Skip to main content
Hands-on lab
Offensive
Leader

AutoSec Red Team Lab

Attack the vehicle to defend it

Execute full-scope offensive engagements against real ECUs and vehicle networks — from reconnaissance and bus manipulation to exploitation and reporting.

Primary objectives

  1. Map the attack surface of a connected vehicle
  2. Exploit diagnostic and bus-level weaknesses
  3. Escalate from a wireless entry point to a safety-relevant domain
  4. Report findings in a format engineering can act on

Overview

What This Lab Is For

The Red Team Lab runs full-scope authorised engagements against real ECUs and vehicle networks. Participants map an attack surface, exploit diagnostic and bus-level weaknesses, chain a wireless foothold into a safety-relevant domain, and write it up in a form engineering can act on — because a finding nobody can action has no value.

Execute full-scope offensive engagements against real ECUs and vehicle networks — from reconnaissance and bus manipulation to exploitation and reporting.

Learning goals

  • Run a structured automotive penetration test end to end
  • Translate offensive findings into engineering remediation

Technology stack

  • CAN
  • Automotive Ethernet
  • UDS
  • Bluetooth
  • SDR

Tools used

Hardware, Software and Security Tooling

Production-representative equipment and the toolchains engineers use on the job — not simulators standing in for them.

  • Hardware

    Physical targets and instrumentation you will work on directly.

    • Multi-ECU vehicle network benchInterconnected ECUs across segregated bus domains
    • Software-defined radioWireless entry point analysis
    • CAN and Automotive Ethernet interfacesBus interface
    • Hardware analysis benchProbing, glitching and debug port access
    • CAN interface and bus tooling
    • Software-defined radio
  • Security tools

    Analysis, testing and cryptographic tooling applied to the targets.

    • Exploitation framework

Exercises

2 Assessed Exercises

Each exercise is assessed rather than demonstrated. Durations are indicative and vary with cohort experience.

  1. Diagnostic session takeover

    advanced

    Defeat weak seed-key authentication and reach a privileged UDS session.

    Duration
    4 hours
  2. Wireless entry to CAN pivot

    advanced

    Chain a wireless foothold into control of an in-vehicle network segment.

    Duration
    5 hours

Learning outcomes

What You Can Demonstrate Afterwards

An at-a-glance summary — each item is expanded in the sections above and below.

Skills acquired

2

Assessed competencies, listed in full under Overview above.

Capability levels
L5 · OffensiveL6 · Leader
Programs supported

3

Listed with their capability level in the next section.

Capability framework

Where This Lab Sits in the Framework

All six levels, and this lab’s relationship to each — including the ones it deliberately does not cover.

  1. Not covered

    Level 1 · Awareness

    Cybersecurity Awareness

    Covered by other labs in the estate

  2. Not covered

    Level 2 · Compliance

    Compliance Practitioner

    Covered by other labs in the estate

  3. Not covered

    Level 3 · Secure Developer

    Secure Developer

    Covered by other labs in the estate

  4. Not covered

    Level 4 · Validation

    Security Validation Specialist

    Covered by other labs in the estate

  5. Supported

    Level 5 · Offensive

    Develop automotive penetration testing, red team and exploit research capabilities.

  6. Supported

    Level 6 · Leader

    Lead CSMS transformation, security governance and enterprise capability programmes.

Common questions

AutoSec Red Team Lab FAQ

What engineers and their managers ask before booking lab time.

Is this legal to practise outside the lab?
Lab work is performed on AutoSec hardware under a defined authorisation scope. Testing a vehicle you do not own, or one connected to a manufacturer backend, raises legal and contractual questions that vary by jurisdiction. Establishing authorisation properly is taught as part of the engagement methodology.
Why does the lab expect defensive implementation experience?
Because knowing how a control was built is the fastest route to its weakness. Participants who have implemented secure boot and SecOC themselves consistently find implementation flaws that testers without that background miss.
How is the engagement assessed?
On the report as much as the findings. A practitioner panel reviews whether an engineering team could act on what you wrote: is the precondition stated, is it reproducible, and is the scope you did not test declared honestly.

Get Your Engineers Into the AutoSec Red Team Lab

Lab access is included with the programs above, and can be delivered onsite, remotely or as part of a corporate academy.