OffensiveGuardian

Sample report

Read the whole deliverable before you buy one.

A complete adversary validation report, cover to appendices. Not an extract, not a teaser, and not behind a form. The client is invented. The methodology, the ratings, the finding template, and the standard of evidence are exactly what a real engagement delivers.

Download the report

84 pages · PDF · no email required

Pages
84
Findings, in full
14
Behaviours tested
36
Retest record
Included

Inside the document

Four pages out of eighty-four.

The rest is in the PDF. Nothing is redacted from the download.

Sample report page: Cover and engagement record

Cover and engagement record

Sample report page: Executive summary and scorecard

Executive summary and scorecard

Sample report page: The evidence matrix, all 36 behaviours

The evidence matrix, all 36 behaviours

Sample report page: One finding, complete

One finding, complete

What you get

Eight things most reports leave out.

01

An executive summary that answers a question

It opens with the decision the engagement was commissioned to settle and answers it in the first paragraph. Objectives, outcomes, and where the defensive chain broke, in three tables a board can read.

02

The attack narrative, with times

What was done, in order, with the moment each step happened and the finding it produced. Written so a defender can see where their own team would have had to be standing to interrupt it.

03

A defensive timeline kept by both sides

Our operator log reconciled against the client's own record of what they saw. Where the two disagree, theirs is authoritative on the defensive side. This is the section that makes the rest checkable.

04

The evidence matrix

Every behaviour we ran, walked along the chain, with the state of the control, the telemetry, the detection, and the analyst decision. One row per reproducible test case.

05

Fourteen findings, none of them orphaned

Each carries two ratings, a business consequence, a root cause, a named owner, ranked remediation with the trade-off stated, and a retest condition written so it can be proven false.

06

What held

Nine controls that stopped a technique we ran deliberately to test them, recorded to the same standard as the failures. A report that only lists breaks gives you no way to tell a working control from an untested one.

07

A retest record with the awkward parts kept in

Nine remediated, three partial with the residual stated precisely, one risk accepted with a named acceptor and a review date, one not remediated. Plus a section on what the retest could not verify and why.

08

Appendices you can act on

Rating definitions, ATT&CK coverage including what was deliberately not run, and a test case catalogue written so your own team can re-run the work without us.

Read this before you read the report

The client does not exist. The deliverable does.

Northwind Mutual Assurance Group is invented, and the report says so from the cover onward. We built a scenario rather than publishing a real client's compromise, which means the environment is a construction and the technical detail is there to carry the illustration. What is real is the instrument: the method, the two rating axes, the evidence standard, and the sections that report what could not be verified. Read it for how it reasons.

Real, and what you would receive

  • The methodology and the four-phase loop
  • The evidence chain notation and its states
  • The two-axis rating system
  • The persistent issue catalogue
  • The finding and retest templates
  • The standard of evidence throughout

Invented for the specimen

  • Northwind Mutual Assurance Group
  • Every finding, timestamp, and number
  • The people, the estate, the outcomes
  • The environment, so technical specifics illustrate rather than document
  • Hostnames and addresses use reserved documentation ranges
  • No real system was tested to produce it

Why there is no form

A report's job is to travel. This one was built to be forwarded to the people who are not in the room: the person who signs, the person who owns the fix, the auditor who asks what you actually got. A form stops a document doing that, and asking for an email before showing evidence is a strange way to argue that we lead with evidence.

Read it, then bring us the thing you cannot currently prove.

An attack path, a coverage claim, or a detection question. We turn it into a controlled, evidence-producing exercise, or tell you if there is no material fit.

Download the report