What It Delivers
Targeted Kill Chain Validation
Adversary simulation runs specifically against the kill chain identified in the Brownhat Diagnostic and modified by previous hardening modules. Not a broad-scope red team โ a focused test of whether the paths we said we closed are actually closed. The attack surface is the attack surface your organisation faces, not a generic penetration test scope.
Identity and Privilege Assumption Testing
Kerberoasting, DCSync simulation, PIM bypass attempts, and OAuth consent abuse โ the techniques that succeed on hardened estates because the hardening is present but not tested. A control that has never been exercised is a hypothesis. This engagement converts hypotheses to evidence.
Detection Validation
Security alerts deliberately triggered to test whether detection rules fire, whether alerts reach a human, and whether that human knows what to do. Many estates generate the right alert into a queue nobody reads. Detection validation distinguishes between "we detect this" and "we detect this and respond to it."
Structural Finding, Not a CVE List
Every gap found produces a structural recommendation โ not "patch this CVE" but "this path exists because of this architectural condition; severing it requires this change." The output is a shorter kill chain, not a longer remediation backlog. We do not add controls. We find why the existing ones do not work.
When to Run This Module
Module 10 is a post-hardening engagement. It is the evidence check after the work โ the test that distinguishes security improvement from compliance improvement. Run it after Modules 2, 3, 6, and 12 have had time to bed in. Running it before hardening is simply a penetration test; running it after hardening is adversarial validation.
Scope and Prerequisites
| Duration | 15โ30 days |
| Environment | Any |
| Prerequisites | Written authorisation covering all test activities; at least two hardening modules completed; initial kill chain from Module 0 documented |
| Natural follow-on | Update kill chain map with validated findings; feed structural gaps back into the module roadmap |
Find out which controls are real
Green dashboards and untested reality are the most dangerous combination in security. Module 10 converts one to the other.