Red Team Operations
Full-scope and objective-driven. No prior knowledge, no announced window. We stop when we hold the thing you told us we couldn't reach.
Offensive security — Boston — Since 2019
Red Rook is the adversary you're paying. We run the full attack against your network — access, escalation, movement, exfiltration — and hand you the board before someone else plays it for free.
Capabilities
Every engagement is run by the operators who scope it. No handoffs, no sales engineers, no report written by someone who wasn't in the room.
Full-scope and objective-driven. No prior knowledge, no announced window. We stop when we hold the thing you told us we couldn't reach.
We reproduce a named group's tradecraft against your environment, technique for technique, and score your detections against what they actually do.
Source-assisted testing of the code that touches money, identity, or customer records. Business logic first, injection second.
Every path from a contractor's laptop to your production tenant, mapped, rated, and demonstrated rather than asserted.
We attack, your analysts hunt, and we sit in the same room. Everything we do is logged, timestamped, and replayable against your rules.
A tabletop your executives will not enjoy, followed by the runbook they should have had before it started.
Method
We write ours up the way a game is recorded: our move, then your network's reply. Both columns matter. A finding without your response is only half the position.
Objectives written as outcomes, not IP ranges. One page, signed.
Your no-go list, your escalation path, your two named contacts.
Public exposure, acquisitions, staff, shadow tenants, forgotten DNS.
Usually a third larger than the asset inventory says it is.
The cheapest credible door. Rarely the one you've spent money on.
Whatever fires — or doesn't. We note the time either way.
Local to domain, tenant to tenant, human to service account.
Scored against your own rules, not a generic maturity model.
Straight lines through flat networks. The rook's whole game.
Where it holds, we say so loudly. It's the finding worth paying for.
The payment run, the patient record, the release pipeline. Proven.
Stated in your language: money, downtime, regulator, headline.
Live walkthrough with the engineers who own the fix, not a PDF drop.
Ranked by attack path, not by scanner severity.
Included. We replay the exact path, ninety days later.
Or it isn't, and we say that too. That's the only honest ending.
Field notes
Redacted with client permission. The annotation marks the move, not the people — every network below is in better shape than the one you're running right now.
A decommissioned VPN concentrator still trusted the old domain. Nobody had signed into it since 2021. It was the shortest path to every teller terminal in fourteen branches.
Engagement 24‑118
Regional bank
Five weeks · Black box
Decommission process rewritten. Retest at ninety days found no residual trust.
Their detection was excellent — for malware. So we used their own deployment tooling, and the SOC watched the whole operation go past as a routine change window.
Engagement 25‑032
Healthcare SaaS
Three weeks · Purple
Eleven new detections written jointly. Change-approval path now alerts on out-of-band use.
Seven days in, blocked at every turn. The segmentation held, the credentials were short-lived, and the alerts were real. We wrote the shortest report in the firm's history.
Engagement 25‑077
Logistics operator
Six weeks · Full scope
Scope widened at the client's request. We got in through an acquired subsidiary on day nineteen.
Engage
Engagements begin with a forty-five minute scoping call — no deck, no discovery questionnaire. You'll be talking to the operator who would run the work.