Threat-Led Penetration Testing

Test your resilience against the threats that matter.

StealthMole TLPT transforms relevant threat intelligence into realistic, organisation-specific attack scenarios. We help financial institutions, critical industries and government organisations assess how effectively their people, processes and technology can prevent, detect and respond to the adversaries most likely to target them.

Intelligence-led. Scenario-driven. Governed for safe and controlled execution.

WHY TLPT

Move from generic findings to evidence-based resilience.

A conventional penetration test is valuable for identifying technical weaknesses in a defined environment. But critical organisations also need to understand whether their defences can withstand the behaviours of real adversaries operating in their sector.

Threat-Led Penetration Testing begins with intelligence. It considers the organisation's critical functions, sector dynamics, attack history, relevant threat actors, third-party dependencies and governance obligations. These inputs are used to build plausible attack scenarios that test more than a single control: they test how prevention, detection, decision-making and response work together under realistic pressure.

Relevant by design

Focus testing on the adversaries, assets and attack paths that present the greatest credible risk to your organisation.

Grounded in evidence

Use targeted threat intelligence to justify scenario selection, attacker behaviours and testing priorities.

Built for learning

Turn observations into concrete improvements across security controls, operational processes and executive governance.

Penetration testing finds weaknesses. TLPT tests resilience in context.

Dimension Conventional Penetration Testing Threat-Led Penetration Testing
Starting point Defined assets, vulnerabilities or control requirements Critical functions and the threats most relevant to the organisation
Scenario basis Known techniques and a predetermined technical scope Targeted intelligence on sector threats, actors, intent, capability and TTPs
Test focus Technical exposure and exploitability People, processes and technology supporting critical functions
Execution Time-boxed assessment of selected systems Controlled, scenario-driven emulation of realistic attacker behaviour
Defensive learning Findings and remediation recommendations Prevention, detection and response observations, purple teaming and improvement planning
Primary outcome A clearer view of technical weaknesses Evidence of how the organisation responds to credible, intelligence-led attack scenarios

Note: TLPT does not replace every form of vulnerability assessment or penetration testing. It complements them by applying threat intelligence and operational context to the testing of critical functions.

THE INTELLIGENCE FOUNDATION

Scenarios informed by the external threat environment.

StealthMole investigates threat activity across the deep and dark web and other external sources relevant to cybercrime. For a TLPT engagement, our specialists identify the intelligence that is relevant to the organisation, its sector and the agreed scope. This evidence helps determine which adversaries and attack paths deserve attention and why.

Deep and dark web exposure

Signals associated with illicit marketplaces, forums, infrastructure and criminal communities that may affect the organisation or its sector.

Compromised credentials and access

Evidence of exposed accounts, credential abuse and access pathways that could support intrusion scenarios.

Ransomware and extortion ecosystems

Actor activity, victimology, leak-site signals and sector-specific patterns relevant to disruptive and data-extortion threats.

Hacking forums and criminal channels

Discussions, tools, tradecraft and intent observed in underground communities and channels, including relevant Telegram activity.

Actor and TTP context

An assessment of the actors most relevant to the target environment, including their motivation, capability, targeting patterns and known tactics, techniques and procedures.

Organisation-specific exposure

Externally observable information that may influence reconnaissance, social engineering, credential attacks, supply-chain access or targeting decisions.

Evidence principle: Intelligence is selected for relevance and assessed by specialists. A signal is not treated as fact without appropriate evaluation, and the absence of an observed signal is not presented as proof that a threat does not exist.
OUR METHODOLOGY

From critical functions to controlled attack simulation.

Every engagement is tailored to the organisation, but the methodology follows a disciplined lifecycle designed to preserve safety, evidence and learning.

  1. Initiation & Governance

    We establish the engagement mandate, decision rights and operating boundaries before testing begins. The organisation appoints a small control team, identifies accountable stakeholders and agrees how sensitive information will be handled.

    • Confirm objectives, stakeholders and governance structure.
    • Define legal, privacy, regulatory and contractual constraints.
    • Agree escalation paths, risk acceptance, stop conditions and emergency contacts.
    • Set rules for evidence handling, communications and provider access.
    Output: Engagement governance, roles and rules of engagement.
  2. Critical Function Scoping

    We identify the business services whose disruption or compromise would create the greatest operational impact. The scope connects these critical functions to the people, processes, applications, infrastructure and third parties that support them.

    • Map critical functions and supporting systems and services.
    • Identify material third-party and supply-chain dependencies.
    • Define scenario objectives and evidence-based compromise flags.
    • Document exclusions and prohibited actions.
    Output: A controlled scope specification linking critical functions to test objectives.
  3. Targeted Threat Intelligence

    Our threat intelligence specialists develop a target-specific view of the adversaries and external exposures that are most relevant to the organisation and its sector.

    • Review sector attack history, geopolitical and criminal motivations, and relevant campaigns.
    • Assess actor intent, capability, targeting patterns and TTPs.
    • Investigate relevant deep and dark web exposure, compromised credentials, criminal channels and ransomware activity.
    • Evaluate organisation-specific information that could support reconnaissance or initial access.
    • Record confidence, relevance and limitations for key intelligence judgments.
    Output: A targeted threat intelligence assessment and a justified set of candidate threat scenarios.
  4. Scenario Design

    Threat intelligence is translated into realistic attack narratives. Each scenario connects a relevant actor profile to a critical function, plausible entry points, attacker objectives and observable defensive opportunities.

    • Prioritise scenarios by relevance, plausibility, impact and safe testability.
    • Map attacker behaviours to recognised TTPs, using MITRE ATT&CK where appropriate.
    • Define attack paths, scenario flags, test evidence and decision gates.
    • Revalidate scope and safeguards before execution.
    Output: An approved red team test plan with intelligence-backed scenarios and safety controls.
  5. Controlled Red Team Execution

    The red team emulates the agreed adversary behaviours against the in-scope environment. Testing is conducted under the authority of the control team and within the approved rules of engagement.

    • Conduct reconnaissance and simulate agreed access and attack paths.
    • Emulate selected adversary TTPs without exceeding approved boundaries.
    • Capture evidence of security controls, detection opportunities and response actions.
    • Use escalation and stop procedures when safety thresholds are reached.
    • Adapt execution only when intelligence, operational conditions and authorisation support the change.
    Output: Controlled test evidence and an account of the attack paths attempted and achieved.
  6. Purple Teaming, Reporting & Remediation

    Testing concludes with structured collaboration between offensive and defensive stakeholders. The objective is not a pass-or-fail score, but a shared understanding of what happened, what was visible and what should improve.

    • Replay selected techniques with defenders to validate telemetry and detection logic.
    • Identify root causes across technology, process, communication and governance.
    • Prioritise remediation by critical function, risk and achievable impact.
    • Define owners, target outcomes and opportunities for retesting.
    • Brief technical teams, operational leadership and executives at the appropriate level of detail.
    Output: Red team and defensive observations, a purple team record, executive findings and a prioritised remediation plan.
SECTOR CONTEXT

Threats behave differently across industries. Testing should too.

The following examples illustrate how sector context can shape a TLPT scenario. They are representative examples, not claims about a specific customer or active operation.

Financial Services

From compromised access to a critical payment function

Intelligence indicates that financially motivated actors are trading credentials and targeting remote access, service providers and privileged identities in the financial sector. A controlled scenario tests whether an actor could use a plausible access path to approach a critical payment or customer service function while evading or delaying detection.

Capabilities assessed

  • Identity and privileged-access controls
  • Third-party access governance
  • Detection of credential abuse and lateral movement
  • Coordination between security, fraud, operations and crisis teams
Manufacturing & Energy

IT intrusion with potential operational consequences

Sector intelligence shows that ransomware and extortion actors frequently exploit exposed credentials, suppliers and poorly separated environments. A safe scenario examines how an initial IT compromise could threaten systems supporting production or energy operations without performing prohibited actions against safety-critical assets.

Capabilities assessed

  • IT and operational technology boundary controls
  • Supplier and remote-maintenance access
  • Detection and containment across segmented environments
  • Operational escalation and continuity decision-making
Government & Public Sector

Targeted access to sensitive public-sector information

Threat intelligence identifies a relevant actor profile interested in public policy, citizen data or government operations. A controlled campaign combines externally available targeting information with approved social-engineering and credential-based techniques to assess whether sensitive services and information can be reached and whether the activity is detected and escalated.

Capabilities assessed

  • Protection against targeted social engineering and credential compromise
  • Monitoring of external exposure and criminal channels
  • Detection of persistence and unauthorised access
  • Coordination between security, leadership, legal and public-sector stakeholders

These scenarios are illustrative. Each engagement is designed from the intelligence and critical functions specific to the organisation.

FRAMEWORK ALIGNMENT

A methodology informed by established European resilience frameworks.

TIBER-EU provides a European framework for threat intelligence-based ethical red teaming. It describes how authorities, tested entities, threat intelligence providers and red team testers can work together to conduct controlled, intelligence-led tests of critical functions.

The EU Digital Operational Resilience Act (DORA) establishes requirements for threat-led penetration testing for designated financial entities. Commission Delegated Regulation (EU) 2025/1190 specifies regulatory technical standards covering identification criteria, the use of internal testers, scope, methodology, testing phases, results, closure, remediation and supervisory cooperation.

The TIBER-EU framework was updated in 2025 to align with the DORA TLPT regulatory technical standards, including required process steps, deliverables, terminology and mandatory purple teaming. A TIBER-EU-aligned approach can therefore support relevant financial entities as they prepare for and conduct DORA TLPT activities.

Important qualification: Applicability and compliance obligations depend on the entity, jurisdiction and competent authority. StealthMole TLPT services should be assessed against the organisation's specific regulatory requirements and procurement criteria. This page does not constitute legal advice, certification or a guarantee of regulatory compliance.

Official references

WHAT YOU RECEIVE

Evidence for technical action and executive decisions.

  1. Scope and governance package

    Critical functions, in-scope systems and services, stakeholder roles, rules of engagement, escalation paths and stop conditions.

  2. Targeted threat intelligence assessment

    Relevant actor profiles, external exposure, sector context, intelligence judgments, confidence and limitations.

  3. Intelligence-backed scenario portfolio

    Prioritised attack narratives linking threat actors and TTPs to critical functions, objectives and observable flags.

  4. Red team test plan and execution record

    Approved attack paths, safety controls, activities performed and evidence collected during controlled execution.

  5. Detection and response observations

    A view of what defenders could prevent, observe, investigate, escalate and contain across the tested scenarios.

  6. Purple team outcomes

    Validated telemetry, detection opportunities and shared learning from selected technique replays.

  7. Prioritised remediation plan

    Actions grouped by critical function, risk, ownership and intended security outcome.

  8. Executive briefing

    A concise account of material resilience themes, business implications and decisions requiring leadership attention.

CONTROLLED BY DESIGN

Realistic testing without unmanaged risk.

The value of TLPT depends on realism, but realism does not remove the need for control. Every engagement requires explicit authorisation, defined accountability and safeguards proportionate to the target environment.

Authorised scope

Testing is limited to approved objectives, systems, identities and techniques.

Control team oversight

A small, authorised team governs the engagement and can escalate, pause or stop activity.

Risk-based stop conditions

Safety thresholds and emergency contacts are agreed before execution.

Sensitive evidence handling

Collection, access, storage, transfer, retention and destruction requirements are documented.

Third-party coordination

Provider, cloud, legal and contractual dependencies are identified before testing affected services.

Operational protection

Prohibited actions and special controls protect safety-critical, life-critical and high-impact services.

Need-to-know communication

Test secrecy is balanced with legal, safety and accountability requirements.

Traceable decisions

Material scope, scenario and risk decisions are recorded and approved.

PLATFORM IN ACTION

See how TLPT works — from domain to dashboard.

The following screens illustrate a representative TLPT workflow inside the StealthMole platform. Each stage translates raw intelligence and domain context into actionable security findings.

Step 01

Domain Input & Target Scoping

The engagement begins when an analyst enters the target organisation's primary domain. The platform immediately queries multiple intelligence sources — dark web markets, credential leak databases, sector threat feeds, and exposed infrastructure signals — to build an initial exposure profile.

Supported inputs: primary domain, subsidiary domains, ASN ranges, brand keywords. The platform resolves DNS records, identifies hosting providers, maps known IP space, and flags any immediately observable external exposures before formal scoping begins.

app.stealthmole.com / tlpt / new-engagement
Navigation
Dashboard
New Engagement
All Engagements
Threat Intel
Reports
New TLPT Engagement

Define Target Domain

Enter the primary domain of the organisation under test. The platform will begin building an intelligence exposure profile immediately.

targetbank.co.kr
Analyse Domain
+ Add subsidiary domain + ASN range + Brand keyword
Dark Web Signals
14
credential leaks detected
Exposed Infra
7
open services found
Threat Actors
3
relevant sector actors
Step 02

Knowledge Analysis & Guideline Generation

After domain submission, the platform analyses the organisation's sector classification, regulatory environment, and observed threat actor activity. It cross-references this context against a knowledge base of sector-specific attack patterns to auto-generate a tailored diagnostic guideline set.

The generated guidelines include: applicable threat actor profiles (with TTP mappings), prioritised attack surface categories, recommended test objectives for each critical function area, and initial scenario hypotheses ranked by relevance and plausibility. Analysts review and approve the guideline set before it advances to the procedure phase.

app.stealthmole.com / tlpt / engagement / KR-2025-041 / guidelines
KR-2025-041
Domain Input
AI Analysis
Checklist
Dashboard
AI Analysis Complete

Sector Knowledge & Generated Guidelines

Financial Services · Korea
Sector Intelligence Summary
Lazarus Group and APT38 active against Korean financial sector
Credential stuffing via dark web markets (3 active campaigns)
Supply-chain targeting of fintech middleware vendors
SWIFT messaging systems remain high-value target class
Auto-Generated Test Objectives
OBJ-01Assess credential-based initial access pathways
OBJ-02Evaluate third-party API trust boundaries
OBJ-03Test lateral movement to payment processing
OBJ-04Detect capability: SOC visibility and SIEM coverage
Generated Diagnostic Guidelines — 6 guidelines ready for review
GL-01 Phishing & Credential Harvest
GL-02 VPN / Remote Access Abuse
GL-03 Supply-Chain Pivot
GL-04 Lateral Movement to Core Systems
GL-05 Payment Function Proximity
GL-06 SOC Detection Coverage
Step 03

Guideline Procedure & Interactive Checklist

The approved guidelines are expanded into a structured test procedure with phased activities, evidence collection requirements, and completion checkpoints. Each procedure item links back to the originating threat scenario and maps to MITRE ATT&CK techniques where applicable.

The interactive checklist tracks: reconnaissance activities completed, initial access vectors tested, lateral movement paths explored, critical function proximity flags triggered, detection and response observations recorded. Control team members can annotate items, record stop decisions, and mark evidence artefacts directly against checklist entries in real time.

app.stealthmole.com / tlpt / engagement / KR-2025-041 / checklist / GL-04
Guidelines
GL-01 Phishing
GL-02 Remote Access
GL-03 Supply-Chain
GL-04 Lateral Movement
GL-05 Payment Function
GL-06 SOC Coverage
Progress
3 of 6 complete
In Progress

GL-04 · Lateral Movement to Core Systems

MITRE: TA0008 · T1021 · T1550
Enumerate internal DNS and AD structure via compromised foothold
Recon T1018
Attempt pass-the-hash against service accounts identified in GL-01
Exec T1550.002
Evaluate Kerberoasting opportunities on high-privilege SPNs
Exec T1558.003
Attempt RDP / SMB pivot toward core banking VLAN segment
Movement T1021.001
Active
Test trust relationships between DMZ and internal application tier
Movement T1021.002
Record SOC alert latency — first detection event timestamp
Detect Detection
Validate SIEM coverage: lateral movement rules firing correctly
Detect Detection
Step 04

Hacking Scenario Dashboard & Threat Score

The final dashboard consolidates all executed attack scenarios into a unified view. Each scenario is scored across four dimensions — access difficulty, detection probability, potential impact, and remediation complexity — producing a composite Threat Score that prioritises findings by business risk.

Dashboard panels include: scenario execution timeline with key events, ATT&CK technique heatmap, critical function proximity chart, detection and response gap analysis, and a ranked remediation backlog. Executive and technical views can be toggled, and all data is exportable for inclusion in the formal engagement report.

app.stealthmole.com / tlpt / engagement / KR-2025-041 / dashboard
Engagement KR-2025-041 · Final Dashboard

Hacking Scenario Outcomes & Threat Score

Executive View
Technical View
Composite Threat Score
7.4
HIGH RISK
Scenarios Executed
6/6
all completed
Critical Function Reached
2
payment + auth
Detection Rate
38%
62% undetected
Scenario Threat Score Breakdown
SC-01 Credential Stuffing → Account Takeover 6.4
Access
Detect
Impact
Remediate
SC-02 Supply-Chain API → Internal Pivot 6.1
Access
Detect
Impact
Remediate
SC-03 Spear-Phishing → Finance Staff 6.1
Access
Detect
Impact
Remediate
SC-04 VPN Exploit → Core Banking Reach 6.2
Access
Detect
Impact
Remediate
ATT&CK Technique Coverage
Initial Access 4/4
Execution 3/5
Persistence 2/4
Lateral Movement 3/4
Collection 1/3
Top Remediation Priorities
P1 Enforce MFA on all external-facing portals
P1 Segment payment VLAN from general IT environment
P2 Deploy UEBA rules for after-hours service account activity
P2 Review third-party API permission scopes
FAQ

Common questions about TLPT.

Build a test around your real threat environment.

Talk to StealthMole about your critical functions, sector exposure and resilience objectives. We will help you explore whether a threat-led engagement is appropriate and how relevant intelligence can inform the scope.

No new application account is required. Your enquiry will use StealthMole's existing contact process.