aptpen.com OPS · ONLINE
scope_engagement →
◢ SERVICES · CAMPAIGN VERTICALS

Fourteen services,
each scoped as a campaign.

// Every offering below maps to one or more MITRE ATT&CK tactics and ships with reproducible findings and proposed detections. Scoping starts from the campaign archetype that matches your sector and threat model, then the relevant services compose into the engagement plan.

§01 14 OFFERINGS · ALL ATT&CK-ALIGNED

Services.

SVC.01adv-em

Adversary emulation

Named-actor TTP replay. We emulate APT29, Volt Typhoon, and Scattered Spider on your stack, with their playbook.

  • Threat-intel scoped
  • ATT&CK-aligned plan
  • Atomic and chained tests
  • Purple-team option
SVC.02red

Red team

Objective-based, full-scope. Initial access through impact. No scanners, no checklists, just operators with a real plan.

  • Black, grey, or white-box
  • OPSEC-tight infrastructure
  • Physical and social
  • Crown-jewel objectives
SVC.03cont

Continuous engagement

Always-on offensive operations. Quarterly operator rotations, persistent infrastructure, weekly findings into your Slack.

  • Dedicated operators
  • CTEM-aligned
  • Retest on patch
  • Slack and Teams integrated
SVC.04ext

External network

Perimeter attack surface. Forgotten subdomains, exposed APIs, leaked credentials, and the management interfaces that get left in production.

  • ASM-driven recon
  • Auth bypass
  • Cred spray, rate-aware
  • Exposed mgmt
SVC.05int

Internal / Active Directory

Assume-breach. Domain Admin in days. ESC1 through ESC15. Kerberoast. BloodHound. The full identity layer.

  • ADCS abuse
  • Tier-0 attack paths
  • NTLM relay
  • Group Policy / GPO
SVC.06web

Web app and API

Beyond OWASP Top 10. Business logic, IDOR chains, GraphQL, OAuth, SSRF-to-cloud.

  • Auth and session
  • Multi-tenant isolation
  • JWT and OIDC abuse
  • GraphQL introspection
SVC.07cloud

Cloud · AWS / Azure / GCP

IAM is the new perimeter. We chain misconfigurations to root, then to your data.

  • IAM privilege chains
  • KMS and Secrets abuse
  • Cross-account trust
  • SSPM and CSPM gaps
SVC.08k8s

Kubernetes and container

Pod to node to cluster to cloud. RBAC, admission, supply chain.

  • RBAC escalation
  • Container breakout
  • Sidecar abuse
  • Helm and Argo supply
SVC.09wifi

Wireless

WPA3, 802.1X, captive portals, rogue APs, BLE and Zigbee, guest network leaks.

  • EAP relay, PEAP downgrade
  • PMKID
  • Rogue AP / Evil Twin
  • BLE / Zigbee
SVC.10phys

Physical and social

Badge cloning, tailgating, drop boxes, vishing campaigns. We get in, we plant, we exfil.

  • HID and Mifare cloning
  • Lock bypass
  • Pretext vishing
  • Implant deployment
SVC.11mob

Mobile

iOS and Android. Static, dynamic, and runtime analysis. Frida, Objection, root and jailbreak chains.

  • IPA / APK reversing
  • Cert pinning bypass
  • Keychain and KeyStore
  • Deeplink abuse
SVC.12ot

OT and ICS

Purdue model. Safe-by-design test plans. PLC, HMI, historian, and jump-host pivots.

  • L3.5 / DMZ review
  • Protocol fuzz (safe)
  • Historian and HMI
  • Vendor remote access
SVC.13ai

AI / LLM red team

Prompt injection, jailbreaks, training-data poisoning, RAG exfil, agent abuse.

  • Indirect prompt injection
  • Tool and agent jailbreak
  • RAG data exfil
  • Model DoS and cost abuse
SVC.14src

Source code review

Manual review by operators who exploit what they find.

  • Auth and session logic
  • Crypto misuse
  • Supply chain
  • SAST tuning and triage
§02 EIGHT INDUSTRIES · ONE NAMED CAMPAIGN EACH

Campaign verticals.

// Each engagement is shaped against the threat model the sector actually faces. The cards below pair an industry to its campaign archetype, the actors emulated, and the objective the work pursues. The codename, the ops plan, and the actor list are real artifacts, drafted before the work begins.

01
VERTICAL.01

Financial services

CAMPAIGN
OPERATION QUIET HARBOR
ACTORS EMULATED
Scattered Spider · FIN7 · APT29
OBJECTIVE
Tier-0 of identity, with an emphasis on the path from help desk to wire-transfer authority.
Vishing-led intrusions and Okta session theft are the dominant pattern. The deliverable answers a single question: what stops the call?
NYDFS 500 SOX FFIEC PCI
02
VERTICAL.02

Healthcare & life sciences

CAMPAIGN
QUIET HARBOR · EHR-FOCUSED
ACTORS EMULATED
APT41 · Scattered Spider · ransomware affiliates
OBJECTIVE
Read-only access to the EHR via a path that bypasses the vendor support model entirely.
Most live intrusions in this sector reach patient data through a vendor jump host. We test that path on purpose, end to end.
HIPAA HITRUST FDA 21 CFR 11
03
VERTICAL.03

Defense & public sector

CAMPAIGN
OPERATION DEEP TIDE
ACTORS EMULATED
APT28 · APT29 · Volt Typhoon
OBJECTIVE
External foothold to a host with access to CUI, validated without internal handoff.
CMMC and DFARS lead the conversation. The campaign reads the way a real adversary reads, end to end, and any audit signature is a byproduct of how the work was run.
CMMC L2 / L3 DFARS 7012 FedRAMP
04
VERTICAL.04

Critical infrastructure

CAMPAIGN
OPERATION IRON BRIDGE
ACTORS EMULATED
Volt Typhoon · Sandworm
OBJECTIVE
Mapped path from IT to L3.5 in OT with observed boundary control. No PLC interaction unless explicitly scoped.
The point is to find the path quietly under safe-by-design test plans that govern every minute of the work and prohibit any PLC interaction outside an explicitly scoped window.
NERC CIP TSA SD IEC 62443
05
VERTICAL.05

Tech & SaaS

CAMPAIGN
OPERATION NORTH STAR
ACTORS EMULATED
Lazarus · APT41 · Scattered Spider
OBJECTIVE
Cloud root through developer identity, the build pipeline, or a production support path.
IAM and CI/CD are the perimeter in this vertical. Most popped tech firms in the last two years started at a developer laptop and reached production through whatever chain of trust that developer happened to inherit.
SOC 2 ISO 27001 GDPR
06
VERTICAL.06

Legal (AmLaw)

CAMPAIGN
QUIET HARBOR · DMS-FOCUSED
ACTORS EMULATED
APT29 · FIN7 · ransomware affiliates
OBJECTIVE
Cross-matter read access from a junior associate identity.
Document management systems ride on AD trust. Matter isolation rarely survives a single working credential.
Model Rule 1.6 GLBA state bar opinions
07
VERTICAL.07

Retail & hospitality

CAMPAIGN
QUIET HARBOR · PCI-FOCUSED
ACTORS EMULATED
Scattered Spider · FIN7 · Lazarus
OBJECTIVE
Access to a network segment with cardholder data, via help-desk pretext or a third-party connection.
A PCI signature is the byproduct of this campaign. The campaign itself answers what a real intrusion looks like in 2026, against a threat profile that shifted years ago.
PCI DSS 4.0 state breach laws
08
VERTICAL.08

Insurance & asset mgmt

CAMPAIGN
OPERATION QUIET HARBOR
ACTORS EMULATED
APT29 · FIN7
OBJECTIVE
Identity tier-0, read access to actuarial or trading systems, no execution beyond proof.
NYDFS 500 audits a controls posture. The campaign tests the operating model that posture depends on.
NYDFS 500 SOX SEC Rule 30

// Verticals beyond this list are almost always still in scope. The eight above are simply the most common shapes the work has taken. Tell us about the environment and we will draft the archetype to match.

Pick the vertical that fits.

Send us a paragraph about the environment, the threat model that keeps a leader awake, and the timeline involved. We respond within one business day with a draft ops plan and a price.

open_intake →