Red Team Operations
Full-scope and objective-driven. No prior knowledge, no announced window. We stop when we hold the thing you told us we couldn't reach.
Offensive security — Boston — Since 2019
Red Rook is the adversary you're paying. We run the full attack against your network — access, escalation, movement, exfiltration — and hand you the board before someone else plays it for free.
Capabilities
Every engagement is run by the operators who scope it. No handoffs, no sales engineers, no report written by someone who wasn't in the room.
Full-scope and objective-driven. No prior knowledge, no announced window. We stop when we hold the thing you told us we couldn't reach.
We reproduce a named group's tradecraft against your environment, technique for technique, and score your detections against what they actually do.
Source-assisted testing of the code that touches money, identity, or customer records. Business logic first, injection second.
Every path from a contractor's laptop to your production tenant, mapped, rated, and demonstrated rather than asserted.
We attack, your analysts hunt, and we sit in the same room. Everything we do is logged, timestamped, and replayable against your rules.
A tabletop your executives will not enjoy, followed by the runbook they should have had before it started.
Method
We write ours up the way a game is recorded: our move, then your network's reply. Both columns matter. A finding without your response is only half the position.
Objectives written as outcomes, not IP ranges. One page, signed.
Your no-go list, your escalation path, your two named contacts.
Public exposure, acquisitions, staff, shadow tenants, forgotten DNS.
Usually a third larger than the asset inventory says it is.
The cheapest credible door. Rarely the one you've spent money on.
Whatever fires — or doesn't. We note the time either way.
Local to domain, tenant to tenant, human to service account.
Scored against your own rules, not a generic maturity model.
Straight lines through flat networks. The rook's whole game.
Where it holds, we say so loudly. It's the finding worth paying for.
The payment run, the patient record, the release pipeline. Proven.
Stated in your language: money, downtime, regulator, headline.
Live walkthrough with the engineers who own the fix, not a PDF drop.
Ranked by attack path, not by scanner severity.
Included. We replay the exact path, ninety days later.
Or it isn't, and we say that too. That's the only honest ending.
Field notes
Redacted with client permission. The annotation marks the move, not the people — every network below is in better shape than the one you're running right now.
A decommissioned VPN concentrator still trusted the old domain. Nobody had signed into it since 2021. It was the shortest path to every teller terminal in fourteen branches.
Engagement 24‑118
Regional bank
Five weeks · Black box
Decommission process rewritten. Retest at ninety days found no residual trust.
Their detection was excellent — for malware. So we used their own deployment tooling, and the SOC watched the whole operation go past as a routine change window.
Engagement 25‑032
Healthcare SaaS
Three weeks · Purple
Eleven new detections written jointly. Change-approval path now alerts on out-of-band use.
Seven days in, blocked at every turn. The segmentation held, the credentials were short-lived, and the alerts were real. We wrote the shortest report in the firm's history.
Engagement 25‑077
Logistics operator
Six weeks · Full scope
Scope widened at the client's request. We got in through an acquired subsidiary on day nineteen.
Practice
What we do with what we find — in your systems, in the products you depend on, and in our own.
Yours. We report to you and to nobody else. Nothing is published, cited in marketing, or shown to another client without your written consent, asked for specifically rather than buried in the contract.
Coordinated disclosure to the vendor, ninety days to a fix, then publication. You hear first, and where the flaw sits in something you run we hold publication longer while you remediate.
No brokers, no exploit market, no government buyers. A finding goes to the vendor who can fix it or the client who owns it. Nowhere else.
Client names, sector detail, and anything reconstructible come out first. The field notes on this page went through that process and were signed off by the clients they describe.
Anything we take from your systems lives in scope-limited, encrypted storage reachable only by the operators on the engagement. Credentials and extracted records are destroyed when you accept the report, and we issue a certificate of destruction. Logs are retained for the retest and nothing past it.
We run a disclosure program against ourselves at security@redrook.io. One business day to acknowledge, and we credit you unless you ask us not to.
This is an illustrative example of a common rules-of-engagement document. It is not a contract, not legal advice, and not a template to sign. Every engagement gets its own, drafted during scoping and signed by both sides before any testing begins — these are simply the clauses that appear in most of ours.
Named signatories on both sides, with written confirmation that the client owns or is contractually entitled to authorize testing of every asset in scope. Systems hosted by a third party need that provider's consent as well.
Objectives stated as outcomes, with the asset list attached as an appendix rather than serving as the definition. Anything found mid-engagement that falls outside the list is reported, not tested, until scope is amended in writing.
An explicit no-go list: production safety systems, medical devices in clinical use, and anything else the client names. Denial of service and destructive techniques are excluded by default and added only deliberately, in writing.
Start and end dates, permitted hours, and whether the client's own staff are told. Blackout periods — trading days, month end, clinical peaks, peak logistics — are agreed up front rather than negotiated mid-operation.
Two named contacts reachable out of hours, a phrase that halts the engagement immediately when either side uses it, and a shared channel so the client can ask “was that you?” and have an answer in minutes rather than days.
Client data stays in scope-limited storage, encrypted at rest, reachable only by the operators on the engagement. Credentials and any extracted records are destroyed once the report is accepted, and a certificate of destruction is issued.
Every action timestamped and logged, retained for the retest and no longer. The log is handed over with the report so the client's analysts can replay the whole operation against their own detections.
Included, not quoted separately. The same paths, against the same objectives, ninety days after remediation.
Engage
Engagements begin with a forty-five minute scoping call — no deck, no discovery questionnaire. You'll be talking to the operator who would run the work.