Adversary Simulation

Assumed Breach

Simulate an internal compromise to assess your organisation's ability to detect, contain, and mitigate real-world threats that bypass traditional perimeter defences.

Discuss an engagement
Objective
Post-breach containment
Maturity
Mature perimeter defences
Approach
Granted internal foothold
Result
Lateral movement evidence

Testing resilience beyond the perimeter

Perimeter defences are not infallible. Sophisticated adversaries consistently bypass external protections, whether through supply chain attacks, phishing campaigns, or zero-day exploits. The question is not if an attacker will gain initial access, but how far they can go once inside.

SilentGrid's assumed breach assessment starts from the premise that your perimeter has already been compromised. This controlled exercise simulates post-breach scenarios to evaluate your organisation's ability to detect, respond to, and contain adversarial movement within the internal network.

By replicating the tactics, techniques, and procedures (TTPs) of advanced threat actors, SilentGrid tests your organisation's ability to mitigate lateral movement, privilege escalation, and data exfiltration, exposing blind spots and operational gaps that often go unnoticed until a real incident occurs.

Assumed breach assessments are critical

Modern adversaries do not stop at breaching the perimeter. Once inside, attackers exploit misconfigurations, unpatched systems, and overlooked vulnerabilities to achieve persistence, access sensitive data, or escalate privileges.

Internal navigation

Reveals how easily attackers can navigate internal systems

Security gaps

Identifies gaps in segmentation, access controls, and detection

Response effectiveness

Tests SOC, IR, and monitoring solutions under real conditions

Is assumed breach the right fit?

The exercise begins after initial access, so it assumes there are external defences worth bypassing and an internal environment worth defending. Where the perimeter itself is the open question, external infrastructure or perimeter assessment answers it first.

Assumed breach fits organisations that

  • Have mature perimeter defences but need to validate internal security.
  • Want to understand their true breach impact and containment capabilities.
  • Need to test Zero Trust implementations and network segmentation.
  • Require evidence of defence-in-depth effectiveness for compliance or insurance.

SilentGrid's assumed breach methodology

Our approach simulates realistic post-compromise scenarios to thoroughly test your internal defences and response capabilities.

  1. 01

    Establishing initial foothold

    • Simulate scenarios such as compromised endpoints or user credentials
    • Malware deployment through spear phishing or supply chain attacks
    • Insider threat emulation from compromised accounts or rogue employees
    • Evaluate your endpoint detection and response (EDR) capabilities
  2. 02

    Privilege escalation and lateral movement

    • Exploit misconfigurations, weak passwords, and insecure protocols
    • Move laterally using legitimate administrative tools to avoid detection
    • Test Active Directory controls, segmentation, and access restrictions
  3. 03

    Persistence and command & control

    • Establish persistent backdoors using sophisticated techniques
    • Deploy custom C2 infrastructure to simulate APT communication patterns
    • Test your ability to detect and block covert channels
  4. 04

    Data discovery and staging

    • Identify and access sensitive data repositories
    • Test data classification and access control effectiveness
    • Simulate data staging techniques used by real adversaries
  5. 05

    Exfiltration and impact

    • Test data loss prevention (DLP) controls
    • Simulate various exfiltration methods including encrypted channels
    • Assess potential business impact of successful attacks
  6. 06

    Detection and response analysis

    • Comprehensive evaluation of detection capabilities at each stage
    • Analysis of incident response effectiveness and containment strategies
    • Detailed timeline of detection opportunities and misses

Scenario-based testing

Beyond generic testing, we offer targeted scenario simulations based on your industry's most relevant threats. Popular scenarios include:

Ransomware simulation

Test resilience against encryption and lateral spread

Data theft scenarios

Evaluate protection of intellectual property and sensitive data

Supply chain attacks

Simulate compromise through trusted third-party access

Key findings and insights

Assumed Breach assessments provide critical visibility into your internal security posture:

Internal vulnerability exposure

Comprehensive mapping of exploitable vulnerabilities accessible from an assumed breach position

Lateral movement paths

Detailed documentation of how attackers can pivot through your network

Privilege escalation vectors

Identification of pathways to administrative access and domain dominance

Detection blind spots

Areas where adversary activity goes undetected by current security controls

Run it continuously

Test from the foothold once, or all year.

A single assumed breach assessment shows how far an attacker can go from an internal foothold. Where the network changes faster than an annual test can track, CAOS (Continuous Adversary Operations Service) runs adversary cycles through the year and retests the attack paths you remediate.

Explore CAOS

Deliverables and reporting

Attack path documentation

Visual mapping of all successful attack paths and pivot points discovered

Detection opportunity timeline

Chronological analysis of where attacks could have been detected

Risk-prioritised findings

Vulnerabilities ranked by exploitability and potential business impact

Tactical recommendations

Specific hardening measures to block identified attack vectors

Strategic security roadmap

Long-term improvements for defence-in-depth architecture

Executive risk assessment

Business-focused analysis of potential breach impacts

Why SilentGrid

SilentGrid's consultants are hand-picked, and between them they have delivered red team engagements globally over decades, including CBEST for UK financial institutions and CORIE engagements in Australia. Their sector experience covers banking and financial services, insurance, government, critical infrastructure and healthcare.

Consultants find 0-day vulnerabilities in commercial software and speak or teach at security conferences. That research produces the custom tooling used to bypass EDR and network controls, and keeps techniques current with the threat actor being simulated. The methodology follows concepts set out in NIST, OWASP, PTES and OSSTMM.

CREST ANZApproved company

Individual credentials across our team include

  • OSEE
  • OSCE3
  • OSED
  • OSEP
  • OSWE
  • GXPN
  • CRTO
  • CRTE
  • CRTP
  • OSCP
Meet the team

Common questions

What is an assumed breach assessment?

An assumed breach assessment tests an organisation the way an attacker already inside would: it starts from a granted foothold, such as a compromised endpoint or user credentials, and spends the whole exercise on lateral movement, privilege escalation and data access, with detection and containment evaluated at each stage. It does not test whether the initial compromise would have succeeded.

Where does the assessment start from?

From a simulated initial foothold, such as a compromised endpoint or set of user credentials, malware deployed through spear phishing or a supply chain attack, or insider threat emulation from a compromised account.

How is this different from a red team engagement?

A red team engagement works covertly towards an agreed business objective and includes gaining initial access. An assumed breach assessment grants that starting access up front, so the whole exercise is spent on what happens inside: lateral movement, privilege escalation, data access and the response to it.

How long does an assessment take?

Two to six weeks is typical, depending on the size of the internal environment in scope and the scenarios being simulated.

Can the exercise be built around a specific threat?

Yes. Targeted scenario simulations are based on the threats most relevant to your industry, and popular scenarios include ransomware, data theft and supply chain compromise. Scenario testing validates incident response procedures against specific threats, tests backup and recovery capabilities under pressure, identifies the critical assets most at risk, and builds confidence in breach response capabilities.

Does the assessment test detection and response?

Yes. Detection capabilities are evaluated at each stage, incident response effectiveness and containment strategies are analysed, and you receive a detailed timeline of detection opportunities and misses.

What do we receive at the end?

Visual documentation of the attack paths and pivot points discovered, a detection opportunity timeline, risk-prioritised findings, tactical hardening recommendations, a strategic security roadmap and an executive risk assessment.

Test your internal defences

Get started with assumed breach

Discover how far an attacker can go once inside your network

Our expert team will simulate realistic breach scenarios to identify critical gaps in your internal security controls.