Nation-state operator pedigree
70% of our 38 consultants come from offensive roles at NSA TAO, Israeli Unit 8200, GCHQ, and the in-house red teams of Fortune 100 firms. Founded in 2017 by former NSA TAO and CrowdStrike Services operators.
OFFENSIVE SECURITY · RED-TEAM OPERATIONS
Phantom X runs continuous red-team engagements modeled on real APT tradecraft. In 94% of first-time client environments, our operators surface a critical-severity finding within the first 72 hours of active testing.
01 · WHY CISOS HIRE PHANTOM X
Most red-team vendors run a templated scan, ship a PDF, and call it done. Our engagements are run by former NSA TAO, Unit 8200, GCHQ, and Fortune 100 in-house red-team operators, against custom ATT&CK-mapped playbooks per environment.
70% of our 38 consultants come from offensive roles at NSA TAO, Israeli Unit 8200, GCHQ, and the in-house red teams of Fortune 100 firms. Founded in 2017 by former NSA TAO and CrowdStrike Services operators.
Across 600+ engagements since 2017, our median time-to-first-critical-finding is 72 hours. 94% of first-time clients had at least one critical-severity finding in week one — typically before automated baseline scans even complete.
Every engagement is built against a threat-model derived from your sector, stack, and likely adversaries — no off-the-shelf scan-and-go deliverables. Playbooks are MITRE ATT&CK mapped cell-by-cell, with detection-engineering guidance for each step.
Our operators hold published credits on 41 CVE disclosures since 2019, including three vendor-acknowledged critical findings. Bug-bounty triage partner for two of the top five U.S. banks and three Fortune 100 SaaS platforms.
Active engagements run in a dedicated Slack war-room with a named lead operator on rotation. Median response time under 15 minutes, 24/7, including weekends — so a finding at 02:00 doesn't wait until 09:00 Monday to be triaged.
On Tier-3 adversary-emulation programs, 100% of our fee is contingent on validated findings beyond the automated baseline. You pay for tradecraft that lands, not hours logged against a statement of work.
02 · HOW AN ENGAGEMENT RUNS
A Phantom X engagement is not a point-in-time pentest. It is a 14-week continuous program on average, structured around the real kill-chain an adversary would walk — with a purple-team validate phase that hands detection-engineering back to your SOC.
Two-week scoping. We meet your CISO, SOC lead, and cloud architects to define in-scope assets, rules of engagement, and a named adversary persona (FIN12, APT29, Volt Typhoon, or a custom profile built from your threat intel).
OSINT, attack-surface mapping, and assumption-driven adversary emulation against external, internal, and cloud tiers. We weaponize real CVE chains where in-scope, including our own published credits, and document the kill-chain path to first foothold.
We emulate the named adversary across persistence, privilege escalation, defense evasion, credential access, lateral movement, and exfiltration paths. Custom tooling, custom payloads, custom C2 — nothing off-the-shelf.
Findings are validated live with your blue team in a co-piloted purple-team session. Each validated finding ships with a detection-engineering addendum: Splunk/Elastic query, Sigma rule, and EDR tuning guidance.
Executive brief for the board, technical report for engineering, and a 30-day re-test on critical findings. Continuous-program clients roll directly into the next 14-week cycle against an evolved adversary profile.
03 · ENGAGEMENT SHAPES
Beyond a flat red-team menu: programs tailored to the question your board is asking, your cloud estate, your AI/ML stack, or your bug-bounty pipeline.
FLAGSHIP
Continuous 14-week program modeled on a named APT (FIN12, APT29, Volt Typhoon, Lazarus). Custom ATT&CK-mapped playbook per engagement. This is our most-bought shape — 38 active engagements across financial services, SaaS, healthcare, and federal verticals.
See adversary profilesCO-PILOTED
Time-boxed co-piloted exercise with your SOC. We emulate; your blue team detects. Each technique lands with a detection rule, EDR tuning note, and runbook step.
CLOUD-NATIVE
Identity-first cloud offensive program. IAM escalation paths, cross-account pivots, CI/CD supply-chain compromise, Kubernetes runtime escapes.
AI / ML
Adversarial inputs, model exfiltration, training-data poisoning, prompt-injection paths against LLM-backed features. Built for CTOs of AI/ML platforms.
FEDERAL
Cleared facility (U.S. SECRET), CJIS-compliant ops, FedRAMP Moderate alignment. SOC 2 Type II and ISO 27001 certified. Built for federal contractors and state-level engagements.
TRIAGE
24/7 triage, severity validation, and researcher management for in-scope bug-bounty programs. Trusted by two of the top five U.S. banks and three Fortune 100 SaaS platforms.
See triage SLA04 · TRACK RECORD
05 · PEER SIGNAL
"Our previous vendor ran a two-week pentest, shipped a 90-page PDF, and called it done. Phantom X embedded with our SOC for fourteen weeks and surfaced a credential-rotation gap in our CI/CD that two prior firms had walked past. The 30-day retest on the critical finding was the moment I knew we'd finally hired a real red team."
A scoping call is 30 minutes. It includes a free pre-engagement threat-model sketch and a no-pressure quote.
Book a Red-Team Scoping Call