3.9 KiB
title, description, eyebrow, lead, actions
| title | description | eyebrow | lead | actions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Module 10 — Red Team & Adversarial Validation | Adversary simulation against the specific kill chain identified in the Brownhat Diagnostic. Validates whether hardening modules produced real security improvement or compliance dashboard improvement. | Consulting Module | The client has MFA. They have Conditional Access. They have Intune. The dashboard is green. This is the most dangerous estate to walk into — not because it is badly configured, but because everyone believes it works. Module 10 finds out which controls are real and which are representations. |
|
What It Delivers
Targeted Kill Chain Validation
Adversary simulation runs specifically against the kill chain identified in the Brownhat Diagnostic and modified by previous hardening modules. Not a broad-scope red team — a focused test of whether the paths we said we closed are actually closed. The attack surface is the attack surface your organisation faces, not a generic penetration test scope.
Identity and Privilege Assumption Testing
Kerberoasting, DCSync simulation, PIM bypass attempts, and OAuth consent abuse — the techniques that succeed on hardened estates because the hardening is present but not tested. A control that has never been exercised is a hypothesis. This engagement converts hypotheses to evidence.
Detection Validation
Security alerts deliberately triggered to test whether detection rules fire, whether alerts reach a human, and whether that human knows what to do. Many estates generate the right alert into a queue nobody reads. Detection validation distinguishes between "we detect this" and "we detect this and respond to it."
Structural Finding, Not a CVE List
Every gap found produces a structural recommendation — not "patch this CVE" but "this path exists because of this architectural condition; severing it requires this change." The output is a shorter kill chain, not a longer remediation backlog. We do not add controls. We find why the existing ones do not work.
When to Run This Module
Module 10 is a post-hardening engagement. It is the evidence check after the work — the test that distinguishes security improvement from compliance improvement. Run it after Modules 2, 3, 6, and 12 have had time to bed in. Running it before hardening is simply a penetration test; running it after hardening is adversarial validation.
Scope and Prerequisites
| Duration | 15–30 days |
| Environment | Any |
| Prerequisites | Written authorisation covering all test activities; at least two hardening modules completed; initial kill chain from Module 0 documented |
| Natural follow-on | Update kill chain map with validated findings; feed structural gaps back into the module roadmap |
Find out which controls are real
Green dashboards and untested reality are the most dangerous combination in security. Module 10 converts one to the other.