TLPT: Realistic Testing with an “Assumed-Breach Mindset”
Cybersecurity is no longer just about closing known vulnerabilities.Organizations must prepare for a realistic scenario: what if an attacker is already inside? This is where TLPT (Threat-Led Penetration Testing) comes in.
With TLPT, an “assumed breach” approach is used. This means we do not only try to gain access, but above all test how far an attacker can get, and how well an organization detects and responds to the attack.
Limina Hacking Company uses this approach to give organizations a realistic view of their cyber resilience.
What is TLPT?
TLPT (Threat-Led Penetration Testing) is an advanced form of a red team engagement, in which real threat actors are simulated. Unlike traditional penetration testing, the focus is not only on technical vulnerabilities, but on the full attack path: from initial access to impact.
A TLPT engagement always starts with thorough preparation.

Step 1: Business Profiling & OSINT
Before an attack begins, we perform business profiling. This includes looking at:
Company structure
Critical systems
Key employees
Sector-specific threats
This process makes extensive use of OSINT (Open Source Intelligence.) This means that public sources are analyzed, such as:
Websites
Annual reports
Job vacancies
Technical documentation
Social platforms also play an important role. Social media attacks often start with information that employees unknowingly share, such as job titles, tools, and internal processes.
Step 2: Digital Footprint & Data Reconnaissance
Every organization leaves a trace: its digital footprint. Limina Hacking Company maps this out completely, including:
Domains and IP-ranges
External systems
Cloud environments
Data breaches are also investigated, such as password dumps. This involves looking at previously compromised accounts that could potentially be reused.
Step 3: Social Engineering & Initial Access
An important part of TLPT consists of social engineering attacks: manipulating people rather than systems.
Examples we use include:
Phishing: deceptive emails designed to obtain login credentials
Smishing: phishing via SMS
Vishing — voice phishing: phone-based attacks in which trust is built
This type of attack is highly effective because people are often the weakest link.
Step 4: Technical Vulnerabilities & Enumeration
Once access has been obtained or simulated the technical phase begins.
During this phase:
Vulnerabilities are identified and exploited
Systems are further explored
An important component is the enumeration of the Azure Cloud environment, where the following are examined:
User permissions
Privilege escalation opportunities
Access to sensitive data
In addition, a software inventory is created: an overview of all software and versions in use, in order to identify known vulnerabilities.
Step 5: Physical Security Tests
Cybersecurity does not stop at digital systems. We also perform a physical assessment.
This may include:
Attempts to enter office locations
Attempts to gain access to workstations
Manipulation of hardware
A well-known technique used here is the mystery guest: a tester who poses as a supplier, job applicant, or employee.
Step 6: Red Team Operation
All these techniques come together in a full Limina Red Team operation.
During a Red Team engagement:
Real attackers are simulated
The attack remains partially hidden from the organization
Detection and response mechanisms are tested
The goal is not only to gain access, but to simulate impact without causing real damage.
Why TLPT Is Valuable
TLPT answers crucial questions:
How quickly do we detect an attack?
How do our teams respond?
Where are the greatest risks?
By combining OSINT, social engineering, technical exploits, and physical testing, a complete picture of the organization’s security posture is created.
Conclusion
Limina Hacking Company uses Threat-Led Penetration Testing (TLPT) to test organizations in the same way real attackers would. From an assumed-breach mindset, the focus is not only on prevention, but especially on an organization’s detection and response capabilities. The central question is: how quickly can the organization become operational again, while keeping the damage limited?
Within this approach, various attack techniques are brought together into one realistic scenario. This includes phishing and social engineering, as well as Azure enumeration and physical assessments. Everything is combined into a coherent attack path that reflects reality as closely as possible.
What sets us apart is the use of our own Threat Intelligence platform. This enables scenario-based testing and provides insight into how the software and systems used within an organization are interconnected. The focus is therefore not only on individual vulnerabilities, but specifically on how combinations of systems and tools can together form a realistic attack path, exactly as a real attacker would approach it.
The goal is clear: not only to discover where vulnerabilities exist, but above all to gain insight into the organization’s resilience:
How quickly is an attack detected?
How effective is the response?
Where is the greatest impact risk?
TLPT therefore does not deliver a theoretical report, but a realistic and practical view of resilience.
Because ultimately, the question is not whether you will be attacked… but when.


