Skip to content
Caldmere Technologies

Find out before someone else does.

Risk intelligence, signature management, custom security software, and full-scope red teaming — across your networks and the physical space around them.

Engagement replay Synthetic — not a client engagement
  1. T+00:00 Initial access Credentialed phish. No malware, no payload. Undetected
  2. T+00:47 Discovery Directory and file share enumeration. Undetected
  3. T+04:12 Credential access Cached service account ticket recovered. Undetected
  4. T+11:36 Lateral movement Jump host to build infrastructure. Undetected
  5. T+29:05 Collection Source repository and signing material staged. Undetected
  6. T+52:07 First detection Endpoint alert raised. Triaged as benign. Alert
Time before anyone noticed 52h07m

The gap between the first action and the first alert is the number worth knowing. Most organizations have never measured theirs.

US-based engineering
No offshore development. Provenance is never in question.
Written rules of engagement
Scope, deconfliction, and abort criteria agreed before we touch anything.
OPSEC discipline
We do not publish clients, engagements, or findings. Yours included.
Methodology you can audit
Engagements map to recognized frameworks, so results compare over time.
Why Caldmere

The team that breaks it also builds it.

One team, both sides

The operators who run the engagement are the engineers who build your systems the rest of the week. Findings come back with working fixes — and when the fix needs software that does not exist yet, the same team builds it.

Findings you can act on

Every report is ordered by consequence to your business, with reproduction steps and a named owner against each item. No severity inflation to pad a total, no four-hundred-page PDF nobody opens.

We write down what we did not test

Scope limits, blocked paths, and anything we ran out of time on are stated plainly in the report. An assessment that hides its own gaps is worse than no assessment, because you will trust it.

How it runs

How an engagement runs.

Five phases, agreed in advance. It starts with us understanding your environment and ends with the fix built and proven. The only party a red team should surprise is the one being tested.

  1. Engage

    We go through your environment with you: what you run, what protects it, and where coverage actually ends. Most teams finish this step knowing things about their own estate they did not know going in.

  2. Scope

    Objectives, rules of engagement, deconfliction contacts, and abort criteria — agreed in writing, and shaped by what the review found rather than by a standard package.

  3. Execute

    We work the objective the way an adversary would, logging every action with timestamps so it can be replayed against your own telemetry afterward.

  4. Report

    Prioritized findings with reproduction steps, business consequence, and owners. Delivered to a briefing with your team in the room, not dropped in an inbox.

  5. Remediate

    We build the fix rather than recommend it: remediation engineering, custom tooling, and platform changes written by the same team that found the problem. Where people were the way in, that includes training built from the pretexts that actually worked on your staff — not a click-through module. Then we retest to prove it holds.

Engage

It starts with a review of what you already have.

Tell us what you are responsible for. We go through your current setup, map where your coverage actually ends, and come back with an approach, a team, and a scope.