Skip to content
Client access

Service

Red Team & Ethical Hacking

Human-led adversary exercises that test whether your organization detects and contains a real attack, with tactics mapped to MITRE ATT&CK.

Automation
Between exercises, Kynapt keeps the map of your exposed attack surface up to date, so every campaign starts from what an attacker would see today.
Human validation
Certified operators design the attack chain and evasion techniques, and your portal shows what was tested and what your team detected.

The challenge

Would your organization detect a real attack in time?

Firewalls, EDR and a SOC do not, on their own, guarantee that an adversary will be stopped. The only way to know is to test them against the techniques attackers use today.

Our engagements combine two approaches. Penetration tests identify and prioritize vulnerabilities within a defined scope. Red Team exercises emulate an adversary with a specific objective —for example, reaching a payment system or customer data— and measure whether your Blue Team detects and contains it.

We always work under formal authorization, agreed rules of engagement and an escalation channel that stays open throughout the exercise.

What we assess

Engagements tailored to your maturity

From a focused first assessment to full adversary emulation. We combine engagement types based on your objectives and obligations.

Red Team exercise

Objective-driven adversary emulation using initial access, lateral movement and controlled persistence techniques. It measures your real detection and response capability.

Infrastructure pentest

External and internal testing of networks, servers and exposed services, including Active Directory, to identify the paths that lead to a compromise.

Web applications and APIs

Manual and automated testing guided by the OWASP WSTG and OWASP API Security Top 10: authentication, access control, business logic and injection flaws.

Mobile applications

Android and iOS app analysis based on OWASP MASVS/MASTG: local storage, backend communication and anti-tampering protections.

Cloud and hybrid environments

Offensive review of configurations and identities in AWS, Azure and Microsoft 365: excessive permissions, data exposure and escalation paths.

Purple Team

Collaborative sessions with your Blue Team: we execute specific techniques, review together what was detected, and tune rules and procedures on the spot.

How we work

A controlled methodology, from planning to retest

01

Scope and rules of engagement

We define objectives, in-scope and out-of-scope systems, testing windows, emergency contacts and the formal authorization for the exercise.

02

Reconnaissance

We map your external attack surface and public information (OSINT), just as an adversary would before acting.

03

Initial access

We exploit vulnerabilities and, when in scope, social engineering vectors to gain a first foothold.

04

Lateral movement and objectives

We escalate privileges and move toward the agreed objectives, documenting every technique against MITRE ATT&CK.

05

Detection assessment

We compare our timeline with your Blue Team’s: what was detected, when, and how it was handled.

06

Reporting and retest

We present results to leadership and to the technical team, and verify that critical fixes actually work.

Deliverables

Evidence your team can act on the next day

Reference frameworks

  • MITRE ATT&CK
  • PTES
  • NIST SP 800-115
  • OWASP WSTG
  • OWASP MASTG
  • CVSS
  • Executive summaryRisk level, key findings and recommendations in business language, for leadership and the board.
  • Detailed technical reportEvery finding with evidence, reproduction steps, CVSS severity and its concrete impact on your operations.
  • MITRE ATT&CK matrixTechniques executed and the detection outcome for each one: detected, partially detected or not detected.
  • Prioritized remediation planActions ranked by risk and effort, with recommendations specific to your technology stack.
  • Results briefingSeparate sessions with the technical team and with leadership to answer questions and agree on next steps.
  • RetestVerification of fixes for critical and high findings, with a closing report.

Frequently asked questions

What clients usually ask before we start

Can a Red Team exercise disrupt operations?

Risk is managed from day one: the rules of engagement exclude destructive techniques and any critical systems you define, testing windows are agreed in advance, and an emergency contact can halt any action immediately.

What is the difference between a pentest and a Red Team?

A pentest looks for as many vulnerabilities as possible within a defined scope. A Red Team pursues a specific objective stealthily and measures whether your organization detects and responds to the attack. If you do not yet have a vulnerability management process, we recommend starting with a pentest.

Who in my organization needs to know?

In a Red Team exercise only a small group knows (the “white team”), usually security management and an executive sponsor, so that the Blue Team’s response is realistic. In a pentest, the IT team is usually informed.

How long does it take?

It depends on the scope and engagement type. Our proposal includes a phased timeline covering preparation, execution, reporting and retest.

Does it help with SBS or PCI DSS compliance?

Yes. PCI DSS requires periodic penetration testing, and SBS Resolution No. 504-2021 calls for assessing the effectiveness of cybersecurity controls. Our reports are structured to serve as evidence for auditors and regulators.

Other services

A comprehensive view of your security

Penetration Testing

Manual testing of web applications, APIs, mobile apps, infrastructure and cloud that goes where a scanner can’t.

Source Code Review

We find vulnerabilities in your code before they reach production, in any language.

Kamaya Secure logo on an office wall

Let’s define the right scope for your organization

Tell us about your objectives and constraints. We will send you a proposal with scope, rules of engagement, timeline and deliverables.

Chat on WhatsApp (opens in a new tab)