Skip to content
winfunc
Red teaming

Adversary emulation that starts from your source code.

Objective-driven engagements that chain real weaknesses across code, cloud, and identity, map every step to MITRE ATT&CK, and prove each one before it reaches your report.

What's included
  1. acme
  2. /Engagements
  3. /Red team · Q3
Objective reached
ObjectiveRead customer invoice exports from outside the network
1Initial accessT1190

Webhook preview fetches any URL

POST /integrations/test url=http://169.254.169.254/webhooks/preview.ts:61
2Credential accessT1552.005

Instance role credentials read from the metadata service

GET /latest/meta-data/iam/security-credentials/app-role
3Privilege escalationT1078.004

Role grants s3:GetObject on every bucket

iam/role/app-role s3:* on arn:aws:s3:::*infra/iam.tf:88
4CollectionT1530

Invoice exports listed and read from storage

s3://acme-exports/2026-09/*.csv
Engagement
Window
Sep 8 – Sep 19
Rules
Sandbox copies only · no customer data leaves
Findings
4 linked · 2 critical
Detected
1 of 4 steps
Red team · attack chainIllustrative data
The problem

Attackers chain small issues. Most testing reports them one at a time.

A medium-severity SSRF, an over-broad cloud role, and a readable bucket rarely look urgent on their own. Together they are a breach. winfunc works toward an objective you agree on and chains weaknesses the way an attacker would, with the source code open, so every step is understood rather than guessed.

Included

What winfunc covers.

  • Objectives and rules of engagement agreed before testing starts
  • Attack chains across application code, cloud configuration, and identity
  • Every step mapped to MITRE ATT&CK tactics and techniques
  • Code-informed exploitation: entry points, data flows, and trust boundaries read from source
  • Proof for each step, captured against agreed targets or isolated replicas
  • Detection notes for each step: what your monitoring saw and what it missed
  • Fixes opened as pull requests, then the chain run again
Outcomes

What your team walks away with.

01

The path, not just the parts

See how individual weaknesses combine into a route to the objective, and which single fix breaks the chain earliest.

02

Evidence at every step

Each step records the request, the response, and the code behind it, so your engineers can reproduce it without us.

03

A head start for defenders

Detection notes feed straight into a purple team replay, so the gaps the chain exposed turn into tested rules.

04

Closed, then re-tested

Fixes land as pull requests and the chain runs again. The engagement ends when the objective is no longer reachable.

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

Scoped with you. Delivered with evidence.

A voxel chessboard: a bone rook and a red knight, with the traced path between them lit green after the fix was verified