Assumed breach methodology
How the Strobes red team simulates an attacker who is already inside, from internal reconnaissance through post-exploitation and exfiltration, to measure how fast you detect and respond.
Assumed breach is a type of adversary simulation exercise where an organization assumes that a breach has already happened, or that it is only a matter of time until it will. The goal is to evaluate how well the organization can detect and respond to a compromise.
In an assumed breach engagement, the Strobes red team starts from a foothold already inside the network and works outward, using the same tactics, techniques, and procedures (TTPs) that real threat-actor groups employ.
Assumed breach starts from the attacker's best day: a foothold already inside. It measures whether you can detect and respond before that foothold becomes a crisis.
From a foothold inside to data out
The assumed breach path: starting from access already inside the network, measured against detection and response.

Where the red team focuses
In an assumed breach engagement, the Strobes red team focuses on:
- Use the current user's privileges and the built-in tools available on the workstation
- Move laterally through the network to reach password vaults, highly confidential servers, and any custom objectives set by the customer
- Exfiltrate sensitive information, or a representative sample of it
- Use the tactics, techniques, and procedures (TTPs) employed by real threat-actor groups
Internal reconnaissance
The team enumerates the internal network to build situational awareness and find the weaknesses an intruder would use to move.
- Enumerate the network for situational awareness
- Discover network misconfigurations such as open shares
- Enumerate domain user privileges
- Identify Active Directory misconfigurations
- Perform weak-password spraying
Post-exploitation
Using the intelligence gathered during reconnaissance, the team:
- Escalate privileges: raise privileges on the current workstation, or move to one held by a compromised user with higher privileges
- Lateral movement: pivot to high-security Tier 0 and Tier 1 networks or workstations, in the cloud or on-premises, where possible
- Persistence: employ a variety of techniques to maintain access on compromised workstations or hosts
Exfiltration
The team tests whether target data can leave the environment without being caught.
- Bypass egress restrictions set on the customer infrastructure
- Exfiltrate a proof-of-concept (PoC) sample of sensitive data to attacker-controlled infrastructure
Objectives
Objectives vary with the purpose of the exercise. Typical assumed breach goals include, and are not limited to:
- Gain access to a highly sensitive server
- Emulate a user's privileges to identify over-privileged accounts
- Gain access to a specific user's mailbox and exfiltrate information
- Bypass host-based controls to execute specific payload types
- Execute sample ransomware payloads to assess detection and response
Requirements from customers
- Access to a workstation inside the corporate network with common domain-user privileges
- Set of objectives to achieve, if any
Deliverables
- Assumed breach report
- Executive summary report
Frequently asked questions
Assume you're already breached. Then find out.
Let the Strobes red team start from a foothold inside your network and show you how far an attacker gets, and how fast you would catch them.
Join 150+ security teams already reducing exposure with Strobes
