training-Data-Poisoning und OWASP Top 10 for LLM Applications - mit Defense-Strategien.
Lateral Movement erkennen und stoppen: Angreifer im Netzwerk abfangen
Lateral Movement erkennen: Pass-the-Hash, Kerberoasting, PsExec und WMI - SIEM-Erkennungsregeln und Präventionsmaßnahmen nach dem Initial Access.
Ready for the ultimate test?
94% of all red teams achieve their objective. Test your defences before a real attacker does.
Kostenlos · 30 Minuten · Unverbindlich