Start with legitimate access. Measure where trust stops.
The engagement tests how legitimate access can be misused or expanded—not whether a particular employee is trustworthy. A synthetic or controlled identity starts with agreed permissions, then tests data, privilege, process and monitoring boundaries toward a named objective.
REQUEST → SCOPE → AUTHORIZE → KICKOFF → EXECUTE
Each boundary is tested independently, then examined as part of the complete path.
- 01ACCESS
- 02DATA
- 03PRIVILEGE
- 04PROCESS
- 05OBJECTIVE
LEGITIMATE ACCESS / EXPLICIT BOUNDARIES
ASSESSMENT BOUNDARY
What is being assessed?
The engagement boundary is defined by systems, identities, workflows and restrictions—not only a list of URLs or assets.
- Authorized starting identities and permissions
- Sensitive-data access boundaries
- Privilege expansion paths
- Administrative and business-process controls
- Movement between approved systems
- Logging, alerting and escalation for selected actions
What Botnet tests.
Coverage follows reachable trust decisions and agreed risk, with destructive or disruptive actions excluded unless explicitly authorized.
Starting trust
Exact role, entitlements, device and network position granted to the scenario.
Data boundary
Whether the identity can discover, aggregate or access data beyond intended need.
Privilege
Reachable role, group or administrative changes within authorization.
Process
Approval, separation-of-duty and verification gates around material actions.
Movement
Approved paths between applications, infrastructure or cloud resources.
Visibility
Whether selected behaviors create useful signals and escalation.
How the work progresses.
- 01
Scenario
Define actor type, starting access, objective and business question.
- 02
Approve
Complete security, legal, HR and privacy review as applicable.
- 03
Provision
Use a controlled identity and synthetic/minimized data where possible.
- 04
Progress
Test only approved access and process paths.
- 05
Observe
Record control outcomes without broad employee monitoring.
- 06
Close
Revoke access, account for evidence and deliver process-focused findings.
EVIDENCE + ACTION
What the customer receives.
- Scenario and starting-access definition
- Trust and privilege-path diagram
- Validated control and process findings
- Minimized evidence and activity timeline
- Prioritized access/process improvements
- Closeout and re-test result where agreed
Evidence over assumption.
01Tests controls, not individual trustworthiness
02Synthetic or minimized evidence preferred
03Technical and business-process paths considered together
04Explicit access revocation and evidence closeout
Before scoping.
Does this monitor real employees?
No employee-monitoring capability is claimed. This page describes a bounded simulation using an authorized scenario and controlled identity.
Can production data be accessed?
Only within explicit scope and safeguards. Synthetic or minimized data should be used where it can answer the same control question.
Is this part of a Red Team assessment?
It can be a standalone scenario or an agreed starting condition within a broader exercise.
Define the target, constraints and required evidence.
An assessment request starts a scoping conversation. It does not authorize testing. Work proceeds only after scope acceptance, executed authorization/SOW and kickoff.