Skip to content
StrikeCyberStrikeCyber
Red Teaming

Reconnaissance & Threat Modelling

The opening stage of a red team engagement: we study your people, infrastructure and digital footprint the way a real attacker would, and model the adversary before touching anything.

How it works

Inside Reconnaissance & Threat Modelling

01

OSINT and Footprinting

Attackers profile you long before they act. Leaked credentials, exposed staff detail and forgotten infrastructure all shape the first move.

Our methodology

We run open-source intelligence on staff and exposed infrastructure and map your external attack surface, building the same picture a determined adversary would, aligned to the MITRE ATT&CK Reconnaissance tactic.

  • OSINT
  • Attack-surface mapping
  • MITRE ATT&CK
02

Threat Actor Modelling

A credible test is scoped to the adversaries who would actually target you, not a generic checklist.

Our methodology

We model credible threat actors against your objective and sector, deciding who we would impersonate and which techniques best reflect the real threat, mapped to the Resource Development tactic.

  • Threat modelling
  • Adversary emulation
  • Scenario design
03

Objective and Rules of Engagement

Red teaming is goal-driven. Without a clear objective and safe boundaries the exercise proves little.

Our methodology

We agree the engagement objective, scope and rules of engagement up front, so the campaign is realistic, safe and measured against outcomes that matter to your business.

  • Objective-led
  • Rules of engagement
  • Safe testing
FAQ

Reconnaissance & Threat Modelling FAQs

What is the reconnaissance stage of a red team?

It is the opening stage where we study your organisation the way a real attacker would, building a picture of your people, infrastructure and digital footprint before touching anything. It defines who we would impersonate and where the softest ways in are likely to be, aligned to the MITRE ATT&CK Reconnaissance and Resource Development tactics.

Do you use information about our staff?

Yes, from public and open sources only. Attackers profile employees through social media, breach data and public records, so we do the same to model realistic pretexts and entry points. Everything is handled confidentially and within the agreed rules of engagement.

How is this different from a vulnerability scan?

A scan looks for known technical flaws. Reconnaissance in a red team builds an adversary's whole picture of you, people, process and technology, to plan a goal-driven campaign rather than list issues.

Is our data kept private?

Yes. Findings and any collected intelligence are isolated to your organisation and handled in access-limited environments we control in Australia. Nothing is pooled, sold or fed into public models.

Talk to an operator about your engagement

Scope this with a senior operator. Fixed scope, fixed price, no obligation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation