Adversary Simulation & Incident Response

We find what your team
doesn't know to look for.

Adversary simulation and incident response.
We work where threat models end.

Tell Us About Your Situation →

The Problem

Your security program protects against known threats.

Most programs are built around what's already been named. CVEs get patched. Known attack patterns get detected. Compliance frameworks get checked.

Sophisticated adversaries don't operate in your known space. They find the entry you haven't thought to defend, the detection rule you haven't written, the assumption you didn't know you were making.

That's the unknown unknown. That's where breaches start. That's where we work.

What We Do

01

Adversary Simulation

We attack your environment the way a motivated, well-resourced adversary would — not to generate a compliance report, but to find the paths that will actually hurt your business. Red team operations, assumed breach exercises, and purple team engagements that sharpen your detection capability.

Learn more →
02

Incident Response

When you're breached, every hour costs you. We've been in the room before — with legal counsel, the board, and the threat actor. Retainer-based IR support and emergency response, including ransomware situations that require negotiation alongside remediation.

Learn more →
03

Executive Advisory

Most security leaders speak to engineers. We speak to boards. We translate adversary behavior into business risk, help executives ask the right questions, and provide fractional CISO support for organizations that need senior security leadership without a full-time hire.

Learn more →

How We Work

A methodology built around the adversary, not the deliverable.

01

Threat Profiling

We identify which adversaries are realistically motivated to target your organization. The emulation is built around a credible threat — not a generic attack scenario.

02

Emulation Planning

Threat actor TTPs are mapped to the MITRE ATT&CK framework and sequenced into a structured emulation plan. Every technique has a source — public threat intelligence, government advisories, or documented incident data.

03

Adversary Execution

We operate against your environment the way the named threat actor would — not to find every vulnerability, but to replicate the specific behavior your defenses need to detect and stop.

04

Detection Gap Analysis

Findings are mapped back to ATT&CK technique IDs. You receive a detection coverage map — not a vulnerability list — showing exactly where your security program is blind and where it works.

Why Unknown²

We came up on the defensive side, then switched.

Years building SOC teams and threat intelligence programs gave us an operator's view of what defenders miss. Moving to offensive work made those gaps obvious. We've conducted ransomware negotiations, led enterprise red teams, and built the detection engineering programs that the adversaries we now simulate try to evade.

We work with a small number of clients at a time. The work is deep, not wide. You get a partner who understands your environment — not an engagement manager who hands the work to junior analysts.

  • SOC leadership and threat intelligence program development
  • Ransomware negotiation and crisis response
  • Enterprise red team operations across financial, healthcare, and critical infrastructure sectors
  • Detection engineering — from log architecture to validated SIEM content
  • Board-level security advisory and fractional CISO
About Matticus Hunt →

Representative Work

Work that changes what clients know about their risk.

Adversary Simulation — Financial Services

Full-scope red team engagement against a financial services firm with a mature security program. Reached trading infrastructure undetected. The SOC had no alerts for the duration of the engagement. Six previously unknown attack paths identified and mapped to ATT&CK.

Assumed Breach — Enterprise Healthcare

Assumed breach exercise starting from a compromised endpoint with standard user access. Reached patient data systems and administrative infrastructure without triggering a single alert. A purple team engagement followed, producing validated detection logic for every gap identified.

Incident Response — Active Ransomware

Emergency response to an active ransomware incident at a mid-market manufacturing company. Parallel negotiation and technical containment. Business-critical systems restored within 72 hours while forensic investigation ran concurrently.

Start a Conversation

We work with a small number of clients at a time. If you're evaluating your security posture, managing an active incident, or want to understand what your unknown unknowns look like — tell us about it.

Matticus Hunt

Founder, Unknown²

hello@unknown2.com

Common Questions

What you're probably wondering

What is adversary simulation?
Adversary simulation replicates the full attack lifecycle of a real-world threat actor — from initial access through lateral movement, privilege escalation, and impact — to identify gaps your existing security program cannot detect.
How is adversary simulation different from a penetration test?
Penetration tests focus on finding vulnerabilities in a defined scope. Adversary simulation replicates the behavior of a specific threat actor across your entire environment, testing detection and response capabilities rather than just exploitability.
What is an assumed breach exercise?
An assumed breach exercise starts with the attacker already inside your network, simulating a scenario where perimeter defenses have failed. It tests your ability to detect, contain, and respond to an active intrusion.
What does Unknown² do?
We are an adversary simulation and incident response consultancy. We conduct red team operations, assumed breach exercises, ransomware negotiations, and provide fractional CISO advisory to organizations that need senior security leadership.