Find the path an attacker would take — before they take it
Guardian's offensive security practice runs scoped penetration tests,
full-scope red team operations and collaborative purple team exercises against the
same infrastructure you defend every day. Every engagement ends with a reproducible
attack path, a prioritised remediation plan and detection content you can deploy.
1,240+Offensive engagements delivered in the last 24 months
94%Of red team operations reached a pre-agreed crown-jewel objective
3.1 daysMedian time from first foothold to domain-wide privilege
61%Of critical findings traced to identity or configuration, not missing patches
Figures drawn from Guardian Offensive Security Group engagement telemetry,
January 2024 – December 2025. Client identities are never disclosed.
Engagement types
Testing that matches the surface you actually run
Scope a single application or commission a multi-month campaign across
the estate. Each engagement type has a fixed methodology, a defined deliverable set
and a named technical lead who stays with you from kickoff to retest.
External network testing
Full enumeration of the internet-facing perimeter: exposed services, forgotten
subdomains, expired certificate hosts, VPN concentrators and edge appliances.
We attempt authenticated pivots wherever credentials are obtained legitimately
during the test window.
Typical duration 5–10 days · Grey box
Internal network testing
Assumed-breach assessment from a standard corporate workstation or a network drop.
Covers Active Directory attack paths, Kerberos abuse, relay and coercion,
certificate services misconfiguration and flat-network lateral movement.
Typical duration 8–15 days · Assumed breach
Web application testing
Manual, business-logic-led testing aligned to the OWASP Testing Guide and ASVS
Level 2. Authenticated multi-role coverage, tenant isolation checks and
server-side request forgery chains against cloud metadata endpoints.
Typical duration 6–12 days · Authenticated
API and microservice testing
Schema-driven testing of REST, GraphQL and gRPC surfaces. Broken object-level
authorisation, mass assignment, token replay, rate-limit bypass and
service-to-service trust abuse inside the mesh.
Typical duration 5–10 days · Spec-informed
Cloud and container review
Configuration review plus live exploitation across AWS, Azure and Google Cloud:
over-permissive roles, cross-account trust, public storage, exposed control planes,
container escape and CI/CD pipeline poisoning.
Typical duration 7–14 days · Hybrid
Mobile application testing
iOS and Android binaries assessed against the OWASP MASVS: local storage exposure,
certificate pinning bypass, jailbreak and root detection resilience, deep-link
abuse and backend API authorisation.
Typical duration 6–10 days · Binary + backend
Social engineering
Targeted phishing, vishing, MFA-fatigue and help-desk pretexting campaigns run
under strict rules of engagement. Measures both human susceptibility and the
technical controls that should have contained the click.
Typical duration 3–8 days · Consent-gated
Physical and wireless
Badge cloning, tailgating, unattended-port access and rogue device placement,
combined with wireless assessment of corporate WPA2/3-Enterprise, guest
segregation and pre-shared-key hygiene.
Typical duration 3–6 days · On-site
OT and ICS assessment
Purdue-model-aware testing of industrial environments. Passive-first discovery,
protocol analysis for Modbus, DNP3 and OPC UA, and safety-reviewed exploitation
limited to levels 3 and above unless explicitly authorised.
Typical duration 10–20 days · Safety-gated
Every engagement is retested at no additional cost.
Remediation verification within 90 days of report delivery is included in the base
fee. You receive an updated report with each finding marked as resolved, partially
resolved or unchanged, suitable for submission to auditors and customers.
Adversarial operations
Red team, purple team and adversary emulation
A penetration test measures exposure. An adversarial operation measures
your ability to notice and respond. Choose the posture that matches your programme's
maturity — or run them in sequence over a twelve-month cycle.
Objective-based, no-notice operations
A small cell of operators works against a written objective —
"obtain and exfiltrate the customer master database", "execute a funds transfer
from the treasury workstation", "gain persistent access to the manufacturing
execution system" — with only your executive sponsor and a designated white cell
aware that the operation is running.
Full attack lifecycle. Initial access is earned, not granted:
phishing, exposed services, third-party trust or physical entry.
Custom tooling. Operators use purpose-built implants and
living-off-the-land tradecraft rather than off-the-shelf frameworks that your
EDR already signatures.
Blue team measurement. Every operator action is timestamped
so detection, triage and containment intervals can be reconstructed exactly.
Deconfliction protocol. A 24/7 channel lets your responders
confirm whether an alert is the red team or a genuine intrusion.
Typical shape: 6–10 weeks, 2–4 operators, one written
objective per 3-week phase.
Operators and defenders in the same room
Purple team engagements drop the secrecy. A Guardian operator
executes a technique, your SOC watches the console, and together you determine
whether the telemetry existed, whether a rule fired, and whether the alert was
actionable. Failures are fixed the same day and re-tested before moving on.
Session format
Two-week sprint: 8–12 techniques executed per day
across a chosen ATT&CK tactic, with a 30-minute tuning block after each block of four.
Deliverable
A signed-off detection matrix showing, per technique,
whether coverage was absent, partial or complete before and after the exercise.
Content you keep
Every rule written during the engagement is handed over
in Sigma and in native Guardian Sentinel detection syntax.
Adversary emulation reproduces the documented tradecraft of a
specific threat group that is known to target your sector. Guardian Labs maintains
emulation plans for 46 tracked groups; each plan is a sequenced list of techniques,
tooling characteristics and infrastructure patterns derived from incident response
casework and public reporting.
Financial services
SILVERCOIL
Financially motivated intrusion set specialising in payment
switch manipulation. Emulation covers help-desk pretexting for MFA reset,
Kerberoasting of service accounts, and staged SWIFT-adjacent host access.
38 techniques · 11 tactics · 4-week plan
Manufacturing & energy
HOLLOWFORGE
State-aligned group targeting IT/OT boundaries. Emulation covers
edge VPN exploitation, historian credential theft, and jump-host abuse to reach
level 2 supervisory systems without touching controllers.
Group names are Guardian Labs designations. Mapping to
public aliases is provided under NDA as part of the engagement brief. Read the latest
tracking notes on the threat intelligence page.
Methodology
Seven phases, documented and repeatable
Guardian's methodology aligns to PTES, the OWASP Testing Guide, NIST SP 800-115
and CREST assessment standards. Nothing about the process is improvised, and nothing
happens outside the authorisation you sign.
Scoping and authorisation
We agree targets, exclusions, testing windows, escalation contacts and the legal
authorisation to test. Third-party hosting providers are notified where their terms
require it. Nothing starts without a countersigned rules-of-engagement document.
Reconnaissance
Passive collection of DNS records, certificate transparency logs, code repositories,
job postings, breach corpora and cloud tenant metadata. The output is an asset
inventory that regularly surprises the client — shadow infrastructure is the
single most common source of external findings.
Enumeration and mapping
Active service discovery, technology fingerprinting and application crawling under
agreed rate limits. Every host is catalogued with its owner, exposure and business
function so that later findings carry real context.
Vulnerability analysis
Automated scanning is used only as an input. Each candidate issue is manually
verified, false positives are discarded, and exploitability is assessed against the
specific configuration in front of us rather than a generic CVE score.
Exploitation
Controlled exploitation to prove impact. Destructive techniques, denial of service
and data modification are excluded by default. Every action is logged with a
timestamp, source address and command transcript.
Post-exploitation and pivoting
Privilege escalation, credential harvesting, lateral movement and access to the
data that matters. We stop at the point where impact is demonstrated — we take a
directory listing, not the database.
Reporting, debrief and retest
Draft report within five working days of test completion, technical debrief within
ten, and a free remediation retest within ninety days. Critical findings are reported
within four hours of discovery, not held back for the report.
Attack path reconstruction
How a finding becomes a narrative
Findings are never presented as an isolated list. Each critical issue
is drawn as the chain of steps that produced it, with the control that should have
broken the chain marked at every hop.
Emulation coverage
What we exercise, tactic by tactic
Every operation is planned and reported against MITRE ATT&CK. This is the
standard coverage set for an enterprise red team engagement; emulation plans for a named
threat group narrow it to that group's observed tradecraft.
Standard coverage set — enterprise red team engagement, ATT&CK v16.
Tactic
Representative techniques exercised
Included in
Techniques
Reconnaissance
Search of open technical databases, certificate transparency mining, victim identity
gathering from public code and job listings
Red team · External test
6
Initial access
Spear-phishing with attachment or link, exploitation of public-facing applications,
valid accounts from credential-stuffing corpora, trusted-relationship abuse
Account manipulation, boot or logon autostart execution, valid cloud accounts,
event-triggered execution, implant via scheduled task
Red team · Purple team
14
Privilege escalation
Abuse of elevation control, exploitation for privilege escalation, domain policy
modification, access token manipulation
Red team · Internal test
12
Defence evasion
Impair defences, indicator removal, masquerading, reflective code loading,
obfuscated files or information
Red team · Purple team
17
Credential access
OS credential dumping, Kerberoasting, adversary-in-the-middle coercion, MFA request
generation, unsecured credentials in repositories
Red team · Internal test
13
Discovery
Domain trust discovery, cloud infrastructure discovery, permission group discovery,
remote system discovery
All engagements
10
Lateral movement
Remote services over SMB and WinRM, pass-the-hash and pass-the-ticket, internal
spear-phishing, taint shared content
Red team · Internal test
8
Collection
Data from information repositories, email collection, screen capture, staged archives
on an intermediary host
Red team
7
Command and control
Application-layer protocol tunnelling, web service C2, domain fronting, encrypted
channel with custom certificate
Red team · Adversary emulation
9
Exfiltration
Exfiltration over C2 channel, over web service, over alternative protocol, with
size-limited transfer to defeat volumetric alerting
Red team · Adversary emulation
6
Impact
Simulated only. Ransomware staging, account access removal and data destruction are
demonstrated in a sandboxed replica, never in production.
Tabletop extension
4
Scroll the table horizontally to see every column.
Techniques marked as simulated are executed in an isolated environment
provisioned by Guardian. See incident response
for full ransomware readiness exercises.
Deliverables
A report your board and your engineers can both use
Two audiences, one document. The first twelve pages are written for people who
approve budget; everything after that is written for the people who will fix the problem,
with enough detail to reproduce each finding without contacting us.
Executive summary
Three pages, written in plain business language. States what an attacker could
achieve, how long it took, which controls worked, and the three changes that would
most reduce risk. Includes a comparison against the previous assessment where one
exists, so a board can see direction of travel rather than a snapshot.
Attack narratives
Each successful chain is documented as a numbered sequence: the action taken, the
observable it produced, the control that should have stopped it, and whether an
alert was generated. Screenshots are redacted of live data but retain enough detail
for your team to locate the same objects.
Technical findings
One page per finding, structured as: identifier, title, severity with the full
CVSS 4.0 vector string, affected assets, business impact, technical detail,
reproduction steps, remediation guidance and references. Findings are written so
that an engineer who was not on the call can act on them alone.
Remediation roadmap
Findings are grouped into fixes rather than listed individually — a single
Active Directory tiering project may close eleven findings at once. Each item is
plotted on an effort-versus-risk-reduction grid with an owner suggestion and a
target date.
Detection content pack
Machine-readable output: indicators of compromise from the operation, Sigma rules
for every technique that went undetected, and ready-to-import
Guardian Sentinel detection logic. Supplied
as JSON and YAML alongside the PDF.
Retest addendum
Delivered after remediation verification. Restates each original finding with a
new status — resolved, partially resolved, risk accepted or unchanged — and is
signed by the engagement lead. Suitable for submission to auditors, insurers and
enterprise customers running vendor assurance.
Formats included in every engagement.
PDF report, editable DOCX, a CSV finding register for your ticketing system, a
board-ready slide deck, and the detection content pack. There is no additional
charge for any deliverable format.
Scoring and triage
How severity is assigned — and what it obliges
Guardian scores every finding with CVSS 4.0 and then adjusts for
environmental reality: an unauthenticated remote code execution on an isolated lab host is
not the same risk as the same bug on a payment gateway. Both scores appear in the report.
Severity bands, disclosure timing and recommended remediation windows.
Severity
CVSS 4.0 base
Disclosed to you
Recommended fix window
Critical
9.0 – 10.0
Within 4 hours of confirmation, by phone
7 days, with compensating control same day
High
7.0 – 8.9
Within 24 hours, in the engagement channel
30 days
Medium
4.0 – 6.9
In the draft report
90 days
Low
0.1 – 3.9
In the draft report
Next planned maintenance cycle
Informational
0.0
In the appendix
Discretionary — hardening opportunities
Aggregate finding profile
Where findings land
Distribution across 340 enterprise engagements completed in 2025.
Most risk sits in the middle bands — and most breaches start there too.
Sample finding register
Extract from a redacted engagement register. Every report ships with this view as CSV.
ID
Finding
Severity
Affected surface
Retest status
GDN-0114
Unauthenticated deserialisation in the partner portal permits remote code execution
Critical
External web application
Resolved
GDN-0118
Certificate template allows subject alternative name specification by any domain user
Critical
Active Directory Certificate Services
Resolved
GDN-0121
Service accounts with SPNs configured use passwords under 20 characters
High
Identity infrastructure
Resolved
GDN-0126
Cross-account IAM role trusts a wildcard principal in the analytics organisation unit
High
AWS production account
Partially resolved
GDN-0133
Object-level authorisation missing on the invoice export endpoint permits tenant crossover
High
Billing API v3
Resolved
GDN-0141
SMB signing not enforced on 214 workstations, enabling NTLM relay
Medium
Corporate workstation fleet
Partially resolved
GDN-0147
Build pipeline secrets readable by all repository collaborators
Medium
CI/CD platform
Resolved
GDN-0152
Verbose error responses disclose framework version and stack traces
Low
Customer web portal
Risk accepted
Scroll the table horizontally to see every column.
The people doing the work
Operators, not scanner operators
The Offensive Security Group is 118 full-time operators across
London, Austin, Singapore and Warsaw. No engagement is subcontracted. Every consultant
holds at least one hands-on practical certification and spends 20% of their year on
internal research that feeds
Guardian Labs intelligence.
CREST-accredited for penetration testing and simulated target attack and response
TIBER-EU and CBEST threat intelligence-led testing experience across 9 jurisdictions
PCI DSS 4.0 qualified for requirement 11.4 segmentation and penetration testing
Cleared personnel available for UK SC, NATO Secret and US public trust engagements
61 published CVEs from internal research in the last three years
OSCE3CRTOOSEPCREST CCTGXPNGPEN
Guardian's red team reached our core banking replica in
nine days using nothing but a helpdesk phone call and a certificate template we had
forgotten about. That was uncomfortable, and it was exactly what we paid for. The
retest four months later took them to day thirty-one without a foothold.
Standard scheduling is four to six weeks from signed statement of work. Retests and
targeted application tests can usually start within ten working days. If you are in an
active incident, contact
incident response instead — that team
mobilises within one hour.
Can you test production systems safely?
Yes, and we do so on the majority of engagements — a test against a staging clone
rarely reflects production identity, network policy or data. Destructive techniques are
excluded by default, rate limits are agreed in advance, and a named engagement lead
is reachable throughout the test window. For OT and safety-critical environments we
run passive discovery first and require sign-off from the process safety owner before
any active step.
Do you provide evidence acceptable to auditors?
The report package is built for assurance use. It includes an attestation letter
naming the tester and their certifications, the scope statement, the methodology
reference, and the retest addendum. Customers routinely submit it for PCI DSS
requirement 11.4, ISO 27001 Annex A 8.8, SOC 2 CC7.1 and DORA threat-led penetration
testing evidence. See compliance advisory
for framework mapping.
Who owns the findings and the data?
You do. Engagement data is held in an isolated, encrypted tenant, is never used to
train models, and is destroyed 90 days after the retest unless you ask us to retain it
for trend analysis. Anonymised technique-level statistics may contribute to aggregate
benchmarks, and never include client names, addresses or asset identifiers. Details
are in trust and security.
Do we need to be a Guardian Sentinel customer?
No. Offensive engagements are sold and delivered independently of the platform, and a
substantial share of our clients run competing tooling. If you do run
Guardian Sentinel, the detection content pack imports
directly and the purple team console shows technique coverage in real time — but that
is a convenience, not a requirement.
How is pricing structured?
Fixed fee per engagement, based on scoped consultant-days. There are no per-host or
per-IP charges, and reporting, debriefs and the 90-day retest are included. Multi-test
annual programmes are discounted and can be drawn down against a prepaid day pool.
See pricing or
talk to the team for an estimate.
Book the attack before someone else runs it
Tell us what you are worried about losing. We will scope an engagement that tries to
take it, and hand you the plan to make that impossible next time.