Skip to content
OPS-LIVE

// ENGAGEMENT MODELS

Four engagement models.
One operator menu.

Phantom X engagements are ATT&CK-mapped, fixed-scope offensive programs — not scan-and-go pentests. Across 600+ engagements since 2017, our median time-to-first-critical-finding lands inside the first 72 hours of active testing.

  • Fixed-scope SOW
  • Median 72h to critical finding
  • 14-week continuous default

// 01 — FOUR ENGAGEMENT ARCHETYPES

Pick the model that maps to your threat surface.

Each Phantom X engagement is delivered by a named lead operator, scored against a custom adversary playbook, and closed with a kill-chain narrative — not a vulnerability scan dump.

01 8–14 wks

Red-Team Engagement

Goal-based, full-scope offensive operation against your production environment. Objectives are co-defined with the CISO; methods are operator-chosen.

  • objectivePre-defined crown-jewel target
  • scopePeople, process, prod, cloud
  • comms24/7 Slack war-room
  • closeoutKill-chain narrative + ATT&CK heatmap
Scope this engagement →
02 4–6 wks

Purple-Team Exercise

Joint attacker–defender rehearsal. Our operators run live techniques in coordination with your SOC to validate detection and response in real time.

  • objectiveDetection coverage uplift
  • scopeSpecific ATT&CK tactic subset
  • commsLive on-call with your SOC
  • closeoutDetection-rule gap report + tuning
Scope this engagement →
03 12–24 wks

Adversary-Emulation Program

Continuous emulation of a named APT (e.g. FIN7, APT29, Scattered Spider) using their real TTPs, infrastructure, and dwell-time patterns.

  • objectiveNamed-actor resilience validation
  • scopeMulti-quarter, repeated cycles
  • commsWeekly exec + daily ops brief
  • closeoutQuarterly resilience scorecard
Scope this engagement →
04 Standby retainer

Incident-Response Support

Pre-vetted surge capacity for active intrusions. Our operators embed with your IR lead for containment, root-cause, and adversary eviction.

  • objectiveContainment + eviction
  • scopeActivated on declared incident
  • comms4-hour SLA to deploy
  • closeoutLessons-learned + hardening plan
Scope this engagement →

// 02 — DELIVERY TIERS

Three tiers. Pick by program maturity, not by budget.

Phantom X engagements ship in three delivery tiers. The tier sets pricing model, deliverable depth, and operator seniority — not the scope itself, which is always negotiated per SOW.

TIER 1

Recon

A scoped, time-boxed discovery engagement to map your external attack surface before committing to a longer program.

duration
2–4 weeks
pricing
Fixed-fee SOW
team
1 lead + 1 operator
deliverable
Attack-surface map + prioritized finding queue

BEST FOR

First-time buyers; pre-funding diligence; boards asking "where are we exposed?"

TIER 3

Contingent

Outcome-priced. 100% of the fee is contingent on validated findings beyond an automated baseline.

duration
Open-ended until objectives met
pricing
Outcome-based, milestone-gated
team
3 leads + named operators from Tier 2
deliverable
Continuous finding feed + exec narrative on close

BEST FOR

Mature buyers with hard resilience objectives (e.g. M&A diligence, regulator-mandated validation).

// 03 — A CANONICAL 14-WEEK ENGAGEMENT

Five phases. ATT&CK-mapped. Observable end-to-end.

Below is the default phase structure for a Continuous-tier engagement. Each phase has a named lead, a written weekly cadence, and a defined exit criterion. You see what we're doing while we do it.

  1. 01

    WEEK 0–1 · ATT&CK TA0043 (Reconnaissance)

    Scoping & Rules of Engagement

    We sit with your CISO and security architect to lock the SOW: in-scope assets, out-of-scope actions, communication channels, legal letters, escalation paths. Nothing moves past week 1 until this is signed.

  2. 02

    WEEK 2–3 · TA0043 / TA0042 (Resource Dev)

    Intel & Recon

    External attack-surface mapping, OSINT collection on employees, infrastructure enumeration, and target prioritization. Output is a written intel brief shared with your team before initial access begins.

  3. 03

    WEEK 4–7 · TA0001 / TA0002 / TA0003

    Initial Access

    Operator-led attempts to establish a foothold via phishing, exposed services, identity weaknesses, or third-party trust. Median time-to-first-critical-finding across 600+ engagements: 72 hours into this phase.

  4. 04

    WEEK 8–12 · TA0003 / TA0008 / TA0005

    Persistence & Lateral Movement

    Living-off-the-land tradecraft, credential abuse, AD/EntraID traversal, and pivot toward the scoped crown-jewel target. Weekly check-ins with your SOC if a purple-team overlay is in scope.

  5. 05

    WEEK 13–14 · TA0006 / Reporting

    Reporting & Retest

    Close-out: executive narrative, ATT&CK-mapped findings report, kill-chain narrative, IOC package, and a 30-day retest window to validate remediation against the original finding set.

// 04 — WHAT LANDS ON YOUR DESK AT CLOSE

Six deliverables. Every engagement. No upsells.

A Phantom X engagement always ships the same six artifacts at close-out. The depth scales with tier — Tier-1 Recon ships an abridged set; Tier-2 Continuous ships the full manifest.

D-01

ATT&CK-Mapped Findings Report

Each finding is scored against a specific MITRE ATT&CK technique ID, with reproduction steps, affected asset inventory, and a remediation owner assignment template. The format is consistent across all four engagement archetypes.

D-02

Executive Narrative

A 6–10 page read for your CISO and board: what we attempted, what worked, what didn't, and the business risk delta between day-0 and day-90.

D-03

Kill-Chain Narrative

The full attack path from initial foothold to objective, told as a single story. Built for IR tabletop rehearsal and SOC detection-tuning review.

D-04

IOC Package & Detection Rules

Every artifact dropped, every domain registered, every hash, and every behavior observed — packaged in STIX 2.1 with a matching Sigma/YARA rule bundle your SOC can deploy immediately.

D-05

Retest Certificate

A 30-day retest window after close. We re-run the original finding set and issue a remediation certificate that maps each finding to closed/open/partially-mitigated status.

D-06

24/7 Slack War-Room

Active for the full engagement duration plus 14 days post-close. Sub-15-minute operator response on weekdays, sub-60-minute on weekends. Operator-led, not a triage bot.

// 05 — A NOTE FROM THE OPERATOR DESK

Read this before you book.

Phantom X is built for security leaders who already accept that their defenses have blind spots and want those blind spots mapped by operators, not scanners. If that is you, the scoping call is the right next step.

We work best with CISOs, heads of security, and security architects at mid-market and enterprise organizations who can name their crown-jewel assets, who have a SOC or managed detection partner they trust, and who measure their program against ATT&CK coverage rather than checkbox compliance. Most of our buyers come from financial services, SaaS, healthcare, and critical infrastructure — verticals where a real adversary modeling exercise pays for itself within a quarter.

We are the wrong fit if you are shopping for a low-cost vulnerability scan to satisfy a one-time audit checkbox; if your environment has no detection capability to validate against; or if the engagement is being procured as a marketing deliverable rather than an operational input. The Tier-3 Contingent model in particular requires a buyer who can absorb operator-grade findings and turn them into a 90-day hardening plan with budget and authority. Without that, the engagement produces a report nobody reads.

If the above fits, the next step is a 30-minute scoping call. Bring your SOW template, your last pen-test report, and a list of the three assets you most fear losing. We will tell you honestly whether a Phantom X engagement is the right vehicle — and if it is not, we will name two firms that are.

— The Phantom X operator desk · Reston, VA & Tel Aviv