AutoSec Red Team Lab
Attack the vehicle to defend it
Execute full-scope offensive engagements against real ECUs and vehicle networks — from reconnaissance and bus manipulation to exploitation and reporting.
Primary objectives
- Map the attack surface of a connected vehicle
- Exploit diagnostic and bus-level weaknesses
- Escalate from a wireless entry point to a safety-relevant domain
- Report findings in a format engineering can act on
Overview
What This Lab Is For
The Red Team Lab runs full-scope authorised engagements against real ECUs and vehicle networks. Participants map an attack surface, exploit diagnostic and bus-level weaknesses, chain a wireless foothold into a safety-relevant domain, and write it up in a form engineering can act on — because a finding nobody can action has no value.
Execute full-scope offensive engagements against real ECUs and vehicle networks — from reconnaissance and bus manipulation to exploitation and reporting.
Learning goals
- Run a structured automotive penetration test end to end
- Translate offensive findings into engineering remediation
Technology stack
- CAN
- Automotive Ethernet
- UDS
- Bluetooth
- SDR
Tools used
Hardware, Software and Security Tooling
Production-representative equipment and the toolchains engineers use on the job — not simulators standing in for them.
Hardware
Physical targets and instrumentation you will work on directly.
- Multi-ECU vehicle network benchInterconnected ECUs across segregated bus domains
- Software-defined radioWireless entry point analysis
- CAN and Automotive Ethernet interfacesBus interface
- Hardware analysis benchProbing, glitching and debug port access
- CAN interface and bus tooling
- Software-defined radio
Security tools
Analysis, testing and cryptographic tooling applied to the targets.
- Exploitation framework
Exercises
2 Assessed Exercises
Each exercise is assessed rather than demonstrated. Durations are indicative and vary with cohort experience.
Diagnostic session takeover
advancedDefeat weak seed-key authentication and reach a privileged UDS session.
- Duration
- 4 hours
Wireless entry to CAN pivot
advancedChain a wireless foothold into control of an in-vehicle network segment.
- Duration
- 5 hours
Learning outcomes
What You Can Demonstrate Afterwards
An at-a-glance summary — each item is expanded in the sections above and below.
- Skills acquired
2
Assessed competencies, listed in full under Overview above.
- Capability levels
- L5 · OffensiveL6 · Leader
- Programs supported
3
Listed with their capability level in the next section.
Capability framework
Where This Lab Sits in the Framework
All six levels, and this lab’s relationship to each — including the ones it deliberately does not cover.
- Not covered
Level 1 · Awareness
Cybersecurity Awareness
Covered by other labs in the estate
- Not covered
Level 2 · Compliance
Compliance Practitioner
Covered by other labs in the estate
- Not covered
Level 3 · Secure Developer
Secure Developer
Covered by other labs in the estate
- Not covered
Level 4 · Validation
Security Validation Specialist
Covered by other labs in the estate
- Supported
Level 5 · Offensive
Develop automotive penetration testing, red team and exploit research capabilities.
- Supported
Level 6 · Leader
Lead CSMS transformation, security governance and enterprise capability programmes.
Common questions
AutoSec Red Team Lab FAQ
What engineers and their managers ask before booking lab time.
- Is this legal to practise outside the lab?
- Lab work is performed on AutoSec hardware under a defined authorisation scope. Testing a vehicle you do not own, or one connected to a manufacturer backend, raises legal and contractual questions that vary by jurisdiction. Establishing authorisation properly is taught as part of the engagement methodology.
- Why does the lab expect defensive implementation experience?
- Because knowing how a control was built is the fastest route to its weakness. Participants who have implemented secure boot and SecOC themselves consistently find implementation flaws that testers without that background miss.
- How is the engagement assessed?
- On the report as much as the findings. A practitioner panel reviews whether an engineering team could act on what you wrote: is the precondition stated, is it reproducible, and is the scope you did not test declared honestly.
Get Your Engineers Into the AutoSec Red Team Lab
Lab access is included with the programs above, and can be delivered onsite, remotely or as part of a corporate academy.