Listing Thumbnail

    Kroll Red Team Services

     Info
    Sold by: Kroll 
    Leadership needs to know whether security controls, people and processes can stop a determined attacker across both cloud and on-premises environments. Kroll delivers threat-led red team exercises that test real attack paths, validate detection and response, expose control gaps and provide practical improvements for AWS, hybrid and traditional enterprise environments.

    Overview

    • Kroll Red Team Services help AWS customers test cyber resilience against realistic adversary behavior. Red teaming is objective-led, threat-informed and tests how people, processes and technology perform during a simulated attack.
    • Kroll performs red teaming across cloud, on-premises and hybrid environments. Cloud environments are identity-centric, API-driven and control-plane oriented. On-premises environments are endpoint-, network- and directory-centric. Hybrid environments require testing paths between AWS, identity providers, admin workstations, VPNs, Direct Connect, CI/CD tooling and internal systems.
    • Kroll’s Offensive Security practice includes 100+ penetration testers, red teamers and application security engineers. Kroll uses real-world threat intelligence to simulate threat actor attacks.

    Buyer problem solved

    • Many organizations have mature security tools but limited evidence that they work together during a realistic attack. Cloud teams may monitor AWS services, SOC teams may monitor alerts, and infrastructure teams may manage identity and network controls. Attackers do not respect those boundaries.
    • Kroll designs red team exercises around business objectives and realistic attack paths. The engagement shows whether an attacker can reach critical assets, whether defenders detect meaningful activity, and whether the organization can contain the threat before material impact occurs.

    Cloud, on-premises and hybrid red team approach

    Kroll applies different red team tradecraft by environment.

    • Cloud red teaming focuses on the AWS control plane, cloud identities, APIs, permissions, managed services, workloads and account boundaries. Kroll evaluates whether an attacker can abuse IAM roles, trust relationships, exposed services, storage, secrets, CI/CD pipelines, containers, serverless functions or logging gaps to reach sensitive data or critical workloads.
    • On-premises red teaming focuses on endpoints, users, internal networks, Active Directory, privileged systems and enterprise controls. We evaluate initial access, endpoint compromise, command and control, EDR visibility, privilege escalation, lateral movement, segmentation and access to critical business systems.
    • Hybrid red teaming tests the paths between cloud and on-premises environments. Kroll evaluates whether AWS compromise can create access to internal systems, whether on-premises compromise can affect AWS workloads, and whether federated identity, VPNs, Direct Connect, admin workstations, shared credentials, CI/CD tooling or privileged operations create cascading risk.

    Customers can use this engagement to:

    • Test controls against realistic adversary tactics
    • Evaluate detection, triage, escalation, containment and response
    • Validate resilience across AWS, hybrid cloud and on-premises environments
    • Identify visibility gaps across cloud logs, endpoint telemetry, identity systems and network controls
    • Test cloud identity, role abuse, privilege escalation and managed-service attack paths
    • Test on-premises Active Directory, endpoint, lateral movement and segmentation controls
    • Improve blue team readiness through replay sessions and collaborative learning
    • Prioritize security investments based on demonstrated business impact

    What is included?

    Scope is customized through a private offer and may include:

    • Threat-led scenario design
    • Cloud red teaming
    • On-premises red teaming
    • Hybrid attack-path testing
    • Initial access simulation
    • Objective execution
    • Detection and response evaluation
    • Purple team collaboration

    Engagement approach: Kroll tailors each red team exercise to the customer’s maturity, risk appetite and business objectives.

    Typical phases include:

    1. Executive scoping and objective definition
    2. Threat scenario development
    3. Communications, project plan, attack infrastructure and escalation path setup
    4. Reconnaissance. Initial access simulation
    5. Adversary execution
    6. Cloud or on-premises attack-path testing, if in scope
    7. Detection and response observation
    8. Analysis and reporting. Purple team replay and remediation support

    Objectives may include:

    • Compromise a critical AWS workload
    • Test cloud identity privilege escalation
    • Validate endpoint-to-Active Directory compromise paths
    • Assess whether on-premises administrative access can affect AWS resources
    • Test cloud-to-internal movement
    • Evaluate phishing or credential abuse readiness
    • Validate segmentation
    • Support executive resilience reporting

    Deliverables may include:

    • Executive summary
    • Attack narrative and timeline
    • Technical findings and evidence
    • Objective achievement summary
    • Cloud, on-premises or hybrid attack-path findings
    • Detection and response observations
    • Control gap analysis
    • MITRE ATT&CK mapping
    • Remediation roadmap
    • Purple team replay materials
    • Executive readout and technical debrief
    • Optional retest

    Highlights

    • Kroll delivers threat-led red teaming across cloud, on-premises and hybrid environments, using different methodologies for AWS control-plane attacks and traditional enterprise compromise paths.
    • Kroll simulates objective-based, business-inspired attack kill chains to test people, process, technology, detection and response.
    • Kroll provides executive-ready reporting, technical attack narratives, control-gap analysis, MITRE ATT&CK mapping, prioritized recommendations and optional purple team replay sessions.

    Details

    Sold by

    Categories

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Resources

    Support

    Vendor support

    Kroll provides engagement planning, project management, controlled execution, stakeholder coordination and post-engagement support according to the agreed scope of work. Communication cadence, escalation procedures and safety protocols are defined during scoping.

    For queries please contact Feroze Mohideen on +27108254369 or feroze.mohideen@kroll.com .