Reconnaissance
OSINT harvesting, attacker-aligned asset enumeration, supply-chain surface mapping. We mirror what an APT would learn before the first packet leaves their infrastructure.
What follows is not a service catalog dressed in marketing copy. It is the working set of tradecraft we deploy against client environments — indexed by MITRE ATT&CK tactic, staffed by operators with a paper trail in that exact domain, and priced around findings rather than head-hours. Read it the way you would read an after-action report.
Every engagement is built from a custom playbook mapped to the full ATT&CK Enterprise matrix. Below is the working surface — the four columns we exercise at depth on every active engagement, and the dense sub-modules we pull in when a buyer's threat model demands them.
OSINT harvesting, attacker-aligned asset enumeration, supply-chain surface mapping. We mirror what an APT would learn before the first packet leaves their infrastructure.
Spearphishing, edge-device exploitation, public-facing app abuse. Validates whether your perimeter is a boundary or a suggestion. Includes mobile (mDNS, MMS) and federated-identity paths.
Post-compromise pivot through AD, Entra ID, EKS, and SaaS trust boundaries. Where we find 70% of critical-severity findings on first-time engagements.
Data destruction, ransomware-emulation (non-encrypting), defacement, denial-of-service within agreed guardrails. The kill-chain endpoint that executives actually want to see tested.
Figures derived from 612 completed engagements across financial services, SaaS, healthcare, and federal verticals through 2024.
We don't rotate generalist consultants across modules. The lead on your cloud engagement has shipped a CVEs in the AWS/Azure control plane. The lead on your purple-team has run joint operations with a Tier-1 SOC for at least four years.
Full-scope emulation of a specific APT (e.g. APT29, FIN7, Volt Typhoon) against your environment, using their real TTPs as documented in CTI. Outputs include a kill-chain narrative, detection-coverage delta, and a SOC playbook tuned to your stack.
Always-on testing against a defined crown-jewel target set. Operators work against your blue team in real time via a dedicated Slack war-room with sub-15-minute response. Outcome-based pricing on Tier-3: 100% of the fee is contingent on validated findings beyond automated baseline.
Structured, time-boxed engagements where Phantom X operators execute pre-agreed TTPs and your SOC tunes detections in real time. We leave behind a coverage matrix mapped to ATT&CK, with before/after MTTD/MTTR metrics.
Authenticated testing of public-facing and internal applications, including GraphQL, gRPC, OAuth/OIDC, mobile (iOS/Android, including mDNS), and federated SSO paths. Findings are demonstrated as exploit chains, not isolated CVSS scores.
We attack the seams: cross-account role assumption, OIDC federation abuse, EKS/EKS-Anywhere privilege paths, GitHub Actions→IAM pivots, and SaaS-to-SaaS OAuth grants. Includes detection engineering for CloudTrail/GuardDuty/Defender for Cloud.
Targeted testing of LLM applications, RAG pipelines, agentic workflows, and ML inference endpoints. Covers prompt injection, training-data extraction, model inversion, supply-chain (HuggingFace/Model Card) abuse, and GPU/accelerator-side paths where in scope.
Phantom X maintains a U.S. SECRET-cleared facility in Reston, VA and a second cleared operations hub in Tel Aviv. We hold SOC 2 Type II, ISO 27001, and FedRAMP Moderate authorizations, and our operators handle CJIS-controlled data for state-level agencies under documented handling procedures.
Scoping is a 60–90 minute working session with one of our principals and a senior operator from the relevant capability module. You bring your environment diagram, crown-jewel asset list, and any prior test reports. We come back within 48 hours with a written statement of work: in-scope targets, out-of-scope guardrails, ATT&CK tactics covered, team composition, and a fixed or outcome-based fee.
Every engagement has a named lead operator, a named secondary, and a designated client-success contact. You'll see resumes, clearance levels, and prior engagement references before kickoff. If the named lead is unavailable at any point during the engagement, we provide a 48-hour written notice and a replacement with comparable tradecraft depth.
Yes. Our threat-modeling practice uses actor-aligned scenario development drawn from our own CTI team's tracking of 40+ named APTs and criminal crews. We don't subscribe to a single commercial feed — we correlate from primary sources (vendor advisories, leaked playbooks, CISA alerts, court documents) and rebuild the relevant TTP set for your environment before the first day of testing.
Continuous engagements run with a 24/7 Slack war-room, sub-15-minute operator response, and a weekly finding triage. Time-boxed engagements ship a written report on day 5 of closeout, plus a live walkthrough with your security leadership and an optional board-ready executive summary. All findings are delivered with a reproducer script and a recommended remediation owner.
Yes — for federal, state, and CJIS-bound engagements we operate from a U.S. SECRET-cleared facility in Reston, VA. Our operators hold active clearances at SECRET/TS levels or the equivalent national clearance from partner nations. We sign BAAs, MOUs, and the specific NDAs your legal team requires before kickoff.
Still weighing the fit? Brief us on your environment and we'll tell you on the call whether a scoped engagement — or a peer referral — is the right move.
Book a Red-Team Scoping Call