UK security consultancy
Red-team exercises for systems that are difficult to test.
CYSTRIKE plans and runs adversary simulations, tests detection and response controls, and traces attack paths across identity, cloud and on-premise systems.
Work starts with a specific question and a written safety boundary. The handover includes the activity record, the evidence behind each finding and a retest your team can run again.
Work
Details →Adversary simulation
Plan and run a bounded exercise around an agreed objective, starting position and set of prohibited actions.
Detection testing
Follow one controlled action from the source event through collection, analytics and the responder’s queue.
Attack-path review
Check the important edges in an identity, cloud or hybrid path instead of treating a graph as proof.
Remediation and retest
Help implement the correction, then repeat the smallest test that shows whether it worked.
Writing
All notes →Exercises
All exercises →- Exercise charter
Write the scope, budget and stop conditions.
- Detection chain
Find the first stage you have not actually observed.
- Evidence chain
Put the control, change and final check in order.
Have a system or control you are not confident in?
Send a short description of the environment, what you need to learn and anything that must remain untouched. Do not send credentials or live customer data in the first email.
Contact CYSTRIKE