Skip to content
OPS-LIVE

OFFENSIVE SECURITY · RED-TEAM OPERATIONS

Operator-led red teams that find what your EDR misses — before an adversary does.

Phantom X runs continuous red-team engagements modeled on real APT tradecraft. In 94% of first-time client environments, our operators surface a critical-severity finding within the first 72 hours of active testing.

  • 612Engagements since 2017
  • 38Operators · 7 countries
  • 72hMedian time-to-first-critical

01 · WHY CISOS HIRE PHANTOM X

Operators, not scanners — six reasons Phantom X outperforms the boutique default.

Most red-team vendors run a templated scan, ship a PDF, and call it done. Our engagements are run by former NSA TAO, Unit 8200, GCHQ, and Fortune 100 in-house red-team operators, against custom ATT&CK-mapped playbooks per environment.

01

Nation-state operator pedigree

70% of our 38 consultants come from offensive roles at NSA TAO, Israeli Unit 8200, GCHQ, and the in-house red teams of Fortune 100 firms. Founded in 2017 by former NSA TAO and CrowdStrike Services operators.

02

72-hour median time-to-first-critical

Across 600+ engagements since 2017, our median time-to-first-critical-finding is 72 hours. 94% of first-time clients had at least one critical-severity finding in week one — typically before automated baseline scans even complete.

03

Custom ATT&CK-mapped playbooks

Every engagement is built against a threat-model derived from your sector, stack, and likely adversaries — no off-the-shelf scan-and-go deliverables. Playbooks are MITRE ATT&CK mapped cell-by-cell, with detection-engineering guidance for each step.

04

41 published CVE credits since 2019

Our operators hold published credits on 41 CVE disclosures since 2019, including three vendor-acknowledged critical findings. Bug-bounty triage partner for two of the top five U.S. banks and three Fortune 100 SaaS platforms.

05

24/7 war-room, sub-15-minute response

Active engagements run in a dedicated Slack war-room with a named lead operator on rotation. Median response time under 15 minutes, 24/7, including weekends — so a finding at 02:00 doesn't wait until 09:00 Monday to be triaged.

06

Outcome-based pricing on Tier-3

On Tier-3 adversary-emulation programs, 100% of our fee is contingent on validated findings beyond the automated baseline. You pay for tradecraft that lands, not hours logged against a statement of work.

02 · HOW AN ENGAGEMENT RUNS

Five phases. One continuous loop. ATT&CK-mapped from scoping to report.

A Phantom X engagement is not a point-in-time pentest. It is a 14-week continuous program on average, structured around the real kill-chain an adversary would walk — with a purple-team validate phase that hands detection-engineering back to your SOC.

  1. PHASE 01

    Scope & Threat-Model

    Two-week scoping. We meet your CISO, SOC lead, and cloud architects to define in-scope assets, rules of engagement, and a named adversary persona (FIN12, APT29, Volt Typhoon, or a custom profile built from your threat intel).

    Deliverables · Threat-model brief · ATT&CK scope matrix · Rules of engagement · ROE sign-off

  2. PHASE 02

    Recon & Initial Access

    OSINT, attack-surface mapping, and assumption-driven adversary emulation against external, internal, and cloud tiers. We weaponize real CVE chains where in-scope, including our own published credits, and document the kill-chain path to first foothold.

    Tactics · TA0043 Recon · TA0001 Initial Access · TA0002 Execution

  3. PHASE 03

    Emulate & Persist

    We emulate the named adversary across persistence, privilege escalation, defense evasion, credential access, lateral movement, and exfiltration paths. Custom tooling, custom payloads, custom C2 — nothing off-the-shelf.

    Tactics · TA0003–TA0008 · Cloud + identity + endpoint surfaces in parallel

  4. PHASE 04

    Validate & Purple-Team

    Findings are validated live with your blue team in a co-piloted purple-team session. Each validated finding ships with a detection-engineering addendum: Splunk/Elastic query, Sigma rule, and EDR tuning guidance.

    Output · Validated findings · Sigma/Splunk detections · EDR tuning notes

  5. PHASE 05

    Report & Remediation Loop

    Executive brief for the board, technical report for engineering, and a 30-day re-test on critical findings. Continuous-program clients roll directly into the next 14-week cycle against an evolved adversary profile.

    Output · Exec brief · Technical report · 30-day retest · Next-cycle briefing

03 · ENGAGEMENT SHAPES

Five engagement types that match how security leaders actually buy offensive work in 2025.

Beyond a flat red-team menu: programs tailored to the question your board is asking, your cloud estate, your AI/ML stack, or your bug-bounty pipeline.

FLAGSHIP

Adversary Emulation

Continuous 14-week program modeled on a named APT (FIN12, APT29, Volt Typhoon, Lazarus). Custom ATT&CK-mapped playbook per engagement. This is our most-bought shape — 38 active engagements across financial services, SaaS, healthcare, and federal verticals.

See adversary profiles

CO-PILOTED

Purple-Team Exercise

Time-boxed co-piloted exercise with your SOC. We emulate; your blue team detects. Each technique lands with a detection rule, EDR tuning note, and runbook step.

CLOUD-NATIVE

Cloud Red-Team (AWS · GCP · Azure)

Identity-first cloud offensive program. IAM escalation paths, cross-account pivots, CI/CD supply-chain compromise, Kubernetes runtime escapes.

AI / ML

ML Pipeline Red-Team

Adversarial inputs, model exfiltration, training-data poisoning, prompt-injection paths against LLM-backed features. Built for CTOs of AI/ML platforms.

FEDERAL

Federal & CJIS-Compliant Operations

Cleared facility (U.S. SECRET), CJIS-compliant ops, FedRAMP Moderate alignment. SOC 2 Type II and ISO 27001 certified. Built for federal contractors and state-level engagements.

TRIAGE

Bug-Bounty Triage Partner

24/7 triage, severity validation, and researcher management for in-scope bug-bounty programs. Trusted by two of the top five U.S. banks and three Fortune 100 SaaS platforms.

See triage SLA

04 · TRACK RECORD

Six numbers you can verify against public signals.

612
Engagements completed across financial services, SaaS, healthcare, and federal verticals through 2024.
41
Published CVE credits since 2019, including 3 vendor-acknowledged critical findings.
94%
Of first-time clients had at least one critical-severity finding in the first week of testing.
72h
Median time-to-first-critical-finding across 600+ engagements since 2017.
4.9/5
Post-engagement satisfaction across 200+ verified client reviews.
38
Offensive-security consultants across 7 countries — Reston, VA HQ and Tel Aviv ops hub.
Recognition 'Red-Team Operator of the Year' — 2023 Global Cyber Awards (Keren Lahav, Lead Consultant)
Listed CSO Online 'Top 10 Boutique Red-Team Firms' — 2023 and 2024
Compliance SOC 2 Type II · ISO 27001 · FedRAMP Moderate
Clearance U.S. SECRET facility · CJIS-compliant operations

05 · PEER SIGNAL

"Our previous vendor ran a two-week pentest, shipped a 90-page PDF, and called it done. Phantom X embedded with our SOC for fourteen weeks and surfaced a credential-rotation gap in our CI/CD that two prior firms had walked past. The 30-day retest on the critical finding was the moment I knew we'd finally hired a real red team."

Director of Security Series D SaaS platform · 1,200 employees Verified post-engagement review · 2024

A scoping call is 30 minutes. It includes a free pre-engagement threat-model sketch and a no-pressure quote.

Book a Red-Team Scoping Call