Contact Us

Contact Us

Please get in touch using the form below

1000 characters left
I prefer to be contacted by:
View our privacy policy
Book a penetration test today. Get in touch.

Overview

Real-life assessments to evaluate prevention, detection and response capabilities

Measuring the success of security operations on efficiency metrics alone can fail to address a key question all security leaders need to answer: how good are people and controls at preventing, detecting and responding to cyber threats?

Scenario-based testing performed by Redscan’s experienced team of consultants, can help to validate the true effectiveness of your organisation’s capabilities. This is achieved by simulating a wide range of adversarial tactics and providing recommendations to enhance the protection of key assets.

Benefits

Benefits of scenario-based testing

Scenario-based testing is a specialist form of offensive security assessment. Unlike traditional penetration testing, which is focused on uncovering vulnerabilities, scenario-based testing is designed to benchmark the performance of cyber security controls against specific adversarial tactics and behaviours. Scenario-based testing helps to answer important questions such as:

  • How effective are security technologies at preventing, detecting and responding to threats?
  • Are there any network security blind spots that persistent attackers could exploit?
  • Are Blue Team security analysts able to shut down advanced and sophisticated attacks?
  • How good are security analysts at differentiating genuine incidents from false positives?
  • Are incident response plans in place to address threats and manage compromises?
  • Do in-house security teams have the know-how to remediate breaches?

Purpose

Validate the effectiveness of
security operations

Scenario-based testing is commonly used to assess the ability of your organisation to prevent, detect and respond to threats. Unlike a Red Team Operation, which is designed to replicate a full-scale cyber-attack, a scenario-based test is a more focused type of assessment often constructed around a specific adversarial tactic. Regular scenario-based testing creates a culture of continuous improvement, ensuring that your security operations team is better prepared to act against current and emerging threats.

Assessments

Custom assessments

Redscan’s scenario-based testing service can be tailored to help evaluate your organisation’s ability to detect and respond to a range of security risks. The many scenarios and tactics that we can replicate include:

  • A supply chain compromise
  • Data exfiltration by an employee or contractor
  • A spear phishing campaign to harvest credentials
  • Installation of malware
A range of security assessment services

MITRE ATT&CK

The MITRE ATT&CK™ framework

Scenario-based testing can be aligned to a range of adversarial behaviour frameworks. One of the most common is the Adversarial Tactics, Techniques and Common Knowledge (MITRE ATT&CK), which outlines the methods adversaries use to compromise, exploit and traverse networks. The MITRE ATT&CK Framework is divided into 11 groups of TTPs, all of which can be replicated by scenario-based testing.

01. Initial Access
02. Execution
03. Persistence
04. Privilege Escalation
05. Defense Evasion
06. Credential Access
07. Discovery
08. Lateral Movement
09. Collection
10. Exfiltration
11. Command and Control
01.

Initial Access

Gaining a foothold in the target network using tactics such as spear phishing and supply-chain compromise.

02.

Execution

Executing code on a target system once access has been obtained. Includes the abuse of legitimate applications and systems such as Control Panel items and PowerShell.

03.

Persistence

Establishing and maintaining a persistent presence on a network, overcoming interruptions such as system restarts and updated account credentials.

04.

Privilege Escalation

Increasing permission levels to access additional parts of a compromised network through techniques such as hooking, process injection and access token manipulation.

05.

Defense Evasion

Avoiding detection through techniques such as the disablement of security defences, prevention of endpoint inspection or bypassing of application whitelisting.

06.

Credential Access

Seeking to gain access to or control a system or domain by obtaining legitimate credentials, including the use of brute force and credential dumping.

07.

Discovery

Acquiring knowledge of target systems and networks. Includes account, application, browser and directory reconnaissance techniques.

08.

Lateral Movement

Traversing a network and gaining control of remote systems. Includes Pass the Ticket (PtT) and remote service effects techniques.

09.

Collection

Identifying and gathering sensitive information through audio, keystroke, screen and video capture.

10.

Exfiltration

Removing files and information from the target network, often using a combination of compression, encryption and legitimate protocol abuse.

11.

Command and Control

Establishing communication with target systems through the abuse of existing, legitimate protocols.

High-fidelity security telemetry mapped to MITRE ATT&CK

Security insight

Gain deeper insight with scenario-based testing

Scenario-based testing can be commissioned as a standalone engagement or included as part of ThreatDetect™, Redscan’s award-winning Managed Detection and Response service, in order to continually validate visibility and coverage against current and emerging threats.

Expertise

Our security qualifications

About us

Why choose Redscan?

  • A leading UK-based MDR company
  • Red and blue team CREST CSOC expertise
  • High-quality intelligence and actionable outcomes
  • Quick and hassle-free service deployment
  • An agnostic approach to technology selection
  • Avg. 9/10 customer satisfaction, 95% retention rate

Get in touch

Complete the form for a prompt response from our team.

1000 characters left
I prefer to be contacted by:
View our privacy policy

Resources

Discover our latest content and resources

From the blog
From the blog Case studies Latest news
26th October 2021
Ransomware attacks in the UK double in one year
Jeremy Fleming, the Director of GCHQ, has warned that the number of ransomware attacks on UK organisations has doubled over the past year.  
19th October 2021
Organisations found to take more than two days to respond to cyber-attacks
Recent research shows that organisations around the world take, on average, more than two business days to respond to a cyber-attack.
12th October 2021
Over 90% of companies experienced supply chain breaches in the past year
A new survey has found that 93% of organisations around the world suffered a direct breach over the past 12 months due to weaknesses in their supply chains.
5th October 2021
Tech adopted in pandemic linked to 74% of attacks on 94% of organisations
A recent study has found that 94% of organisations experienced a cyber-attack in the past 12 months, with almost three-quarters of the businesses attributing them to vulnerabilities created by technology adopted during the pandemic.