Red Quarry

Critical infrastructure penetration testing / adversary simulation

Open brief

146 · Critical infrastructure penetration testing / adversary simulation

Test the controls without turning the test into the outage.

Red Quarry is a fictional authorised security-testing team for utilities, transport and industrial organisations. Exercises are bounded by explicit objectives, safety constraints, stop conditions and evidence handling before any adversary technique is attempted.

Red Quarry visual study for Critical infrastructure penetration testing / adversary simulation

About / field note

Red Quarry is a fictional authorised security-testing team for utilities, transport and industrial organisations. Exercises are bounded by explicit objectives, safety constraints, stop conditions and evidence handling before any adversary technique is attempted.

Unit: exercise objectiveEvidence: authorisation, target boundary, technique, observed control, safety stop and remediation evidence

Evidence

Proof is useful when the denominator is visible.

100%

exercises under written authorisation

0

safety interlocks targeted

1 h

maximum fictional critical finding notification

14 days

default remediation retest window

Offerings

Four ways into the work.

1

Purple-team exercises

Purple-team exercises is scoped through the exercise objective, with authorisation, target boundary, technique, observed control, safety stop and remediation evidence. The boundary, exclusions and handover evidence are stated before work begins.

2

External attack simulation

External attack simulation is scoped through the exercise objective, with authorisation, target boundary, technique, observed control, safety stop and remediation evidence. Capacity, constraints and decision ownership stay visible from intake to closeout.

3

Identity control testing

Identity control testing is scoped through the exercise objective, with authorisation, target boundary, technique, observed control, safety stop and remediation evidence. The boundary, exclusions and handover evidence are stated before work begins.

4

Tabletop-to-technical drills

Tabletop-to-technical drills is scoped through the exercise objective, with authorisation, target boundary, technique, observed control, safety stop and remediation evidence. Capacity, constraints and decision ownership stay visible from intake to closeout.

Work / dispatches

01

Water utility identity drill

A simulated contractor credential compromise tested MFA, privileged access and SOC escalation without touching live process controls.

02

Rail operator perimeter test

Internet-facing assets were validated against inventory, exposing two unmanaged systems before controlled exploitation was necessary.

03

Generator plant purple team

Defenders and testers replayed one approved lateral-movement path while monitoring every alert and block point together.

Process

One loop, four controlled states.

01

Authorise the boundary

Authorise the boundary is the entry control point for a exercise objective. The team records authorisation, target boundary, technique, observed control, safety stop and remediation evidence so the next decision is made from an explicit state, not memory or assumption.

02

Define stop conditions

Define stop conditions is the next control point for a exercise objective. The team records authorisation, target boundary, technique, observed control, safety stop and remediation evidence so the next decision is made from an explicit state, not memory or assumption.

03

Exercise one objective at a time

Exercise one objective at a time is the next control point for a exercise objective. The team records authorisation, target boundary, technique, observed control, safety stop and remediation evidence so the next decision is made from an explicit state, not memory or assumption.

04

Debrief controls, not theatrics

Debrief controls, not theatrics is the next control point for a exercise objective. The team records authorisation, target boundary, technique, observed control, safety stop and remediation evidence so the next decision is made from an explicit state, not memory or assumption.

Reading room

1

A penetration test without asset inventory teaches the wrong lesson

A penetration test without asset inventory teaches the wrong lesson. A working note from Red Quarry on the decisions hidden inside critical infrastructure penetration testing / adversary simulation. It connects the claim back to exercise objective and names where professional judgement or uncertainty remains.

2

Stop conditions are part of good offensive security

Stop conditions are part of good offensive security. A working note from Red Quarry on the decisions hidden inside critical infrastructure penetration testing / adversary simulation. It connects the claim back to authorisation, target boundary, technique, observed control, safety stop and remediation evidence and names where professional judgement or uncertainty remains.

3

Purple teams should measure controls, not ego

Purple teams should measure controls, not ego. A working note from Red Quarry on the decisions hidden inside critical infrastructure penetration testing / adversary simulation. It connects the claim back to authorisation, target boundary, technique, observed control, safety stop and remediation evidence and names where professional judgement or uncertainty remains.

People

Named responsibility

P01

Nora Mensah

Exercise director

Nora Mensah leads exercise director and owns the decisions that touch each exercise objective. The role is described by responsibility, not decorative biography.

P02

Jaco Mthembu

Adversary emulation

Jaco Mthembu leads adversary emulation and owns the decisions that touch each exercise objective. The role is described by responsibility, not decorative biography.

P03

Priya Shah

Defensive validation

Priya Shah leads defensive validation and owns the decisions that touch each exercise objective. The role is described by responsibility, not decorative biography.

Objections / answers

No accordion required

Will you test production systems?
Only where the organisation authorises it and the risk case supports it. Many objectives can be validated without unsafe interaction with live process assets.
Do you provide exploit code?
Findings include enough technical evidence for remediation and retest; weaponisation beyond the authorised need is not part of the service.
Can this replace continuous monitoring?
No. A bounded exercise samples controls at a point in time and should inform, not replace, ongoing defensive operations.

Conversion / next step

Define the objective, authority and stop conditions for the next exercise.

Write to the fictional team