New Report: The State of AI Governance 2026

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Penetration Testing

Red Team Assessment

By purposefully circumventing your technical and administrative security controls, a red team assessment is the closest you can get to confirmation of how well-equipped your organization is to defend against a skilled and persistent attacker.

Contact a Specialist Start Scoping Your Next Pen Test

What Happens During a Red Team Assessment?

Our primary red team objective is to conduct a comprehensive assessment of your organization's technical infrastructure, as well as evaluate your people and procedures. Upon reaching the predetermined objective, we deliberately attempt to trigger your incident response system to test its effectiveness in detecting and responding to our actions.

Throughout the assessment, we meticulously document any indicators of compromise, exploits, and instances of pivoting or accessing new shares. This information is crucial during the debrief with your defensive team at the conclusion of the engagement.

schellman-red-teaming-1

How We Work

Schellman’s Red Team Assessment Methodology

We run reproducible engagements that mirror real-world attackers, mapped to the MITRE ATT&CK framework so your SOC can analyze and repeat the findings. Payloads are customized to stay under the radar against your AV/EDR, and we try not to get caught, because that is how real adversaries operate. Every assessment follows a consistent process, and is shaped by the engagement path that fits your risk profile.

  • Goal Setting
  • Reconnaissance
  • Vulnerability Discovery
  • Exploitation
  • Post Exploitation
  • Credential Access & Lateral Movement
  • Exfiltration
  • Kill-Chain Analysis
  • Reporting
schellman-red-teaming-1

A Red Team Assessment Can Help You:

https://www.schellman.com/hubfs/social-prepare-for-real-world-attacks.svg

Identify Information Security Gaps

Surface vulnerabilities in processes such as misconfigurations with log aggregation and AV/EDR configurations.

https://www.schellman.com/hubfs/staff-awareness.svg

Empower Your Defense Team

Log and categorize the tactics, techniques, and procedures (TTPs) used in the test so your team has actionable data for continued work.

Four Engagement Paths

Pick the starting conditions that match the threat you care about most, from zero-knowledge external testing to assume-breach, supply chain, and physical scenarios.

The External Threat (Zero-Knowledge)

Scenario: We start where the world starts. No passwords, no badges, just the public Internet.

  • OSINT & Recon: We map your digital shadow (including leaked credentials, GitHub secrets, DNS enumeration, and more).
  • Perimeter Breach: Manual enumeration of edge devices and web applications.
  • Social Engineering: Custom-tailored phishing, vishing, smishing, or social media campaigns.
  • Post-Exploitation: If we get in, we attempt to identify and gain access to high-value assets and perform simulated data exfiltration.

Goal: Test edge defense, social awareness, and internal access detections.

The Assume Breach (The Insider)

Scenario: A user is compromised. Or worse, a disgruntled employee decides to work with an APT.

  • The Foothold: We start with an employee account, standard-issue laptop, access to an internal email account, payload, or a virtual machine.
  • Lateral Movement: Evaluate the internal assets to determine points of interest or vulnerabilities.
  • Internal Deception: Test social engineering between departments.
  • Data Exfiltration: Attempt to move sensitive files out of the network without triggering alarms.

Goal: Test your internal detection (EDR/SIEM) and privilege escalation barriers, with custom payloads built to stay under the radar.

The Supply Chain (The Trusted Partner)

Scenario: You do not get breached by a stranger at the firewall. You get popped by an update you chose to install. We simulate a compromised library or package landing through the same trust path your teams already use.

  • Trojaned Update: Stage a benign but malicious-looking library or package update and see if it is trusted, installed, and executed like any other patch.
  • Dependency Reach: Trace how far a poisoned package travels through registries, lockfiles, and transitive dependencies before anyone notices.
  • Pipeline Carry-Through: Attempt to ride that update through build and deploy into commercial or agreed-upon secured environments.
  • Post-Install Actions: After the update lands, attempt the follow-on moves an attacker would take and measure what detection actually occurs.

Goal: Test whether trusted-update compromise is caught across dependency controls, pipeline gates, and runtime detection, not whether configs merely look audit-clean.

The Physical Breach (The On-Site Test)

Scenario: We test the locks, the guards, and the human helpful nature.

  • Proximity Testing: Tailgate, badge clone, and socially engineer the front desk or other employees.
  • The Clean Desk Audit: Search for passwords on sticky notes, unlocked workstations and easy access to devices.
  • Hardware Injection: Plug keyloggers or other USB devices into employee workstations and connect rogue devices to accessible Ethernet ports.
  • Wireless Access: Attempt to breach wireless networks to obtain internal access.

Goal: Test your physical security, employee awareness, company policies, and wireless configuration.

Is Schellman the Right Firm for You?

Schellman does perform red team assessments. Our Penetration Testing Team continues to grow and is currently comprised of individuals from different backgrounds including former developers, system administrators, and lifelong security professionals. We put serious craft into payload development so engagements stay under the radar against modern EDR, a bar many red teams do not clear. Our team is incredibly experienced, and collectively holds the following professional certifications, among others.

Frequently Asked Questions

How long will a red team assessment test take?

What does a red team assessment cost at Schellman?

How is a red team engagement different than a penetration test?

What is the goal of a red team assessment?

What kinds of organizations should conduct a red team engagement?

Get started with your Red Team Assessment

Our team of practice leaders, not sales, are ready to talk and help determine your best next steps.

Start Scoping Your Penetration Test Contact a Specialist