Red Rook

Offensive security Boston Since 2019

We move laterally. So will they.

Red Rook is the adversary you're paying. We run the full attack against your network — access, escalation, movement, exfiltration — and hand you the board before someone else plays it for free.

Current posture
Booking Q4 2026. Two operator teams available.
Scope
Financial services, healthcare, critical logistics.
Offices
Boston (HQ), Manhattan, Miami, San Francisco.

Capabilities

Six ways to lose,
practiced in advance.

Every engagement is run by the operators who scope it. No handoffs, no sales engineers, no report written by someone who wasn't in the room.

Red Team Operations

Full-scope and objective-driven. No prior knowledge, no announced window. We stop when we hold the thing you told us we couldn't reach.

4–8 weeks
Black box

Adversary Emulation

We reproduce a named group's tradecraft against your environment, technique for technique, and score your detections against what they actually do.

3 weeks
Threat-informed

Application & API Assessment

Source-assisted testing of the code that touches money, identity, or customer records. Business logic first, injection second.

2–4 weeks
Authenticated

Cloud & Identity Review

Every path from a contractor's laptop to your production tenant, mapped, rated, and demonstrated rather than asserted.

2 weeks
AWS · Azure · GCP

Detection Engineering

We attack, your analysts hunt, and we sit in the same room. Everything we do is logged, timestamped, and replayable against your rules.

Continuous
Purple

Incident Readiness

A tabletop your executives will not enjoy, followed by the runbook they should have had before it started.

5 days
Executive

Method

An engagement is a game
with two sides.

We write ours up the way a game is recorded: our move, then your network's reply. Both columns matter. A finding without your response is only half the position.

Move Red Rook Your network
1.

Scoping

Objectives written as outcomes, not IP ranges. One page, signed.

Rules of engagement

Your no-go list, your escalation path, your two named contacts.

2.

Reconnaissance

Public exposure, acquisitions, staff, shadow tenants, forgotten DNS.

Attack surface?!

Usually a third larger than the asset inventory says it is.

3.

Initial access

The cheapest credible door. Rarely the one you've spent money on.

First control

Whatever fires — or doesn't. We note the time either way.

4.

Escalation

Local to domain, tenant to tenant, human to service account.

Detection attempt

Scored against your own rules, not a generic maturity model.

5.

Lateral movement!

Straight lines through flat networks. The rook's whole game.

Segmentation

Where it holds, we say so loudly. It's the finding worth paying for.

6.

Objective

The payment run, the patient record, the release pipeline. Proven.

Impact

Stated in your language: money, downtime, regulator, headline.

7.

Disclosure

Live walkthrough with the engineers who own the fix, not a PDF drop.

Remediation

Ranked by attack path, not by scanner severity.

8.

Retest

Included. We replay the exact path, ninety days later.

Position held!!

Or it isn't, and we say that too. That's the only honest ending.

Field notes

Three positions,
annotated.

Redacted with client permission. The annotation marks the move, not the people — every network below is in better shape than the one you're running right now.

!! Brilliant defence ! Strong ?! Dubious ? Mistake ?? Blunder
??
A decommissioned VPN concentrator still trusted the old domain. Nobody had signed into it since 2021. It was the shortest path to every teller terminal in fourteen branches.

Engagement 24‑118
Regional bank
Five weeks · Black box Decommission process rewritten. Retest at ninety days found no residual trust.

?!
Their detection was excellent — for malware. So we used their own deployment tooling, and the SOC watched the whole operation go past as a routine change window.

Engagement 25‑032
Healthcare SaaS
Three weeks · Purple Eleven new detections written jointly. Change-approval path now alerts on out-of-band use.

!
Seven days in, blocked at every turn. The segmentation held, the credentials were short-lived, and the alerts were real. We wrote the shortest report in the firm's history.

Engagement 25‑077
Logistics operator
Six weeks · Full scope Scope widened at the client's request. We got in through an acquired subsidiary on day nineteen.

Practice

Disclosure policy.

What we do with what we find — in your systems, in the products you depend on, and in our own.

01

Findings in your systems

Yours. We report to you and to nobody else. Nothing is published, cited in marketing, or shown to another client without your written consent, asked for specifically rather than buried in the contract.

02

Findings in third-party products

Coordinated disclosure to the vendor, ninety days to a fix, then publication. You hear first, and where the flaw sits in something you run we hold publication longer while you remediate.

03

We do not sell vulnerabilities

No brokers, no exploit market, no government buyers. A finding goes to the vendor who can fix it or the client who owns it. Nowhere else.

04

Published research

Client names, sector detail, and anything reconstructible come out first. The field notes on this page went through that process and were signed off by the clients they describe.

05

Your data, and how long we keep it

Anything we take from your systems lives in scope-limited, encrypted storage reachable only by the operators on the engagement. Credentials and extracted records are destroyed when you accept the report, and we issue a certificate of destruction. Logs are retained for the retest and nothing past it.

06

Our own systems

We run a disclosure program against ourselves at security@redrook.io. One business day to acknowledge, and we credit you unless you ask us not to.

Rules of engagement.

Example only

This is an illustrative example of a common rules-of-engagement document. It is not a contract, not legal advice, and not a template to sign. Every engagement gets its own, drafted during scoping and signed by both sides before any testing begins — these are simply the clauses that appear in most of ours.

01

Authorization

Named signatories on both sides, with written confirmation that the client owns or is contractually entitled to authorize testing of every asset in scope. Systems hosted by a third party need that provider's consent as well.

02

Scope

Objectives stated as outcomes, with the asset list attached as an appendix rather than serving as the definition. Anything found mid-engagement that falls outside the list is reported, not tested, until scope is amended in writing.

03

Exclusions

An explicit no-go list: production safety systems, medical devices in clinical use, and anything else the client names. Denial of service and destructive techniques are excluded by default and added only deliberately, in writing.

04

Testing window

Start and end dates, permitted hours, and whether the client's own staff are told. Blackout periods — trading days, month end, clinical peaks, peak logistics — are agreed up front rather than negotiated mid-operation.

05

Escalation and deconfliction

Two named contacts reachable out of hours, a phrase that halts the engagement immediately when either side uses it, and a shared channel so the client can ask “was that you?” and have an answer in minutes rather than days.

06

Data handling

Client data stays in scope-limited storage, encrypted at rest, reachable only by the operators on the engagement. Credentials and any extracted records are destroyed once the report is accepted, and a certificate of destruction is issued.

07

Evidence and logging

Every action timestamped and logged, retained for the retest and no longer. The log is handed over with the report so the client's analysts can replay the whole operation against their own detections.

08

Retest

Included, not quoted separately. The same paths, against the same objectives, ninety days after remediation.

Engage

Open the board.

Engagements begin with a forty-five minute scoping call — no deck, no discovery questionnaire. You'll be talking to the operator who would run the work.

Found something in our network?
We run a disclosure program against ourselves. security@redrook.io
PGP fingerprint
B342 55DD 59BE 8112 55DF
2981 6100 782E 5992 BF24
Response window
One business day, acknowledged by a human.