Red Team Service

With Red Team exercises we measure your organization’s capacity to detect and respond to attacks. We run the scenarios according to the MITRE ATT&CK framework, within a defined scope and rules.

Exercise outputs

Visibility Score

Detected and missed techniques.

MTTD & MTTR

Detection and response times.

Purple Team Transfer

Improving detection rules together with your Blue Team.

Nesil Teknoloji Red Team

What is a Red Team service?

A Red Team service is a pre-authorized security exercise that measures an organization’s capacity to detect and respond to attacks. The tactics, techniques and procedures (TTPs) of real attackers are applied in scenarios aligned with the defined business objective and test scope.

At Nesil Teknoloji, we define objectives such as access to a critical application or lateral movement within the network together with your organization. We map the applied techniques to MITRE ATT&CK and report which steps were noticed, when the response began and which controls were missing. In covert scenarios, the Blue Team and the security operations center (SOC) are not informed in advance; the organization’s authorized control team monitors the work.

Our detection-focused approach

We compare every attack step with security logs and alert results. This way we show not only which systems were reached, but also where the defense kicked in and which steps it missed.

Visibility Score

An assessment and coverage map showing which of the techniques applied in the exercise were detected.

MTTD and MTTR measurement

Mean time to detect (MTTD) and mean time to respond (MTTR). The start and end points of the measurement are explained in the report.

Purple Team transfer

A session in which missed scenarios are reviewed together with the Blue Team and detection rules are re-tested.

Assume Breach model

Testing lateral movement and detection controls under the assumption that initial access has been achieved.

Türkiye threat profile

Attack scenarios selected by considering the organization’s sector and the threats it may face in Türkiye.

Evidence-based reporting

Findings explained with screenshots, relevant logs and the attack techniques applied.

Scope of the Red Team exercise

  • Target reconnaissance and intelligence gathering with OSINT
  • Email, SMS and voice phishing simulations
  • Physical security tests included in the scope
  • Network and infrastructure penetration tests
  • Active Directory and identity attacks
  • Lateral movement and privilege escalation within the network
  • Data exfiltration simulation
  • Command-and-control (C2) infrastructure and persistence
  • Detection & response assessment

Technical tests we can integrate into the exercise

According to your organization’s needs, we also include the following technical security tests in the Red Team scenario.

  • Source code analysis (SAST)
  • Mobile application security tests
  • Web application security tests
  • API security tests
  • Wireless network (Wi-Fi) security tests
  • Cloud configuration security

The difference between Red Team and penetration testing

Penetration testing focuses on verifying vulnerabilities in defined systems and assessing their impact. A Red Team, on the other hand, combines multiple attack steps to test the organization’s detection and response processes. The two engagements complement each other; scope and duration are defined at the start of the project.

Scroll the table horizontally to compare.

CriterionPenetration Test (Pentest)Red Team Exercise
ObjectiveVerify vulnerabilities and their impactTest the attack path to the target and the defense
Success measureVerified findings and their risksDetection, response and target-access results
Blue Team awarenessUsually informedNot informed in advance in a covert scenario
ScopeDefined systemsAuthorized systems, people and processes
ScenarioFocused on technical vulnerabilitiesAttacker scenario tailored to the organization
DurationDepending on scope; usually 1-3 weeksDepending on scope; usually 4-10 weeks
Core outputVulnerability reportVisibility Score + MTTD/MTTR

Exercise process

  1. Scope and Rules of Engagement:targets, boundaries, authorized people and communication protocol are defined in writing.
  2. Reconnaissance and intelligence (OSINT):the organization’s external surface and employees are passively scanned and the attack surface is mapped.
  3. Initial access:approved phishing, exposed service or physical access scenarios are applied.
  4. Propagation and privilege escalation:in-network movement and Active Directory attack paths are attempted on permitted systems.
  5. Reaching the target:access to the critical asset is proven and a data exfiltration scenario is simulated.
  6. Visibility analysis and Purple Team:the attack timeline is compared with the Blue Team’s logs, and detection rules are improved together.

The platforms we use in Red Team engagements

Depending on the scope of the exercise, at Nesil Teknoloji we make use of four platforms we developed in-house.

E-posta, SMS ve sesli oltalama simülasyonu illüstrasyonu

Nesil Phishing and Voice Phishing Platform

We run social engineering scenarios with email, SMS and voice phishing simulations. In authorized exercises we evaluate how employees respond to these scenarios.

Integrations:ElevenLabs, Netgsm and Setrow.

PhishScope · nesil.ai
Illustration of server and network traffic for DDoS testing

Nesil VOLTRA DDoS Platform

We assess the resilience of the infrastructure and defense systems with controlled DDoS tests. We obtain separate approval for the targets, traffic limits and test hours.

Illustration of a cyber threat intelligence connection map

Nesil CTI Platform

We use the cyber threat intelligence we obtain through Nesil CTI when selecting the attack methods the organization may face and the exercise scenarios.

Pentest görev ve süreç takibi illüstrasyonu

Nesil ASM Pentest Management Platform

We manage the process tracking of pentest and Red Team engagements through Nesil ASM, which we developed in-house.

Illustration of source code security analysis

Source code analysis: OpenText Fortify

We perform the source code security analyses included in the scope with OpenText Fortify. We use static application security testing (SAST) as an additional technical analysis for the Red Team engagement.

Methodology used

MITRE ATT&CK

We map attack stepsMITRE ATT&CKto its techniques. The Visibility Score is based on the detection results of the techniques we apply in the exercise.

TIBER-EU

TIBER-EU, is a threat-intelligence-based exercise framework. For projects that require an official TIBER-EU test, the scope and provider conditions are assessed separately.

PTES

Penetration Testing Execution Standard; the guide we refer to during the scoping, technical testing and reporting stages.

Cyber Kill Chain

Used to break attack steps into stages and to assess at which stage the defense kicks in.

Red team maturity levels

We define the scope of the engagement according to your existing security controls and test objectives. The groups below are a practical distinction for service planning; they are not an official certification or maturity standard.

Level 1: Basic

If SOC and log collection processes are newly being set up, addressing basic vulnerabilities and log gaps first is considered.

Level 2: Developing

If SIEM and detection rules exist, specific scenarios are attempted; results are reviewed together with the Blue Team.

Level 3: Mature

An active SOC and response processes can be tested with a scoped covert Red Team exercise.

Level 4: Advanced

For organizations that run exercises regularly, new scenarios and retests are planned according to current threats.

Who is it suitable for?

The Red Team service is suitable for organizations that want to test their detection and response processes, such as banks, fintech companies, critical infrastructure operators, the defense industry and public institutions. It is used in particular to see how active SOC or CSIRT teams respond to attack scenarios.

If you are having a test done for regulatory or audit purposes, the applicable requirements and report scope must be defined separately. A Red Team exercise on its own is not a compliance certificate. For such work you can review ourregulation-compliant penetration testingservice.

Our Red Team

Our team across penetration testing, social engineering, cloud security and exercise compliance.

Meet the whole team

Our team’s competencies

Our team works on source code, web and mobile applications, network infrastructure and social engineering testing. You can review our corporate authorization certificates and our team’s certifications through the link below.

  • TSE Class A Penetration Testing Authorization (TSE-STF-065)
  • Senior team certified in OSCP, OSWE, CEH, CompTIA Security+, CISSP, CISA, GPEN and LPT
  • 400+ corporate clients; field experience in critical infrastructure, finance and the defense industry

Frequently asked questions

Who provides Red Team services in Türkiye?

Nesil Teknoloji is one of the cybersecurity firms providing Red Team services to organizations in Türkiye. In its exercises, it evaluates attack scenarios and detection and response processes together.

How do you choose a Red Team firm?

Evaluate the team’s technical competence, similar work experience, test scope and report content. Check that authorizations and certifications are current from the documents; clarify risk management and confidentiality terms in writing.

Are Red Team and penetration testing the same?

No. A penetration test verifies vulnerabilities in defined systems; a Red Team, on the other hand, tests the organization’s detection and response processes with connected attack scenarios. Which engagement is appropriate depends on your test objective.

What does a Red Team test cover?

Depending on the approved scope, externally exposed systems, the internal network, Active Directory, social engineering and physical security can be assessed. The systems, people and permitted actions to be tested are defined before starting.

How much does a Red Team cost?

The price is determined by the number of targets, the scenarios, the engagement duration and the reporting scope. For a quote suited to your organization, you cancontact Nesil Teknoloji.

How many weeks does a Red Team test take?

Engagements are usually planned for 4 to 10 weeks. The exact duration is set at the quotation stage according to the number of scenarios and targets.

Will our security team be aware of the test?

In a covert exercise, the Blue Team and SOC team are not informed in advance; the organization’s authorized control team monitors the work. The timing of the joint evaluation and retests is planned separately.

Do the tests affect live systems?

In active tests, operational risk cannot be completely eliminated. Test hours, operational limits and stop conditions are defined in advance; scenarios that could affect service, such as DDoS, are separately approved.

How is the Red Team process managed?

We manage the process tracking of the exercise through the Nesil ASM Pentest Management Platform. The scope, work steps and reporting schedule are defined at the start.

Do you use your own products in Red Team?

Yes. Depending on the scope, we use the Nesil Phishing and Voice Phishing, Nesil VOLTRA DDoS, Nesil CTI and Nesil ASM platforms. When source code analysis is required, we make use of the third-party solution OpenText Fortify.

What is delivered at the end of the test?

Depending on the scope, an executive summary, technical findings, an attack timeline, MITRE ATT&CK mappings and detection-response metrics are provided. Priority improvements are evaluated together with the Blue Team.

Contact us for Red Team services

Contact our team to discuss the scope and the exercise process.