RINP // CYBERSECURITY SERVICES
Red Team · Modular Scenario ValidationWe verify the attack path to a critical asset and the detection gaps in your defenses.
We design each Red Team engagement around a critical asset and a defined threat scenario. We run the attack path under controlled testing and record which steps your defenses catch and miss. The executive summary and the technical report present the chain-breaking controls within a single risk picture.
- The attack path to a critical asset is verified within an approved scenario and defined rules of engagement.
- The steps your defenses catch and miss are documented in a detection gap matrix.
- Chain-breaking controls are prioritized by business impact and feasibility.
3 modules
- 01
Threat-Actor Simulation
TTP-based scenario (RT-1)
- 02
Goal-Driven Red Team
Crown-jewel objective (RT-2)
- 03
Assumed-Breach Simulation
Attacker-inside hypothesis (RT-3)
Controlled execution · attacker's eye
What this service is, and is not
- It tests the threat scenario under controlled conditions along an end-to-end attack path to a critical asset.
- It documents the attack steps with technical evidence and a timeline, and the detection gaps through MITRE ATT&CK mapping.
- It grounds the executive summary, the technical report, and the chain-breaking control plan in the same verified scenario.
- Not a scenario version of the Network Security Penetration Test; network-surface exposure opens a different decision moment.
- Not a flashy version of Continuous Penetration Testing; a managed periodic program and controlled threat-scenario execution are separate decisions.
- Not a reach-guaranteed exercise, DoS/destructive test, real data exfiltration, persistence or unauthorized third-party action; it runs within written authority, rules of engagement and stop criteria.
Scope and boundaries
- Scenario design along the Threat-Actor Simulation, Goal-Driven Red Team or Assumed-Breach Simulation axis
- Controlled execution within written authority, rules of engagement (RoE), stop criteria and approval gates
- Attack-path evidence pack: timeline, technical trace and reproducible evidence
- Detection-gap matrix: ATT&CK-aligned control visibility and defense records
- Chain-breaking control recommendations and a fix-verify work list (owned, ordered)
- Executive summary: decision sentence, risk narrative and the first remediation priority
- Technical closure assessment and an optional Purple Team scenario-replay sprint
- Decision support for management + an actionable work list for the technical team (two-layer delivery)
- DoS, stress, capacity or destructive test simulation
- Persistence, real malware or real data exfiltration
- Social engineering or physical action without written approval
- Unauthorized third-party systems and forensic/surveillance-type activity
- Automatic catalog scope of regulated frameworks such as TIBER / BEST / CBEST
- A reach or breach guarantee; scope, method and deliverable are guaranteed
- An expectation of a pentest report or a vulnerability list only
- Written authorization, rules of engagement, stop criteria and an emergency line are approved.
- The in-scope environment, starting assumption (assisted, gray-box or black-box) and test window are defined.
- Read-only access for SIEM, EDR and log observation, with critical-asset and critical-business-goal definitions, is shared.
- If a human-layer initial-access or physical-entry package is used, extra written authority and human oversight are provided.
- The starting price is an approximate budget; the final proposal narrows once RoE, critical assets, telemetry and the environment reality are clear.
- Written authorization and rules-of-engagement (RoE) approval
- Critical-asset definition and in-scope environment family (on-prem, cloud, SaaS, hybrid)
- Starting assumption (assisted, gray-box or black-box) and the test window
- Emergency-stop contacts, read-only access for SIEM/EDR/log observation and a technical contact
- Optional: extra permissions for human-layer and physical-entry packages, reporting language, regulated-framework info (TIBER/BEST/CBEST), previous Red Team reports
Every engagement runs under written authority with stop criteria and an escalation line. See Rules of Engagement.
How we work: six steps from scenario to control validation
Scope & rules of engagement
Written authorization, rules of engagement (RoE), stop criteria, an emergency line, the in-scope environment, critical-asset definition and the test window are defined; the starting view and risk map are drawn.
Module & scenario design
The right module is chosen along the threat-actor, crown-jewel or assumed-breach axis (Threat-Actor Simulation, Goal-Driven Red Team or Assumed-Breach Simulation); the scenario is designed with the business goal, starting assumption and approval gates.
Controlled execution
Access, telemetry and stop controls are brought online; the scenario is executed within approved scope, human oversight and side-effect control; high-impact actions require written approval.
Attack-path packaging & evidence
We consolidate the verified steps leading to the critical asset in an attack path report, with technical traces, a timeline, and safely handled evidence.
Detection-gap matrix & fix-verify work list
We map the steps your defenses caught and missed in an ATT&CK-aligned matrix and rank the chain-breaking controls with owner and priority.
Delivery and post-remediation retest
We deliver the executive summary and the technical report; once the client applies the controls, we run a retest or a Purple Team engagement within the appropriate scope.
What we deliver
Executive summary
- Attack path summary: explains whether the critical asset was reached and describes the business impact.
- Control priorities: rank the steps that would break the attack chain.
- Management decision note: a short summary supporting management-level ownership of the chain-breaking control recommendations.
Technical report and attack records
- Attack path report: includes the timeline, technical traces, and reproducible steps.
- Detection gap matrix: maps the steps your defenses caught and missed to MITRE ATT&CK.
- Remediation plan: ranks the chain-breaking controls with owner and priority.
- Fix-verify work list: owned, ordered; ready for fix validation.
Optional outputs
- Purple Team sprint or BAS / CCV scenario-replay sprint: detection-rule revision and control validation.
- Human-layer initial-access or physical-entry package report: delivered as a separate line if an extra vector is added to the scenario.
- Management workshop, accelerated delivery or bilingual reporting: priced as a separate line when needed.
Management sees the attack path that reached the critical asset and its business impact. The SOC and technical teams track the detection gaps and the priority controls.
Decision profile
- Duration
- 2–6 weeks (by scope and module)
- Rhythm
- Scenario-based controlled execution
- Delivery
- Management + technical
- Scope
- Threat-actor, crown-jewel or assumed-breach
- Best for
- Organizations with SOC/Blue Team maturity
Which is the right start, and when?
These three approaches do not produce the same evidence object. Starting without knowing the difference wastes time and budget chasing the wrong proof.
| Criterion | ÖnerilenModular Red Team Simulation | Network Security Penetration Test | Continuous Penetration Testing |
|---|---|---|---|
| Decision question | Does the attacker advance to the crown jewels, and does the defense see it? | Where can the network truly be entered, from outside or inside? | Can we regularly see exposure and closure in our release rhythm? |
| Primary evidence object | Validated attack path, chain to the crown jewels, detection-gap matrix, chain-breaking control | Chainable access flaw, segmentation impact, fix-priority order | Rhythm, revalidation, closure visibility, fix-validate cycle |
| Ideal trigger | Crown-jewel, resilience and detection-gap validation; SOC/Blue Team maturity | External, internal or wireless network exposure and segmentation validation | High-release-rhythm product teams; a closure-visibility need |
| Wrong match | Inflating a network-surface exposure need into attack-path execution | Meeting an attack-path and crown-jewel need with a network-surface pentest | Confusing a one-off threat-scenario execution with a continuous web/API program |
One example of decision clarity
Anon case · RT · financial services
After new EDR and segmentation: does the defense see the path to the crown jewels?
A client gave us a written scope to test whether their EDR and segmentation investments protected a critical data asset. Together we defined the starting assumption, the authorized actions, and the stop conditions.
The controlled Red Team scenario surfaced two attack paths reaching the critical asset and the detection gaps along them. We documented each step with technical traces and ATT&CK mapping.
We delivered the executive summary, the technical report, and the chain-breaking control plan. After the client applied the detection and segmentation controls, our retest confirmed that the priority attack path had been broken.
What this case produced
- The attack path to the critical asset was verified technically.
- The detection gaps were recorded through ATT&CK mapping.
- The chain-breaking control was confirmed by a retest.
Let's clarify your scenario scope together
This form helps us clarify the critical asset, the threat scenario, the starting assumption, the telemetry, and the authorized actions.
Frequently asked questions
A network penetration test focuses on security findings across network assets. A Red Team runs the defined threat scenario all the way to the critical asset and measures your defenses' detection capability.
The starting assumption and the objective are set according to the chosen module. The scenario is designed around the organization's critical asset and its need to measure defenses.
Human-layer initial access is added to the scenario only with written authorization. Program-level behavioral measurement is carried out under the Social Engineering Simulation.
We deliver the executive summary, the attack path report, the technical security records, the ATT&CK-aligned detection gap matrix, and the remediation plan.
The critical asset, the environment, the starting assumption, the test window, telemetry access, stop-condition contacts, and reporting expectations should be shared before the engagement.
High-impact steps require separate approval. DoS, persistence, real malware, real data exfiltration, and third-party interaction are kept outside the standard scope.
Related services and add-ons
If your need extends beyond the Modular Red Team Simulation, open the right bridge here.
Network Security Penetration Test
If the focus is chainable access flaws and segmentation impact on the external, internal or wireless network surface, the Network Security Penetration Test is the right start.
PT-4Social Engineering Simulation
If the focus is a human-layer program, reporting-reflex measurement and the correct-escalation rate, the Social Engineering Simulation is the right start.
AIS-1Generative AI Red Team
If the focus is the prompt, tool, RAG or MCP chain in a GenAI agent and runtime control effectiveness, the Generative AI Red Team is the right start.
// RED TEAM · DISCOVERY
Let's clarify the critical asset, the threat scenario, and the testing boundaries together.
In the discovery call we define the module, the starting assumption, the authorized actions, the telemetry scope, and the expected deliverables together.