Red TeamOperationsDigital + Physical Adversary Simulation
Full-scope red team engagements in Malaysia combining digital attacks, physical penetration testing (badge cloning, tailgating, USB drops), and social engineering — to test your organisation's complete security posture against real-world threats.
What is a red team engagement?
A red team engagement is a goal-oriented adversary simulation. Unlike a penetration test — which catalogues vulnerabilities in a defined scope — a red team engagement asks a harder question: can a realistic threat actor reach your Crown Jewels, and would your people, processes, and technology detect and stop them?
nCrypt's red team engagements are full-kill-chain operations. We do not limit our operators to a defined attack surface. We pursue a stated objective — access to the finance system, exfiltration of customer PII, physical entry to the data centre — using any combination of digital exploits, social engineering, and physical intrusion that a real adversary would deploy.
All engagements operate under a signed Rules of Engagement document, an agreed time-window, an emergency abort process, and a get-out-of-jail letter carried by every on-site operator. Nothing moves without written authorisation.
Comprehensive adversary simulation
Our red team operations simulate real-world attacks across digital, physical, and human attack vectors.
Digital Attack Simulation
- Initial access techniques
- Lateral movement
- Persistence mechanisms
- Data exfiltration
- Command & control
- Defense evasion
Physical Security Testing
- Facility access testing
- Badge cloning
- Tailgating assessments
- Secure area penetration
- Document disposal review
- Physical device access
Social Engineering
- Spear phishing campaigns
- Vishing (voice phishing)
- Pretexting scenarios
- Baiting attacks
- Impersonation testing
- Security awareness metrics
On-site physical red team in Malaysia
Physical security testing is conducted by vetted operators under signed Rules of Engagement. Every technique below requires explicit customer authorisation and operates within an agreed time-window with a live emergency contact tree.
Tailgating & Piggybacking
Operators attempt to follow authorised staff into controlled areas — lobbies, server rooms, executive floors — without valid credentials. Scenarios range from visitor impersonation to delivery personnel pretexts, all within written Rules of Engagement.
Badge Cloning (RFID / HID / Mifare)
Using long-range RFID readers, operators clone low-frequency (125 kHz HID/EM4100) and high-frequency (13.56 MHz Mifare Classic) proximity card credentials. Cloned badges are used to access target areas and demonstrate the risk of unencrypted card technologies still deployed widely in Malaysian buildings.
Lock-Picking & Physical Bypass
Padlocks, pin-tumbler cylinders, door-code panels, and server-rack locks are evaluated under written ROE with explicit time-windows. Objectives are agreed in advance — never destruction, always detection. Findings document how long each bypass takes and what evidence is left behind for defenders.
USB Drop Campaigns
Custom USB payloads are left in high-footfall areas — car parks, reception desks, break rooms. We measure how many devices are inserted, how quickly, and whether endpoint controls (USB block policies, AV) fire in time. Payloads are safe, non-destructive, and beacon only to nCrypt's controlled listener infrastructure.
Pretext-Based On-Site Reconnaissance
Operators conduct walk-throughs using pre-agreed pretexts (vendor visit, fire-safety inspection, job candidate tour) to map physical security controls, CCTV blind spots, door schedules, and staff behaviours. Reconnaissance findings directly inform later physical and digital access attempts within the same engagement.
Four hard rules — no exceptions
These rules apply to every nCrypt red team engagement. They are non-negotiable.
Written authorisation only
A signed scope document and letter of authorisation from the customer's accountable executive must be in nCrypt's possession before any testing — digital or physical — begins.
Agreed scope and time-window
Locations, systems, personnel, and testing hours are agreed in advance and documented. Operators do not deviate from the agreed scope without a written change request.
Emergency stop process — always active
A 24/7 abort line connects directly to the customer's named security lead. Any party — operator or customer — can halt all testing immediately. All on-site activity ceases within minutes of an abort call.
Get-out-of-jail letter on every operator
Every physical operator carries a printed authorisation letter on the customer's headed paper, signed by the customer's authorised representative. This letter is presented immediately if operators are challenged by security, police, or other third parties.
Combined digital + physical engagement timeline
Six phases covering ROE sign-off through final debrief. Nothing proceeds to the next phase without the prior phase being complete and documented.
ROE & Legal Authorisation
Signed scope document, emergency contact tree (24/7 abort line), and a get-out-of-jail letter issued to every on-site operator before any testing begins. Time-windows are agreed per-venue. Nothing physical proceeds without written customer sign-off.
OSINT & Reconnaissance
2–3 weeks of passive intelligence gathering: employee profiling, LinkedIn, Maltego entity mapping, exposed credential hunting, physical site photography from public areas, building access schedule observation, and digital perimeter fingerprinting.
Digital Initial-Access Attempts
Phishing, spear-phishing, vishing, password spraying, and exploitation of externally facing services. Objective is to establish a foothold before any physical presence — mirroring how real threat actors operate.
Physical Reconnaissance & On-Site Testing
1–2 days on-site per agreed location. Operators execute tailgating, badge-cloning, USB drops, and lock evaluation attempts under strict time-windows and with the emergency contact tree active throughout.
Lateral Movement & Objective Pursuit
Once initial access — digital or physical — is established, operators attempt lateral movement toward the agreed objective: Crown Jewels access, data exfiltration proof-of-concept, domain-admin compromise, or physical server access.
Reporting & Debrief
Full written report delivered within 10 business days of test completion. Live debrief with the blue team (SOC/IR). Findings mapped to MITRE ATT&CK. Remediation roadmap with ownership, effort, and priority scoring.
What you receive: sample report contents
Every nCrypt red team engagement produces a structured written report delivered within 10 business days of test completion. The report is accompanied by a live debrief session with the customer's security and operations teams.
Three engagement archetypes
Indicative starting prices. Final scope and cost depend on number of locations, target complexity, and duration. All prices are exclusive of SST.
Goal-Based
4–6 weeks
From RM 80,000
Single agreed objective (e.g., 'access the payroll server' or 'reach the trading floor'). Full digital + physical kill chain. Ideal for first-time red team customers or specific Crown Jewels validation.
- One primary objective
- Digital + physical kill chain
- OSINT & reconnaissance phase included
- Get-out-of-jail letter + emergency contact tree
- MITRE ATT&CK-mapped report
- Live debrief with blue team
Purple Team
8 weeks
From RM 120,000
Collaborative exercise with your defenders present. Offensive actions are announced incrementally to the SOC, allowing real-time improvement of detection rules and response playbooks. Best for maturing blue teams.
- Collaborative attack + defend format
- SOC/SIEM tuning sessions included
- Detection-rule development workshop
- Tabletop + live execution hybrid
- Weekly progress reviews
- Detection coverage improvement metrics
Continuous Adversary Simulation
12 weeks
From RM 180,000
Sustained campaign that mirrors an advanced persistent threat. Multiple objectives, repeated attempts, evolving TTPs. Measures whether your organisation's detection and response improves over time under sustained pressure.
- Multiple objectives across campaign
- Evolving TTPs per wave
- Monthly interim reports
- Physical + digital + social engineering all waves
- Trend metrics: MTTD, MTTR per wave
- Final maturity scoring + roadmap
Frequently asked questions
Common questions about red team engagements and physical security testing in Malaysia.
Do you conduct physical red team engagements in Malaysia?
Yes. nCrypt conducts physical red team engagements across Peninsular Malaysia and East Malaysia under strict written Rules of Engagement. Every on-site operator carries a get-out-of-jail letter signed by the customer's authorised representative and an emergency abort contact number that reaches the customer's security lead 24/7. Physical testing — badge cloning, tailgating, lock evaluation, USB drops — proceeds only within the agreed time-window and scope documented in the signed engagement authorisation.
What is the difference between a red team engagement and a penetration test?
A penetration test is a time-boxed, scoped technical assessment of a defined attack surface — a web application, a network segment, a set of IP ranges. It answers 'what vulnerabilities exist in these systems.' A red team engagement is a goal-oriented adversary simulation across the full attack kill chain — digital, physical, and human — that answers 'can a realistic threat actor reach our Crown Jewels, and would we detect and stop them in time.' Red team engagements are deliberately stealth-oriented; the blue team is not typically informed in advance (except in purple team variants).
Is red team testing legal under Malaysian law?
Yes, when conducted under signed customer authorisation. The Computer Crimes Act 1997 (CCA 1997) §3 (Unauthorised Access) and §5 (Modification of Computer Contents) create criminal liability for unauthorised access. A properly documented red team engagement — signed authorisation, defined scope, agreed time-window — establishes explicit consent that removes the conduct from CCA 1997 prohibition. nCrypt requires a signed Rules of Engagement document and letter of authorisation before any testing begins. Customers should involve their legal counsel in reviewing the authorisation document if required.
Who carries out the physical testing — are they certified?
Physical red team operations are conducted by vetted operators under signed Rules of Engagement. All operators are background-checked, operate under nCrypt's direct supervision, and carry customer-issued authorisation letters throughout. We do not claim CREST Physical certification for on-site operators; the engagement authorisation framework is the legal and operational safeguard. Digital components are assigned to practitioners with relevant credentials confirmed during scoping.
How do you handle an emergency or unexpected incident during on-site testing?
Before any physical testing begins, we establish an emergency contact tree: a named customer security lead reachable 24/7 by both direct phone and a secondary contact. Every on-site operator has the abort number saved and carries a get-out-of-jail letter printed on the customer's headed paper with the authorised signatory's details. If local security, police, or any third party challenges an operator, the operator immediately presents the letter and calls the abort number. All on-site activities cease and nCrypt notifies the customer's CISO within 30 minutes of any incident.
Does your red team cover cloud environments and OT/ICS?
Digital red team components cover cloud environments (AWS, Azure, GCP, Alibaba Cloud) as part of the initial-access and lateral-movement phases. OT/ICS red team is a specialist sub-discipline — speak to us about scope; engagements that include OT targets require additional safety engineering and are priced separately.
How long does a red team engagement take?
Goal-based engagements run 4–6 weeks from ROE sign-off to report delivery. Purple team engagements run approximately 8 weeks. Continuous adversary simulation runs 12 weeks. These include the OSINT/reconnaissance phase, active testing, and reporting. We do not begin active testing before reconnaissance is complete and the authorisation documents are signed.
Pairs naturally with
Penetration Testing
Scoped technical assessments that validate specific attack surfaces before or alongside a red team engagement.
Attack Surface Management
Continuous external surface discovery that feeds directly into red team OSINT and reconnaissance phases.
Digital Risk Protection
Dark web and threat intelligence monitoring that surfaces adversary targeting activity before red team findings need to be learned the hard way.
Talk to a senior security consultant
Share your scope. We'll come back with a fixed-fee proposal.
Get a Free Quote
Share your scope. We'll come back with a fixed-fee proposal.
Test your complete security posture
Red team engagements provide the most realistic assessment of your organisation's ability to detect and respond to a determined adversary — digital or physical. Contact us to scope your engagement.
Related Services
Complementary services Malaysian buyers commonly pair with red team operations.
Social Engineering Assessment
Phishing, vishing and physical intrusion testing of your people layer.
Learn morePhishing Simulation
Targeted phishing campaigns to baseline and uplift user resilience.
Learn moreBreach & Attack Simulation
Continuous control validation against MITRE ATT&CK techniques.
Learn moreNot sure what you need?
Tell us what needs testing and we come back with a fixed fee within 48 hours — no hourly estimates.