Skip to content
Pillar I · Red Team

Specialists in command, automation at the right scale.

Pentest, EHT, Red Team, Agentic EHT and Threat Intelligence act at different points of the adversarial cycle. Each approach starts from a question and produces a type of evidence.

Overview

Berghem's Offensive Security pillar covers the full adversarial cycle — from essential pentesting to long-duration operations. Ethical Hacking Tests in three tiers for defined scopes, Red Team and multi-vector simulations to validate real defenses, and Monitoring & Threat Intel to anticipate the adversary before impact.

We operate as a patient adversary: we map the attack surface, validate the controls that matter, and deliver actionable evidence for technical and executive leadership. Each engagement is designed with business objectives, conducted with operational discretion, and closed with a joint review between Red and Blue Teams.

Everything included

Ethical Hacking Tests — Silver, Gold, and Diamond
Red Team and multi-vector simulation
Cyber War Games and cross-team tabletops
Breach and Attack Simulation (BAS) continuous
Dark Web Monitoring and Threat Intelligence
Threat Hunting in client telemetry
Module 01 · Core

Ethical Hacking Tests (EHT)

Offensive analysis with a business view. Three tiers — Silver, Gold, and Diamond — for core scopes, plus unique scopes for Cloud, IoT, and Payment Methods.

Silver · Gold · Diamond

Web & API Applications

Authentication, authorization, session, business logic, and LGPD compliance — available in all three tiers.

Silver · Gold · Diamond

Mobile Applications

Android and iOS — local storage, backend, transactional flows, and biometrics — available in all three tiers.

Silver · Gold · Diamond

Infrastructure & Network

Internal and external attacks, segmentation, hardening, and lateral movement — available in all three tiers.

Unique scope

Cloud (AWS, Azure, GCP)

Security review, hardening, and white-box pentest in cloud and on-premises environments.

Unique scope

IoT & Embedded Systems

Firmware, communication, interfaces, and updates — from device to cloud.

PCI-DSS

Payment Methods

Card EMV, POS / Smart POS terminals, ATM, PIX, and facial biometrics (BFA).

Want to compare tiers side by side?  See the full Silver, Gold, and Diamond matrix.
View tier details
Module 02 · Specialized

Red Team and Attack Simulation

Multi-vector offensive operations, cross-team exercises, and continuous defense validation — with evidence that your defense is ready for an adversary with time, motivation, and resources.

MITRE ATT&CK

Red Team

Advanced simulation of sophisticated attacks — long-duration multi-vector operations with business objectives defined by leadership: access to critical systems, specific data exfiltration, or compromise of sensitive processes.

Tabletop · Wargame

Cyber War Games

Incident response exercises with multiple teams — security, IT, legal, communications, and leadership engaged in real decisions under pressure. Immersive tabletops and technical wargames.

Continuous program

Breach and Attack Simulation

Continuous simulation program that validates controls at scale — endpoints, email, network, cloud, and identity — against real TTPs with MITRE ATT&CK coverage.

Module 03 · Anticipation

Monitoring and Threat Intel

Operational intelligence, not loose reports. Continuous dark web monitoring combined with proactive hunting in client telemetry — always contextualized to the sector and business risk profile.

24/7 · Real-time alerts

Dark Web Monitoring

Continuous dark web monitoring for detection of data exposures, leaked credentials, and targeted offers to the organization in underground forums and markets.

EDR · SIEM · Cloud

Threat Intelligence & Threat Hunting

Threat intelligence (actors, TTPs, and motivation) contextualized to the sector, combined with proactive hunting in EDR, SIEM, identity, and cloud telemetry — with on-demand detection engineering.

PORTFOLIO

A services architecture, not an undifferentiated list.

Each approach starts from a question, produces a type of evidence and requires its own operating model.

ASSET

Pentest

Validates exposures in assets, applications, APIs, infrastructure and defined environments.

MISSION

EHT

Correlates technical and business routes up to an adversarial objective.

DEFENSE

Red Team

Simulates a multi-vector operation to validate prevention, detection and response.

SCALE

Agentic EHT

Expands exploration, state keeping, correlation and evidence.

CONTEXT

Threat Intelligence

Contextualizes actors, TTPs, exposures and signals relevant to the business.

RESILIENCE

War Games

Exercises technical and executive decision-making under pressure.

HOW TO CHOOSE

From the asset to the core business.

The choice depends on the objective: find an exposure, validate an adversarial mission or test the resilience of the defense.

ApproachStarting pointPrimary evidence
PentestAsset and technical scope.Vulnerability, exploitation and impact.
EHTCore business and adversarial mission.Chain of conditions leading to impact.
Red TeamObjective and defensive controls.Prevention, detection, response and resilience.
Agentic EHTMission, context, boundaries and tooling.Investigated routes and auditable evidence at scale.
OPERATING MODEL

Specialists in command, automation at the right scale.

The agent expands coverage, correlation, repetition and evidence. The specialist defines the mission, interprets the impact and owns the critical decisions.

Specialist operation

Planning, creativity, impact, authorization and client communication.

Agentic capability

Navigation, repetition, correlation, evidence collection and retesting within the rules.

Ready to get started?

In a 30-minute conversation we map your attack surface and design the ideal offensive scope — from the essential pentest to a long-duration Red Team operation.

Contact Us