Consulting Module

Module 10 โ€” Red Team & Adversarial Validation

The client has MFA. They have Conditional Access. They have Intune. The dashboard is green. This is the most dangerous estate to walk into โ€” not because it is badly configured, but because everyone believes it works. Module 10 finds out which controls are real and which are representations.

What It Delivers

๐ŸŽฏ

Targeted Kill Chain Validation

Adversary simulation runs specifically against the kill chain identified in the Brownhat Diagnostic and modified by previous hardening modules. Not a broad-scope red team โ€” a focused test of whether the paths we said we closed are actually closed. The attack surface is the attack surface your organisation faces, not a generic penetration test scope.

๐Ÿ”

Identity and Privilege Assumption Testing

Kerberoasting, DCSync simulation, PIM bypass attempts, and OAuth consent abuse โ€” the techniques that succeed on hardened estates because the hardening is present but not tested. A control that has never been exercised is a hypothesis. This engagement converts hypotheses to evidence.

๐Ÿงช

Detection Validation

Security alerts deliberately triggered to test whether detection rules fire, whether alerts reach a human, and whether that human knows what to do. Many estates generate the right alert into a queue nobody reads. Detection validation distinguishes between "we detect this" and "we detect this and respond to it."

๐Ÿ—๏ธ

Structural Finding, Not a CVE List

Every gap found produces a structural recommendation โ€” not "patch this CVE" but "this path exists because of this architectural condition; severing it requires this change." The output is a shorter kill chain, not a longer remediation backlog. We do not add controls. We find why the existing ones do not work.

When to Run This Module

Module 10 is a post-hardening engagement. It is the evidence check after the work โ€” the test that distinguishes security improvement from compliance improvement. Run it after Modules 2, 3, 6, and 12 have had time to bed in. Running it before hardening is simply a penetration test; running it after hardening is adversarial validation.

Scope and Prerequisites

Duration15โ€“30 days
EnvironmentAny
PrerequisitesWritten authorisation covering all test activities; at least two hardening modules completed; initial kill chain from Module 0 documented
Natural follow-onUpdate kill chain map with validated findings; feed structural gaps back into the module roadmap

Find out which controls are real

Green dashboards and untested reality are the most dangerous combination in security. Module 10 converts one to the other.