FIN-7-style retail engagement
Cardholder data reach proven; PCI segmentation gap identified
Operate against your environment with the tradecraft of a named threat actor — toward a stated objective, with detection scoring and a purple-team debrief.
Engagements end with an impressive narrative but no clear answer to: "Could this attacker reach the crown jewels, and would we catch them before they did?"
Without that answer, red teaming becomes theatre.
KeenSafe red teams start from the business outcome — domain admin, payment data, source code, customer PII — and reverse-engineer the most realistic attacker path.
We pause at every control boundary to validate detection. Engagement ends with a joint purple-team review and a measurable detection-engineering uplift plan.
TTPs sourced from real adversary reporting (APT, FIN, ransomware affiliate) relevant to your sector.
Phishing, exposed services, supply chain, identity abuse — scope-bounded.
Goals stated upfront. Path proof end-to-end.
Per-stage view of which TTPs were blocked, alerted or missed.
Joint walkthrough with blue team. Detection gaps converted to engineering tasks.
Framework-aligned engagements for regulated industries.
A goal-driven engagement is an end-to-end narrative: a threat actor with a stated objective, an environment, and a series of choices. Every choice exposes a control assumption.
Cardholder data reach proven; PCI segmentation gap identified
Ransomware blast radius modelled without encryption
Engagement closes when the stated objective is reached or budget exhausted.
Blocked / alerted / missed across SIEM, EDR, identity controls.
Specific detection-engineering tasks with acceptance criteria.
Same path replayed after detection uplift — closure provable.
Most board reports describe what controls "should" do. A red team engagement reports what they actually do.
The output is a single number every board cares about: how many TTPs in this realistic chain did we catch?
Threat-actor profile selected first; scope and rules-of-engagement formalised; multi-vector access; objective-driven traversal; detection scored at every boundary; closed-blind or purple mode.
Define the objective. We define the chain. Together we measure detection.