Red Team

CANCOM Offense Center

How well do you understand your actual attack surface? Red teaming reveals where your organization is truly vulnerable โ€“ under realistic conditions and without priorwarning. CANCOM simulates targeted, real-world attacks on your IT infrastructure, processes, and physical security to identify risks at an early stage and sustainably strengthen your resilience.

Our modular approach goes far beyond traditional penetration testing: from social engineering and dark web analyses to cloud, OT, and AI audits, we uncover hidden vulnerabilities and lay the foundation for a future-proof cyber defense.

b_cancom_redteam

Red Teaming: Realistic attack simulations for maximum cyber resilience

Red teaming puts your IT security through a targeted test: our experts act like real attackers to uncover vulnerabilities in your infrastructure under the most realistic conditions possible. In doing so, we follow established, Europe-wide recognized frameworks such as TIBERโ€‘EU as well as DORA TLPT (Threatโ€‘Led Penetration Testing), which define a structured, threat-led testing approach. The insights gained are fed directly into the work of the Blue Team (CANCOM Cyber Defense Center), thereby sustainably strengthening your organizationโ€™s resilience against real-world attacks.

Approaches and methods at a glance

Our approach is based on the TIBERโ€‘EU framework (Threat Intelligenceโ€‘Based Ethical Red Teaming). In this context, only the objectives to be achieved are defined โ€“ the timing, method, and attack path are determined by the simulated attacker. The following red teaming modules illustrate the approaches we use to achieve these objectives.

b cancom redteam gute

Pentest vs. Red Teaming

Pentest:

  • Systematic identification and prioritization of technical vulnerabilities
  • Focus on clearly defined systems, services, and configurations
  • Outcome: structured report with findings, risk assessment, and recommendations for action

Red Teaming:

  • Focus on defined attack targets (e.g., email access, ERP, domain admin)
  • Testing the entire attack chain: detection, response, and internal processes
  • Result: Detailed attack timeline, including a replay workshop; the focus is on optimizing processes and workflows (identified vulnerabilities are secondary)

Security Pentest Modules

Our penetration testing modules are based on the Unified Kill Chain structure โ€œIn โ€“ Through โ€“ Out.โ€ It reflects realistic attack stages โ€“ from initial access and lateral movement through to potential data exfiltration scenarios.

i_in

OSINT โ€“ Darknet Snapshot

Open Source Intelligence (OSINT) involves the one-time collection, investigation, and analysis of publicly available company information, as well as its evaluation withregard to potential attack scenarios.

  • Identification of critical, publicly accessible information
  • Research in the dark web for company-related data
  • Search for internal company documents
i_in

External Pentest

External penetration testing simulates an attacker originating from the internet. 

  • Assessment of publicly accessible IT infrastructure (e.g., mail, FTP, and VPN servers, web applications)
  • Performed without the use of social engineering
i_in

Application Pentest

Application penetration testing assesses the security of your cloud, web, mobile, and client applications.

  • Assessment of application logic and, where necessary, the underlying server/OS infrastructure
  • Testing in accordance with relevant standards and guidelines (e.g., OWASP API Security Top 10, OWASP Top 10, OWASP Mobile Security)
  • Includes source code analysis where required
i_in

Social Engineering 

Assessment of your employeesโ€™ security awareness  
On-site:  

  • Physical intrusion (bypassing the perimeter)
  • Search of internal areas for sensitive information
  • Active manipulation of employees
  • USB dropping

Remote:  

  • Execution of broad-based and targeted phishing campaigns
  • Simulation of vishing and smishing attacks
i_in

Custom requests

Tailored security assessments designed to address your specific threat landscape.

  • Analysis of your specific security requirements
  • Development of customized test scenarios
  • Execution of realistic attack methods
  • Clear recommendations for action and prioritized measures

Red Team Security Reports

All insights gained from the interaction between the Red, Blue, and Purple Teams are subsequently consolidated into clear and comprehensible security reports. To ensure clarity, we structure our results into two clearly defined sections:

  1. Executive summary for management
  2. Detailed findings for the technical team

We do not only provide the identified vulnerabilities, but also assess them in terms of risk and deliver clear recommendations for effective remediation.

Our red team assessments meet the requirements of the German IT Security Act (ITโ€‘SiG 2.0), the NIS2 Directive, and relevant BSI standards. We work in accordance with internationally recognized frameworks such as TIBERโ€‘EU, PTES, and NIST, and rely on experienced, certified auditors (including OSCP and ISO 27001). For banks and insurance companies, we also offer TIBERโ€‘DE-compliant testing.

Letโ€™s explore how we can strengthen your IT security โ€“ we look forward to your inquiry.