Guardian Offensive Security Group

Find the path an attacker would take — before they take it

Guardian's offensive security practice runs scoped penetration tests, full-scope red team operations and collaborative purple team exercises against the same infrastructure you defend every day. Every engagement ends with a reproducible attack path, a prioritised remediation plan and detection content you can deploy.

1,240+ Offensive engagements delivered in the last 24 months
94% Of red team operations reached a pre-agreed crown-jewel objective
3.1 days Median time from first foothold to domain-wide privilege
61% Of critical findings traced to identity or configuration, not missing patches

Figures drawn from Guardian Offensive Security Group engagement telemetry, January 2024 – December 2025. Client identities are never disclosed.

Engagement types

Testing that matches the surface you actually run

Scope a single application or commission a multi-month campaign across the estate. Each engagement type has a fixed methodology, a defined deliverable set and a named technical lead who stays with you from kickoff to retest.

External network testing

Full enumeration of the internet-facing perimeter: exposed services, forgotten subdomains, expired certificate hosts, VPN concentrators and edge appliances. We attempt authenticated pivots wherever credentials are obtained legitimately during the test window.

Typical duration 5–10 days · Grey box

Internal network testing

Assumed-breach assessment from a standard corporate workstation or a network drop. Covers Active Directory attack paths, Kerberos abuse, relay and coercion, certificate services misconfiguration and flat-network lateral movement.

Typical duration 8–15 days · Assumed breach

Web application testing

Manual, business-logic-led testing aligned to the OWASP Testing Guide and ASVS Level 2. Authenticated multi-role coverage, tenant isolation checks and server-side request forgery chains against cloud metadata endpoints.

Typical duration 6–12 days · Authenticated

API and microservice testing

Schema-driven testing of REST, GraphQL and gRPC surfaces. Broken object-level authorisation, mass assignment, token replay, rate-limit bypass and service-to-service trust abuse inside the mesh.

Typical duration 5–10 days · Spec-informed

Cloud and container review

Configuration review plus live exploitation across AWS, Azure and Google Cloud: over-permissive roles, cross-account trust, public storage, exposed control planes, container escape and CI/CD pipeline poisoning.

Typical duration 7–14 days · Hybrid

Mobile application testing

iOS and Android binaries assessed against the OWASP MASVS: local storage exposure, certificate pinning bypass, jailbreak and root detection resilience, deep-link abuse and backend API authorisation.

Typical duration 6–10 days · Binary + backend

Social engineering

Targeted phishing, vishing, MFA-fatigue and help-desk pretexting campaigns run under strict rules of engagement. Measures both human susceptibility and the technical controls that should have contained the click.

Typical duration 3–8 days · Consent-gated

Physical and wireless

Badge cloning, tailgating, unattended-port access and rogue device placement, combined with wireless assessment of corporate WPA2/3-Enterprise, guest segregation and pre-shared-key hygiene.

Typical duration 3–6 days · On-site

OT and ICS assessment

Purdue-model-aware testing of industrial environments. Passive-first discovery, protocol analysis for Modbus, DNP3 and OPC UA, and safety-reviewed exploitation limited to levels 3 and above unless explicitly authorised.

Typical duration 10–20 days · Safety-gated

Every engagement is retested at no additional cost. Remediation verification within 90 days of report delivery is included in the base fee. You receive an updated report with each finding marked as resolved, partially resolved or unchanged, suitable for submission to auditors and customers.

Adversarial operations

Red team, purple team and adversary emulation

A penetration test measures exposure. An adversarial operation measures your ability to notice and respond. Choose the posture that matches your programme's maturity — or run them in sequence over a twelve-month cycle.

Objective-based, no-notice operations

A small cell of operators works against a written objective — "obtain and exfiltrate the customer master database", "execute a funds transfer from the treasury workstation", "gain persistent access to the manufacturing execution system" — with only your executive sponsor and a designated white cell aware that the operation is running.

  • Full attack lifecycle. Initial access is earned, not granted: phishing, exposed services, third-party trust or physical entry.
  • Custom tooling. Operators use purpose-built implants and living-off-the-land tradecraft rather than off-the-shelf frameworks that your EDR already signatures.
  • Blue team measurement. Every operator action is timestamped so detection, triage and containment intervals can be reconstructed exactly.
  • Deconfliction protocol. A 24/7 channel lets your responders confirm whether an alert is the red team or a genuine intrusion.

Typical shape: 6–10 weeks, 2–4 operators, one written objective per 3-week phase.

Detection coverage +38% typical 01 · Emulate Execute a known technique 02 · Observe Check telemetry 03 · Tune Write or fix the rule 04 · Validate Re-run and confirm

Operators and defenders in the same room

Purple team engagements drop the secrecy. A Guardian operator executes a technique, your SOC watches the console, and together you determine whether the telemetry existed, whether a rule fired, and whether the alert was actionable. Failures are fixed the same day and re-tested before moving on.

Session format

Two-week sprint: 8–12 techniques executed per day across a chosen ATT&CK tactic, with a 30-minute tuning block after each block of four.

Deliverable

A signed-off detection matrix showing, per technique, whether coverage was absent, partial or complete before and after the exercise.

Content you keep

Every rule written during the engagement is handed over in Sigma and in native Guardian Sentinel detection syntax.

Best paired with

Managed detection and response, so tuned content is monitored by the same analysts who will triage it in production.

Replaying a named adversary against your estate

Adversary emulation reproduces the documented tradecraft of a specific threat group that is known to target your sector. Guardian Labs maintains emulation plans for 46 tracked groups; each plan is a sequenced list of techniques, tooling characteristics and infrastructure patterns derived from incident response casework and public reporting.

Financial services

SILVERCOIL

Financially motivated intrusion set specialising in payment switch manipulation. Emulation covers help-desk pretexting for MFA reset, Kerberoasting of service accounts, and staged SWIFT-adjacent host access.

38 techniques · 11 tactics · 4-week plan

Manufacturing & energy

HOLLOWFORGE

State-aligned group targeting IT/OT boundaries. Emulation covers edge VPN exploitation, historian credential theft, and jump-host abuse to reach level 2 supervisory systems without touching controllers.

31 techniques · 9 tactics · 5-week plan

Technology & SaaS

PALE MERIDIAN

Supply-chain-focused actor. Emulation covers CI/CD token theft, malicious build-step injection, package registry impersonation and downstream tenant access through OAuth application consent.

27 techniques · 8 tactics · 3-week plan

Group names are Guardian Labs designations. Mapping to public aliases is provided under NDA as part of the engagement brief. Read the latest tracking notes on the threat intelligence page.

Methodology

Seven phases, documented and repeatable

Guardian's methodology aligns to PTES, the OWASP Testing Guide, NIST SP 800-115 and CREST assessment standards. Nothing about the process is improvised, and nothing happens outside the authorisation you sign.

Scoping and authorisation

We agree targets, exclusions, testing windows, escalation contacts and the legal authorisation to test. Third-party hosting providers are notified where their terms require it. Nothing starts without a countersigned rules-of-engagement document.

Reconnaissance

Passive collection of DNS records, certificate transparency logs, code repositories, job postings, breach corpora and cloud tenant metadata. The output is an asset inventory that regularly surprises the client — shadow infrastructure is the single most common source of external findings.

Enumeration and mapping

Active service discovery, technology fingerprinting and application crawling under agreed rate limits. Every host is catalogued with its owner, exposure and business function so that later findings carry real context.

Vulnerability analysis

Automated scanning is used only as an input. Each candidate issue is manually verified, false positives are discarded, and exploitability is assessed against the specific configuration in front of us rather than a generic CVE score.

Exploitation

Controlled exploitation to prove impact. Destructive techniques, denial of service and data modification are excluded by default. Every action is logged with a timestamp, source address and command transcript.

Post-exploitation and pivoting

Privilege escalation, credential harvesting, lateral movement and access to the data that matters. We stop at the point where impact is demonstrated — we take a directory listing, not the database.

Reporting, debrief and retest

Draft report within five working days of test completion, technical debrief within ten, and a free remediation retest within ninety days. Critical findings are reported within four hours of discovery, not held back for the report.

Attack path reconstruction

How a finding becomes a narrative

Findings are never presented as an isolated list. Each critical issue is drawn as the chain of steps that produced it, with the control that should have broken the chain marked at every hop.

ATTACKER PATH Exposed VPN edge CVE-2025-31184 Session token theft T1550.001 Service account SPN T1558.003 Lateral to file cluster T1021.002 Certificate template abuse ESC1 Domain compromise Objective CONTROL THAT BREAKS THE LINK Patch SLA Edge devices within 72 h Token binding Device-bound session cookies gMSA Managed service accounts only Segmentation Deny SMB between workstation tiers AD CS hardening Remove SAN enrolment right Tiered admin No tier-0 logon below tier-0 Illustrative chain from a 2025 financial services engagement. Technique IDs reference MITRE ATT&CK v16.

Emulation coverage

What we exercise, tactic by tactic

Every operation is planned and reported against MITRE ATT&CK. This is the standard coverage set for an enterprise red team engagement; emulation plans for a named threat group narrow it to that group's observed tradecraft.

Standard coverage set — enterprise red team engagement, ATT&CK v16.
Tactic Representative techniques exercised Included in Techniques
Reconnaissance Search of open technical databases, certificate transparency mining, victim identity gathering from public code and job listings Red team · External test 6
Initial access Spear-phishing with attachment or link, exploitation of public-facing applications, valid accounts from credential-stuffing corpora, trusted-relationship abuse Red team · Social engineering 9
Execution Command and scripting interpreters, container administration commands, scheduled task execution, user-executed malicious file Red team · Purple team 11
Persistence Account manipulation, boot or logon autostart execution, valid cloud accounts, event-triggered execution, implant via scheduled task Red team · Purple team 14
Privilege escalation Abuse of elevation control, exploitation for privilege escalation, domain policy modification, access token manipulation Red team · Internal test 12
Defence evasion Impair defences, indicator removal, masquerading, reflective code loading, obfuscated files or information Red team · Purple team 17
Credential access OS credential dumping, Kerberoasting, adversary-in-the-middle coercion, MFA request generation, unsecured credentials in repositories Red team · Internal test 13
Discovery Domain trust discovery, cloud infrastructure discovery, permission group discovery, remote system discovery All engagements 10
Lateral movement Remote services over SMB and WinRM, pass-the-hash and pass-the-ticket, internal spear-phishing, taint shared content Red team · Internal test 8
Collection Data from information repositories, email collection, screen capture, staged archives on an intermediary host Red team 7
Command and control Application-layer protocol tunnelling, web service C2, domain fronting, encrypted channel with custom certificate Red team · Adversary emulation 9
Exfiltration Exfiltration over C2 channel, over web service, over alternative protocol, with size-limited transfer to defeat volumetric alerting Red team · Adversary emulation 6
Impact Simulated only. Ransomware staging, account access removal and data destruction are demonstrated in a sandboxed replica, never in production. Tabletop extension 4

Scroll the table horizontally to see every column.

Techniques marked as simulated are executed in an isolated environment provisioned by Guardian. See incident response for full ransomware readiness exercises.

Deliverables

A report your board and your engineers can both use

Two audiences, one document. The first twelve pages are written for people who approve budget; everything after that is written for the people who will fix the problem, with enough detail to reproduce each finding without contacting us.

01 · Executive summary Business risk, 3 pages, no jargon 02 · Scope & authorisation Targets, exclusions, test window, signatories 03 · Risk posture & trend Severity distribution vs. previous assessment 04 · Attack narratives Each chain, step by step, with screenshots 05 · Technical findings Evidence, CVSS 4.0 vector, reproduction steps 06 · Remediation roadmap Sequenced by effort against risk reduction 07 · Appendices Tooling, IOCs, host inventory, detection content
Executive summary

Three pages, written in plain business language. States what an attacker could achieve, how long it took, which controls worked, and the three changes that would most reduce risk. Includes a comparison against the previous assessment where one exists, so a board can see direction of travel rather than a snapshot.

Attack narratives

Each successful chain is documented as a numbered sequence: the action taken, the observable it produced, the control that should have stopped it, and whether an alert was generated. Screenshots are redacted of live data but retain enough detail for your team to locate the same objects.

Technical findings

One page per finding, structured as: identifier, title, severity with the full CVSS 4.0 vector string, affected assets, business impact, technical detail, reproduction steps, remediation guidance and references. Findings are written so that an engineer who was not on the call can act on them alone.

Remediation roadmap

Findings are grouped into fixes rather than listed individually — a single Active Directory tiering project may close eleven findings at once. Each item is plotted on an effort-versus-risk-reduction grid with an owner suggestion and a target date.

Detection content pack

Machine-readable output: indicators of compromise from the operation, Sigma rules for every technique that went undetected, and ready-to-import Guardian Sentinel detection logic. Supplied as JSON and YAML alongside the PDF.

Retest addendum

Delivered after remediation verification. Restates each original finding with a new status — resolved, partially resolved, risk accepted or unchanged — and is signed by the engagement lead. Suitable for submission to auditors, insurers and enterprise customers running vendor assurance.

Formats included in every engagement. PDF report, editable DOCX, a CSV finding register for your ticketing system, a board-ready slide deck, and the detection content pack. There is no additional charge for any deliverable format.

Scoring and triage

How severity is assigned — and what it obliges

Guardian scores every finding with CVSS 4.0 and then adjusts for environmental reality: an unauthenticated remote code execution on an isolated lab host is not the same risk as the same bug on a payment gateway. Both scores appear in the report.

Severity bands, disclosure timing and recommended remediation windows.
Severity CVSS 4.0 base Disclosed to you Recommended fix window
Critical 9.0 – 10.0 Within 4 hours of confirmation, by phone 7 days, with compensating control same day
High 7.0 – 8.9 Within 24 hours, in the engagement channel 30 days
Medium 4.0 – 6.9 In the draft report 90 days
Low 0.1 – 3.9 In the draft report Next planned maintenance cycle
Informational 0.0 In the appendix Discretionary — hardening opportunities

Aggregate finding profile

Where findings land

Distribution across 340 enterprise engagements completed in 2025. Most risk sits in the middle bands — and most breaches start there too.

0% 12% 24% 36% 48% 4% 17% 41% 26% 12% Critical High Medium Low Info n = 340 engagements · 9,118 findings · Guardian Offensive Security Group, 2025

Sample finding register

Extract from a redacted engagement register. Every report ships with this view as CSV.
ID Finding Severity Affected surface Retest status
GDN-0114 Unauthenticated deserialisation in the partner portal permits remote code execution Critical External web application Resolved
GDN-0118 Certificate template allows subject alternative name specification by any domain user Critical Active Directory Certificate Services Resolved
GDN-0121 Service accounts with SPNs configured use passwords under 20 characters High Identity infrastructure Resolved
GDN-0126 Cross-account IAM role trusts a wildcard principal in the analytics organisation unit High AWS production account Partially resolved
GDN-0133 Object-level authorisation missing on the invoice export endpoint permits tenant crossover High Billing API v3 Resolved
GDN-0141 SMB signing not enforced on 214 workstations, enabling NTLM relay Medium Corporate workstation fleet Partially resolved
GDN-0147 Build pipeline secrets readable by all repository collaborators Medium CI/CD platform Resolved
GDN-0152 Verbose error responses disclose framework version and stack traces Low Customer web portal Risk accepted

Scroll the table horizontally to see every column.

The people doing the work

Operators, not scanner operators

The Offensive Security Group is 118 full-time operators across London, Austin, Singapore and Warsaw. No engagement is subcontracted. Every consultant holds at least one hands-on practical certification and spends 20% of their year on internal research that feeds Guardian Labs intelligence.

  • CREST-accredited for penetration testing and simulated target attack and response
  • TIBER-EU and CBEST threat intelligence-led testing experience across 9 jurisdictions
  • PCI DSS 4.0 qualified for requirement 11.4 segmentation and penetration testing
  • Cleared personnel available for UK SC, NATO Secret and US public trust engagements
  • 61 published CVEs from internal research in the last three years
OSCE3 CRTO OSEP CREST CCT GXPN GPEN

Guardian's red team reached our core banking replica in nine days using nothing but a helpdesk phone call and a certificate template we had forgotten about. That was uncomfortable, and it was exactly what we paid for. The retest four months later took them to day thirty-one without a foothold.

Marta Hollis

Group CISO, Northbridge Financial

9 days To objective on the first operation
31+ Days to objective on the follow-up operation

Read the full account in customer case studies, or see how the same findings feed a longer programme in security consulting.

Common questions

Before you scope an engagement

How much notice do you need to start?

Standard scheduling is four to six weeks from signed statement of work. Retests and targeted application tests can usually start within ten working days. If you are in an active incident, contact incident response instead — that team mobilises within one hour.

Can you test production systems safely?

Yes, and we do so on the majority of engagements — a test against a staging clone rarely reflects production identity, network policy or data. Destructive techniques are excluded by default, rate limits are agreed in advance, and a named engagement lead is reachable throughout the test window. For OT and safety-critical environments we run passive discovery first and require sign-off from the process safety owner before any active step.

Do you provide evidence acceptable to auditors?

The report package is built for assurance use. It includes an attestation letter naming the tester and their certifications, the scope statement, the methodology reference, and the retest addendum. Customers routinely submit it for PCI DSS requirement 11.4, ISO 27001 Annex A 8.8, SOC 2 CC7.1 and DORA threat-led penetration testing evidence. See compliance advisory for framework mapping.

Who owns the findings and the data?

You do. Engagement data is held in an isolated, encrypted tenant, is never used to train models, and is destroyed 90 days after the retest unless you ask us to retain it for trend analysis. Anonymised technique-level statistics may contribute to aggregate benchmarks, and never include client names, addresses or asset identifiers. Details are in trust and security.

Do we need to be a Guardian Sentinel customer?

No. Offensive engagements are sold and delivered independently of the platform, and a substantial share of our clients run competing tooling. If you do run Guardian Sentinel, the detection content pack imports directly and the purple team console shows technique coverage in real time — but that is a convenience, not a requirement.

How is pricing structured?

Fixed fee per engagement, based on scoped consultant-days. There are no per-host or per-IP charges, and reporting, debriefs and the 90-day retest are included. Multi-test annual programmes are discounted and can be drawn down against a prepaid day pool. See pricing or talk to the team for an estimate.

Book the attack before someone else runs it

Tell us what you are worried about losing. We will scope an engagement that tries to take it, and hand you the plan to make that impossible next time.