Skip to content
OPS-LIVE
RUNBOOK / CAPABILITIES

Capabilities organized the way adversaries think: by ATT&CK tactic, not by product SKU.

What follows is not a service catalog dressed in marketing copy. It is the working set of tradecraft we deploy against client environments — indexed by MITRE ATT&CK tactic, staffed by operators with a paper trail in that exact domain, and priced around findings rather than head-hours. Read it the way you would read an after-action report.

  • Operator-led70% ex-intel / Fortune 100
  • Time to first critical72h median
  • Engagements to date612 across 4 verticals
MITRE ATT&CK COVERAGE

Fourteen ATT&CK tactics. One playbook per engagement — never an off-the-shelf template.

Every engagement is built from a custom playbook mapped to the full ATT&CK Enterprise matrix. Below is the working surface — the four columns we exercise at depth on every active engagement, and the dense sub-modules we pull in when a buyer's threat model demands them.

TA0043

Reconnaissance

OSINT harvesting, attacker-aligned asset enumeration, supply-chain surface mapping. We mirror what an APT would learn before the first packet leaves their infrastructure.

  • Active scanning
  • Gather victim host info
  • Phishing for info
TA0001

Initial Access

Spearphishing, edge-device exploitation, public-facing app abuse. Validates whether your perimeter is a boundary or a suggestion. Includes mobile (mDNS, MMS) and federated-identity paths.

  • Valid accounts
  • Exploit public-facing app
  • Drive-by compromise
TA0008

Lateral Movement

Post-compromise pivot through AD, Entra ID, EKS, and SaaS trust boundaries. Where we find 70% of critical-severity findings on first-time engagements.

  • Remote services
  • Use alternate auth material
  • Internal spearphishing
TA0040

Impact

Data destruction, ransomware-emulation (non-encrypting), defacement, denial-of-service within agreed guardrails. The kill-chain endpoint that executives actually want to see tested.

  • Data encrypted for impact
  • Service stop
  • Resource hijacking
+ also covered TA0002 Execution TA0003 Persistence TA0004 Privilege Escalation TA0005 Defense Evasion TA0006 Credential Access TA0007 Discovery TA0009 Collection TA0011 Command & Control TA0010 Exfiltration
BY THE NUMBERS

What our coverage actually produces — across 612 engagements since 2017.

72hrs
Median time to first critical-severity finding on first-time engagements
68%
Findings that convert into a validated exploit chain during the same engagement
41cves
Published CVE credits since 2019, including 3 vendor-acknowledged criticals
82%
Of consultant headcount holds active U.S. SECRET or equivalent national clearance

Figures derived from 612 completed engagements across financial services, SaaS, healthcare, and federal verticals through 2024.

CAPABILITY MODULES

Six capability modules. Each one staffed by operators with a paper trail in that tradecraft.

We don't rotate generalist consultants across modules. The lead on your cloud engagement has shipped a CVEs in the AWS/Azure control plane. The lead on your purple-team has run joint operations with a Tier-1 SOC for at least four years.

  1. 01 / Adversary Emulation

    Adversary emulation, scoped to a named threat actor.

    Full-scope emulation of a specific APT (e.g. APT29, FIN7, Volt Typhoon) against your environment, using their real TTPs as documented in CTI. Outputs include a kill-chain narrative, detection-coverage delta, and a SOC playbook tuned to your stack.

    • ATT&CK-mapped execution log with detection gap analysis
    • Custom Sigma/Splunk/Elastic rules tuned to your telemetry
    • Executive narrative + 90-day hardening roadmap
  2. 02 / Continuous Red-Team

    Continuous red-team operations — 14 weeks average.

    Always-on testing against a defined crown-jewel target set. Operators work against your blue team in real time via a dedicated Slack war-room with sub-15-minute response. Outcome-based pricing on Tier-3: 100% of the fee is contingent on validated findings beyond automated baseline.

    • Weekly finding triage with severity and reproducer
    • Quarterly purple-team sync + detection telemetry review
    • Final adversary-emulation capstone against an emerging APT
  3. 03 / Purple-Team Exercises

    Joint operator + defender exercises with measurable detection uplift.

    Structured, time-boxed engagements where Phantom X operators execute pre-agreed TTPs and your SOC tunes detections in real time. We leave behind a coverage matrix mapped to ATT&CK, with before/after MTTD/MTTR metrics.

    • Pre-built exercise pack tailored to your SIEM/EDR stack
    • Live injection dashboard (no script needed — printed runbook)
    • Detection coverage delta report, scoped to your critical assets
  4. 04 / Web, Mobile, API

    Web, mobile, and API testing with offensive depth beyond scanner output.

    Authenticated testing of public-facing and internal applications, including GraphQL, gRPC, OAuth/OIDC, mobile (iOS/Android, including mDNS), and federated SSO paths. Findings are demonstrated as exploit chains, not isolated CVSS scores.

    • Authenticated business-logic testing across roles
    • Mobile binary reverse + runtime instrumentation (Frida/MobSF)
    • Exploit chain narrative with reproducer scripts
  5. 05 / Cloud & Identity

    Cloud and identity — AWS, Azure, GCP, Kubernetes, and SaaS trust boundaries.

    We attack the seams: cross-account role assumption, OIDC federation abuse, EKS/EKS-Anywhere privilege paths, GitHub Actions→IAM pivots, and SaaS-to-SaaS OAuth grants. Includes detection engineering for CloudTrail/GuardDuty/Defender for Cloud.

    • Cloud control-plane attack-path mapping (BloodHound-AD + custom)
    • CI/CD pipeline compromise scenarios
    • Detection-as-code for the four major CSPs
  6. 06 / AI / ML Systems

    Offensive testing of AI/ML systems — model, data, and supply chain.

    Targeted testing of LLM applications, RAG pipelines, agentic workflows, and ML inference endpoints. Covers prompt injection, training-data extraction, model inversion, supply-chain (HuggingFace/Model Card) abuse, and GPU/accelerator-side paths where in scope.

    • OWASP LLM Top 10 + ATLAS-aligned coverage
    • Prompt-injection and indirect-injection scenarios
    • Model card and supply-chain provenance review
FEDERAL & CLEARED OPERATIONS

Cleared operations for federal, state, and CJIS-bound engagements.

Phantom X maintains a U.S. SECRET-cleared facility in Reston, VA and a second cleared operations hub in Tel Aviv. We hold SOC 2 Type II, ISO 27001, and FedRAMP Moderate authorizations, and our operators handle CJIS-controlled data for state-level agencies under documented handling procedures.

  • FacilityU.S. SECRET-cleared, Reston, VA — 11710 Plaza America Drive, Suite 420
  • ComplianceSOC 2 Type II · ISO 27001 · FedRAMP Moderate
  • CJISCompliant handling for state agencies and law-enfusion-adjacent workloads
  • Clearance density82% of consultants hold active national clearance or equivalent
  • OriginFounded by former NSA TAO and CrowdStrike Services operators (2017)
Inside a U.S. SECRET-cleared Phantom X operations room in Reston, VA
Cleared ops room, Reston HQ. Photography restricted; render shown for illustration only.
FREQUENTLY ASKED

What buyers ask before scoping an engagement.

How does scoping actually work?

Scoping is a 60–90 minute working session with one of our principals and a senior operator from the relevant capability module. You bring your environment diagram, crown-jewel asset list, and any prior test reports. We come back within 48 hours with a written statement of work: in-scope targets, out-of-scope guardrails, ATT&CK tactics covered, team composition, and a fixed or outcome-based fee.

Who exactly will be on the engagement?

Every engagement has a named lead operator, a named secondary, and a designated client-success contact. You'll see resumes, clearance levels, and prior engagement references before kickoff. If the named lead is unavailable at any point during the engagement, we provide a 48-hour written notice and a replacement with comparable tradecraft depth.

Do you run intel-grade threat modeling?

Yes. Our threat-modeling practice uses actor-aligned scenario development drawn from our own CTI team's tracking of 40+ named APTs and criminal crews. We don't subscribe to a single commercial feed — we correlate from primary sources (vendor advisories, leaked playbooks, CISA alerts, court documents) and rebuild the relevant TTP set for your environment before the first day of testing.

What does reporting and cadence look like?

Continuous engagements run with a 24/7 Slack war-room, sub-15-minute operator response, and a weekly finding triage. Time-boxed engagements ship a written report on day 5 of closeout, plus a live walkthrough with your security leadership and an optional board-ready executive summary. All findings are delivered with a reproducer script and a recommended remediation owner.

Can your team operate under our security clearance posture?

Yes — for federal, state, and CJIS-bound engagements we operate from a U.S. SECRET-cleared facility in Reston, VA. Our operators hold active clearances at SECRET/TS levels or the equivalent national clearance from partner nations. We sign BAAs, MOUs, and the specific NDAs your legal team requires before kickoff.

Still weighing the fit? Brief us on your environment and we'll tell you on the call whether a scoped engagement — or a peer referral — is the right move.

Book a Red-Team Scoping Call