Skip to content
Red Team adversarial

Human operators
Real AI systems
No rules

We simulate the Promptware Kill Chain end-to-end — from initial prompt injection to full exfiltration. You discover what a motivated adversary can really do, before they do.

4–8 semTypical duration
7Kill-chain stages
100%Human operators
15/21Incidents with 4+ kill-chain stages
57%Attackers with active persistence
4–8Weeks per campaign
72hSLA for critical findings
Campaign phases

Five phases
One coordinated operation

We work like a motivated adversary — not a scanner. Each phase has clear deliverables, and you follow the operation in real time through our dashboard.

01

Threat modeling

We map your AI stack, identify crown jewels, and define adversary objectives jointly with your team.

Week 1Workshop · 2 days
02

Reconnaissance

OSINT, surface enumeration, model identification, plugins, exposed data, and third-party integrations.

Week 2Passive + active
03

Exploitation

Promptware Kill Chain activated — prompt injection, escalation, credential harvesting, persistence via agent memory.

Weeks 3–6Continuous operation
04

Objectives & impact

Lateral movement, simulated exfiltration, business-flow compromise. We document every path with evidence.

Weeks 6–7Forensic evidence
05

Report & debrief

Executive report, technical walkthrough, campaign replay, and impact-prioritized remediation plan.

Week 8Executive session
Tactics, techniques & procedures

The arsenal attackers use — replicated at controlled scale

Every technique below was observed in real 2025–26 incidents or academic research. All are executed with explicit authorization and blast-radius containment.

T1 · INITIAL

Prompt injection multimodal

Hidden instructions in images, PDFs, audio, and metadata. Breaks the trust boundary between data and instructions.

img.alt = "ignore..."
pdf metadata::cmd
audio steganography
T2 · ESCALATE

Tool / function abuse

Chaining of legitimate tool calls to reach unauthorized capabilities — file system, email, transactions.

searchemail$exec
T3 · RECON

Model & system prompt leak

Extraction of system instructions, privileged context, and model details via adversarial prompts.

LEAKsystem_prompt
LEAKmodel: gpt-4o
LEAKapi_key prefix
T4 · PERSIST

Memory poisoning

Injection of persistent instructions into long-term memory, vector stores, and context shared across sessions.

T5 · C2

Indirect prompt channel

Command-and-control channel via shared documents, comments, or content retrieved by RAG.

T6 · LATERAL

Agent-to-agent contagion

Propagation across agents via inter-agent calls, message queues, and shared orchestration contexts.

T7 · OBJECTIVE

Data exfil via legitimate channel

Sensitive data leaving through responses, summaries, or actions that appear legitimate to detection.

15:42EXFIL12,847 records
15:43EXFILvia summarize()
15:44CLEANtrace removed
T8 · EVASION

Guardrail bypass

Encoding, role-play, long context, logic puzzle attacks, and safety classifier evasion.

base64 encode
roleplay::dev_mode
token smuggle
T9 · SUPPLY

Supply chain

Malicious packages, backdoored models, poisoned datasets — attacking before deploy.

npmmodel.safetensorsprod
From kickoff to executive scorecard

What you receive at the end of the campaign

DOC-01

Executive report (15–25 pp)

Business-language impact summary, risk map, top 5 attack paths, prioritized recommendations, and estimated financial exposure.

DOC-02

Technical report (60–120 pp)

Each attack chain documented stage-by-stage, with payloads, screenshots, logs, and reproducible PoC for the engineering team.

PoCcurl-X POST /api/v1/...
PoCprompt"ignore prev..."
PoCresponse200 OK · system
DOC-03

Campaign replay

Interactive visual timeline of each executed stage, operator decisions, and windows where the defense would have detected had observability been active.

DOC-04

90-day remediation plan

Prioritized actions (high/medium/low), suggested owners, estimated effort, and dependencies between controls. We revisit at 90 days to validate.

P1
P2
P3
Rules of engagement

Controlled operations
No surprises

Every campaign starts with documented rules of engagement, blast-radius containment, and a direct channel with your response team if anything escapes scope.

ROE-01

Surgical scope

Systems, test accounts, time windows, and action types approved in writing before any execution.

ROE-02

24/7 red line

Direct channel between the campaign lead and your security team — we pause the operation at any moment.

ROE-03

No real data exfiltrated

We demonstrate exfiltration capability with canaries and synthetic data. Nothing sensitive leaves your perimeter.

ROE-04

Reversibility

Every modification to memory, configuration, or state is documented and rolled back at the end of the operation.

ROE-05

SOC coordination

"Purple team" mode available — we operate in coordination with your SOC to validate detection and response in real time.

ROE-06

Compliance & legal

Contract with NDA, legal authorization, data segregation, and auditable report for regulators and auditors.

Ready to find out what a motivated adversary can actually do?

2-day threat modeling workshop to start — leave with surface map, top 5 hypothetical attack paths, and a complete campaign proposal.

Schedule workshop