Your situation

White Box Red Teaming: reviewing attack scenarios together

You want to look at your organisation from an attacker’s perspective but do not have a permanently available blue team? With White Box Red Teaming, we develop and discuss attack scenarios together with your technical contacts.

Free of charge and without obligation.

  • CRTO and OSCP qualifications on the team
  • BSI-certified for IS penetration testing
  • Co-author: TeleTrusT guideline on penetration testing
Several hands pointing together at the word CYBERSICHERHEIT (cybersecurity) written in sand
White Box Red Teaming: attackers and defenders at one table.

Your situation

You want to examine your organisation from an attacker’s perspective – without the risks and costs of real red teaming?

A penetration test examines a predefined attacker scenario: an attack target (e.g. the new web shop), a methodology (e.g. vulnerability scan of the application server or application testing) and a permission scenario (e.g. shop customer, but not administrator). Individual systems, networks or applications are thus considered in isolation.

Red teaming, by contrast, looks at the organisation as a whole. By its nature, however, it involves risks that cannot be calculated: because the red team lacks knowledge of how critical the target systems are, business-relevant processes can be disrupted. Effort and costs are high, and your blue team has to be active around the clock.

We developed WBRT® – White Box Red Teaming to close this gap. It uses the openness of the red teaming approach without its risks or extreme costs; a blue team is not strictly necessary. Instead of real attacks, our red team designs attack scenarios, which we discuss and document with the people technically responsible on your side in a workshop.

Services & results

WBRT®: from the “Holy Grail” to a catalogue of measures

You see your organisation as a whole from an attacker’s perspective, together with your technical contacts rather than in a covert attack. You define an objective that is critical for you, with prior OSINT research on request, and receive attack paths to it that are developed and assessed in the workshop – even without a permanently available blue team.

WBRT® combines the open, objective-oriented view of red teaming with the workshop format. The results go beyond the limits of a conventional pentest. Because the workshop consists purely of interviews and no real attacks take place, WBRT® – unlike typical red teaming – involves no risk to your operations. Optionally, an OSINT investigation of publicly visible attack surfaces can precede it. In simplified terms, White Box Red Teaming takes place in four steps.

Defining the “Holy Grail”

You specify what an attacker should achieve – for example, control over a control system in production. So it is not about a single vulnerability, but about an objective that is critical for your organisation.

Optional: research phase with open source intelligence (OSINT)

In this optional step, we carry out reconnaissance on your organisation in advance. We research as much as possible about potential attack surfaces and compare the results with your internal knowledge.

Test servers or marketing campaigns that are still active unnoticed or by mistake turn up again and again.

White Box Red Teaming workshop

The workshop takes place with a comparatively large group of participants from your organisation. Our external red team designs the attack scenarios, which we discuss and document together. All relevant technical contacts are represented:

  • Network administrators
  • Server and client administrators
  • Further specialists depending on the objective, e.g. SAP specialists

Documented attack scenarios

Paths to the agreed objective, discussed together – across individual system boundaries.

Next steps: measures and targeted tests

White Box Red Teaming usually results in so many optimisation steps that you first define and implement a catalogue of measures.

In some cases, we derive attack options where real execution provides additional insight. This practical test is a separate step.

it-sa 2022: WBRT® – White Box Red Teaming The 15-minute talk from the it-sa 2022 trade fair gives an overview of the approach and benefits of WBRT®.

Our expertise

WBRT® – White Box Red Teaming is a testing methodology developed by secuvera. We first presented it in 2019; our managing director Tobias Glemser presented the approach in talks at it-sa 2021 and 2022.

A master’s thesis at Aalen University supported by secuvera has shown on a sound scientific basis how demanding the prerequisites for meaningful conventional red teaming are.

The scenarios are designed by our red team, whose experts are CRTO-certified (Certified Red Team Operator). They draw on experience from penetration tests, which we have been carrying out since 2000 as an IT security service provider certified by the BSI.

Getting started

Selecting an attack objective and the right experts

Name a relevant objective

Consider which access or which outage would be particularly critical for your organisation. This objective is the starting point for the scenarios.

Prepare a WBRT® workshop
Top view of joint map work with notes, compasses and navigation instruments
Scenario planned together, insights going straight to your blue team.

Distinguishing between workshop and practical attacks

The workshop and real technical attacks are separate steps. Whether an additional practical test makes sense is decided on the basis of the results.

Questions about White Box Red Teaming

Do we need a blue team for White Box Red Teaming?

No. A dedicated blue team is not strictly necessary for the workshop. What matters is that the relevant technical contacts contribute their knowledge of networks, systems and applications.

Who should take part in the WBRT workshop?

Typically, network, server and client administrators as well as specialists for the affected business systems are involved. The group of participants depends on the attack objective. The shared knowledge helps to consider possible attack paths beyond individual system boundaries.

Are real attacks carried out in White Box Red Teaming?

The workshop first discusses and documents scenarios. Real technical tests are a separate step. The results may show which attack options should be tested in practice for verification.

How specific does our attack objective need to be?

The objective should describe access that is critical for your organisation, such as control of a control system. It is not only about a single technical vulnerability. The workshop examines the paths by which an attacker could reach this objective.

Why not go straight to real red teaming?

Real red teaming requires a blue team that is active around the clock, involves high effort and carries risks to your processes that cannot be calculated. If these prerequisites are met and you want to test your detection, red teaming is the right instrument. Otherwise, WBRT® provides the attacker’s perspective on your organisation in a workshop format.

Articles on this topic (in German)

All 6 articles on the topic (in German)

How can we support you with White Box Red Teaming?