Each CATSCAN® engagement is scoped individually. Answer a few questions and we'll provide a clear, effort-based quote.
A CATSCAN® engagement puts an offensive Red Team against your defensive Blue Team. Our Rainbow Hacker reference card is a plain-English starting point for understanding these team roles before you request a scoping call.
The PROACTIVE RISK team embarks on comprehensive information gathering and vulnerability detection. This crucial step involves collecting extensive data about the target's infrastructure, facilities, and personnel. Utilizing techniques such as Open Source Intelligence Gathering (OSINT), the team acquires valuable insights into the target's people, facilities, and technical elements. By scrutinizing physical and logical security controls, foot traffic patterns, terrain features, and potential infiltration or exfiltration points, the team develops a thorough understanding of the target's security landscape.
Building on the intelligence gathered in Phase I, this phase focuses on in-depth information analysis, meticulous planning, and crafting weaponization strategies. Armed with a comprehensive understanding of the target, the team tailors their operation to exploit identified vulnerabilities effectively. This phase involves creating customized file payloads, configuring hardware trojans, acquiring social engineering disguises, and fabricating falsified personas or companies. Every detail is carefully planned to ensure precise execution.
The team launches the active phase of the operation with a comprehensive attack and penetration strategy. Activities include cloning badges, executing face-to-face social engineering tactics, analyzing cyber vulnerabilities, and planting hardware trojans for remote network persistence. These actions are designed to identify the most advantageous points of exploitation to achieve the CATSCAN® operation's objectives.
This phase focuses on gaining unauthorized access to target systems. The team compromises servers, applications, and networks, employing methods to bypass physical controls including gates, fences, locks, radar, and motion detection systems. The team also exploits target staff through social engineering via face-to-face interactions, email, phone calls, faxes, or text messages. This stage sets the groundwork for further escalation and the installation phase.
The team establishes persistent access within the target's systems by creating a robust foothold — escalating privileges on compromised servers, installing malicious file payloads, utilizing physical key impressions, and bypassing lockpicked doors. The installation phase ensures lasting cyber and physical persistence within the target environment.
This phase focuses on maintaining continuous access to the exploited systems. PROACTIVE RISK implements measures to ensure stable and reliable remote access, setting the stage for subsequent post-exploitation tasks such as data exfiltration. On the physical and social fronts, the team manipulates individuals to circumvent physical barriers, creating backdoors into the facilities.
In the final phase, the PROACTIVE RISK team accomplishes the mission and meets the client's stated objectives. Actions on objective span both cyber and physical domains, involving lateral movement across compromised systems and physical facilities. The team captures video, audio, and photographic evidence to support their findings and ultimately exfiltrates critically sensitive data, information, or physical assets as specified by the target.
Each CATSCAN® engagement is scoped individually. Answer a few questions and we'll provide a clear, effort-based quote.
See Us in Action
A look at how Proactive Risk's adversarial attack simulation service finds the gaps before real attackers do — and what sets our veteran-led team apart.
Video loads from YouTube · no tracking until you press play