Red Team
CANCOM Offense Center
How well do you understand your actual attack surface? Red teaming reveals where your organization is truly vulnerable โ under realistic conditions and without priorwarning. CANCOM simulates targeted, real-world attacks on your IT infrastructure, processes, and physical security to identify risks at an early stage and sustainably strengthen your resilience.
Our modular approach goes far beyond traditional penetration testing: from social engineering and dark web analyses to cloud, OT, and AI audits, we uncover hidden vulnerabilities and lay the foundation for a future-proof cyber defense.

Red Teaming: Realistic attack simulations for maximum cyber resilience
Red teaming puts your IT security through a targeted test: our experts act like real attackers to uncover vulnerabilities in your infrastructure under the most realistic conditions possible. In doing so, we follow established, Europe-wide recognized frameworks such as TIBERโEU as well as DORA TLPT (ThreatโLed Penetration Testing), which define a structured, threat-led testing approach. The insights gained are fed directly into the work of the Blue Team (CANCOM Cyber Defense Center), thereby sustainably strengthening your organizationโs resilience against real-world attacks.
Red teaming uses a broad range of techniques to uncover vulnerabilities in IT systems, business processes, and physical security. Unlike traditional penetration testing, the red team simulates realistic, multi-stage attacks โ including social engineering methods such as spear phishing, which specifically target human weaknesses. The goal is to comprehensively test an organizationโs detection and resilience capabilities against complex attack scenarios.
In addition to digital attacks, the red team also examines physical security, for example by testing access controls or simulating break-in attempts. This reveals not only technical but also structural vulnerabilities that can impact the overall security posture in the long term. The insights gained support both the Blue Team in defense and the Purple Team in further developing the security strategy.
Red teaming enables organizations to test and strengthen their IT security under realistic conditions. Simulated cyberattacks allow vulnerabilities in applications, systems, and processes to be identified at an early stage and effectively remediated. To achieve this, the red team uses a wide range of attack techniques โ making it a key component of modern offensive security strategies.
Close collaboration with the Blue Team creates valuable synergies: insights gained from attack simulations are fed directly into defense efforts, resulting in a continuously optimized security architecture. In this way, you sustainably strengthen your organizationโs cyber resilience and develop a security strategy that is prepared for real-world threats.
Approaches and methods at a glance
Our approach is based on the TIBERโEU framework (Threat IntelligenceโBased Ethical Red Teaming). In this context, only the objectives to be achieved are defined โ the timing, method, and attack path are determined by the simulated attacker. The following red teaming modules illustrate the approaches we use to achieve these objectives.
Simulation of an attacker without constraints attempting to gain access to the internal network.
- Coverage of various realistic attack scenarios
- Assessment of the entire external perimeter (systems, personnel, etc.)
Simulation of an attacker without constraints who has already gained initial access and can move laterally within the internal network without restriction to achieve defined objectives.
- Assessment of the internal attack vector, including defense mechanisms and IT security processes
- Coverage of various realistic attack scenarios
Assessment of how far an attacker can progress within the organization without being detected by the Security Operations Center (SOC).
- Execution of multi-stage tests to evaluate the SOCโs detection and response times
In collaboration with the SOC team, defined objectives are pursued to simulate various attack scenarios.
- Generation of indicators of compromise (IoCs) for the SOC team through replay workshops
- Derivation of new rules and measures to enable faster detection of future attacks
To ensure that red teaming results are effectively integrated into your security strategy, the Red Team and Blue Team work closely together:
- The Red Team adopts the perspective of real attackers, identifies vulnerabilities, and tests attack paths.
- The Blue Team monitors systems, detects attacks, and continuously improves defense mechanisms.
- The Purple Team acts as the link between both sides: it coordinates insights from each team and translates them into concrete measuresโensuring a comprehensive and resilient security strategy.

Pentest vs. Red Teaming
Pentest:
- Systematic identification and prioritization of technical vulnerabilities
- Focus on clearly defined systems, services, and configurations
- Outcome: structured report with findings, risk assessment, and recommendations for action
Red Teaming:
- Focus on defined attack targets (e.g., email access, ERP, domain admin)
- Testing the entire attack chain: detection, response, and internal processes
- Result: Detailed attack timeline, including a replay workshop; the focus is on optimizing processes and workflows (identified vulnerabilities are secondary)
Security Pentest Modules
Our penetration testing modules are based on the Unified Kill Chain structure โIn โ Through โ Out.โ It reflects realistic attack stages โ from initial access and lateral movement through to potential data exfiltration scenarios.
OSINT โ Darknet Snapshot
Open Source Intelligence (OSINT) involves the one-time collection, investigation, and analysis of publicly available company information, as well as its evaluation withregard to potential attack scenarios.
- Identification of critical, publicly accessible information
- Research in the dark web for company-related data
- Search for internal company documents
External Pentest
External penetration testing simulates an attacker originating from the internet.
- Assessment of publicly accessible IT infrastructure (e.g., mail, FTP, and VPN servers, web applications)
- Performed without the use of social engineering
Application Pentest
Application penetration testing assesses the security of your cloud, web, mobile, and client applications.
- Assessment of application logic and, where necessary, the underlying server/OS infrastructure
- Testing in accordance with relevant standards and guidelines (e.g., OWASP API Security Top 10, OWASP Top 10, OWASP Mobile Security)
- Includes source code analysis where required
Social Engineering
Assessment of your employeesโ security awareness
On-site:
- Physical intrusion (bypassing the perimeter)
- Search of internal areas for sensitive information
- Active manipulation of employees
- USB dropping
Remote:
- Execution of broad-based and targeted phishing campaigns
- Simulation of vishing and smishing attacks
Custom requests
Tailored security assessments designed to address your specific threat landscape.
- Analysis of your specific security requirements
- Development of customized test scenarios
- Execution of realistic attack methods
- Clear recommendations for action and prioritized measures
Internal Pentest
Internal penetration testing simulates an attacker who has already gained access to the internal network.
- Assessment of the internal network, including Active Directory, file shares, and applications
OT Pentest
Enterprise-wide assessment of network segmentation with a focus on access to the production environment.
- Evaluation of the security of the production environment in accordance with relevant standards and guidelines
- Assessment of SCADA and industrial control (OT) networks
- Assessment of access control and remote maintenance
AI and LLM Pentest
Assessment of AI systems and their integration into the IT infrastructure.
- Evaluation in accordance with the OWASP Top 10 for Machine Learning
- Data leakage
- Prompt injection and jailbreak scenarios
- Supply chain vulnerabilities and sensitive data disclosure
- Data poisoning and overreliance
- Model theft
Red Team Security Reports
All insights gained from the interaction between the Red, Blue, and Purple Teams are subsequently consolidated into clear and comprehensible security reports. To ensure clarity, we structure our results into two clearly defined sections:
- Executive summary for management
- Detailed findings for the technical team
We do not only provide the identified vulnerabilities, but also assess them in terms of risk and deliver clear recommendations for effective remediation.
Our red team assessments meet the requirements of the German IT Security Act (ITโSiG 2.0), the NIS2 Directive, and relevant BSI standards. We work in accordance with internationally recognized frameworks such as TIBERโEU, PTES, and NIST, and rely on experienced, certified auditors (including OSCP and ISO 27001). For banks and insurance companies, we also offer TIBERโDE-compliant testing.
Letโs explore how we can strengthen your IT security โ we look forward to your inquiry.
