RED TEAM / TRUST PATH

Start with legitimate access. Measure where trust stops.

The engagement tests how legitimate access can be misused or expanded—not whether a particular employee is trustworthy. A synthetic or controlled identity starts with agreed permissions, then tests data, privilege, process and monitoring boundaries toward a named objective.

AUTHORIZED ENGAGEMENT MODEL
01Scenario02Approve03Provision04Progress

REQUEST → SCOPE → AUTHORIZE → KICKOFF → EXECUTE

ENGAGEMENT LENS

Each boundary is tested independently, then examined as part of the complete path.

  1. ACCESS
  2. DATA
  3. PRIVILEGE
  4. PROCESS
  5. OBJECTIVE

LEGITIMATE ACCESS / EXPLICIT BOUNDARIES

01

ASSESSMENT BOUNDARY

What is being assessed?

The engagement boundary is defined by systems, identities, workflows and restrictions—not only a list of URLs or assets.

  • Authorized starting identities and permissions
  • Sensitive-data access boundaries
  • Privilege expansion paths
  • Administrative and business-process controls
  • Movement between approved systems
  • Logging, alerting and escalation for selected actions
02 / TEST MODEL

What Botnet tests.

Coverage follows reachable trust decisions and agreed risk, with destructive or disruptive actions excluded unless explicitly authorized.

01

Starting trust

Exact role, entitlements, device and network position granted to the scenario.

02

Data boundary

Whether the identity can discover, aggregate or access data beyond intended need.

03

Privilege

Reachable role, group or administrative changes within authorization.

04

Process

Approval, separation-of-duty and verification gates around material actions.

05

Movement

Approved paths between applications, infrastructure or cloud resources.

06

Visibility

Whether selected behaviors create useful signals and escalation.

03 / ENGAGEMENT

How the work progresses.

  1. 01

    Scenario

    Define actor type, starting access, objective and business question.

  2. 02

    Approve

    Complete security, legal, HR and privacy review as applicable.

  3. 03

    Provision

    Use a controlled identity and synthetic/minimized data where possible.

  4. 04

    Progress

    Test only approved access and process paths.

  5. 05

    Observe

    Record control outcomes without broad employee monitoring.

  6. 06

    Close

    Revoke access, account for evidence and deliver process-focused findings.

04

EVIDENCE + ACTION

What the customer receives.

  • Scenario and starting-access definition
  • Trust and privilege-path diagram
  • Validated control and process findings
  • Minimized evidence and activity timeline
  • Prioritized access/process improvements
  • Closeout and re-test result where agreed
05 / BOTNET APPROACH

Evidence over assumption.

01Tests controls, not individual trustworthiness

02Synthetic or minimized evidence preferred

03Technical and business-process paths considered together

04Explicit access revocation and evidence closeout

06 / QUESTIONS

Before scoping.

Does this monitor real employees?

No employee-monitoring capability is claimed. This page describes a bounded simulation using an authorized scenario and controlled identity.

Can production data be accessed?

Only within explicit scope and safeguards. Synthetic or minimized data should be used where it can answer the same control question.

Is this part of a Red Team assessment?

It can be a standalone scenario or an agreed starting condition within a broader exercise.

NEXT STEP

Define the target, constraints and required evidence.

An assessment request starts a scoping conversation. It does not authorize testing. Work proceeds only after scope acceptance, executed authorization/SOW and kickoff.