Cybersecurity glossary

What is a Red Team?

Learn what a red team is, how red teaming differs from penetration testing, typical objectives and TTPs, and how organizations use findings to harden detection and response.

Vulnerability managementUpdated August 11, 2026
Also known asRed teamingAdversary simulation teamOffensive security red team

Definition

A red team is an authorized group that simulates real-world adversaries to test an organization’s people, processes, and technology—pursuing specific objectives such as domain dominance or data theft—while measuring whether defenses detect and stop the intrusion path.

Why red teams exist

Patching CVEs does not prove your SOC can catch a patient intruder. A red team stresses the whole control stack—identity, endpoint, network, people, and process—against goal-driven adversary behavior.

The scoreboard is not “number of vulns.” It is whether the organization prevented, detected, and responded before the mission succeeded.

Anatomy of a red team exercise

1

Define adversary and objectives

Pick a threat persona and crown-jewel goals: email access, SAP, cloud admin, OT pivot.

2

Establish rules of engagement

Legal scope, prohibited actions, deconfliction, and emergency stop procedures.

3

Gain and expand access

Phishing, perimeter exploits, or assumed breach—then escalate and move laterally.

4

Operate toward objectives

Stay within stealth goals while collecting evidence of control failures.

5

Debrief with defenders

Replay the path, detection misses, and prioritized purple-team improvements.

Red team vs neighboring functions

Red team

Objective-based adversary simulation across tech and process.

Penetration test

Scoped discovery and exploitation of weaknesses in defined targets.

Blue team

Detect, respond, and harden based on telemetry and playbooks.

Threat intel

Informs which adversary behaviors are worth emulating.

Designing exercises that change outcomes

Design choiceEffect
Blind vs announcedTests real SOC readiness vs collaborative learning speed
Assumed breachFocuses on internal detection when perimeter is already imperfect
ATT&CK-mapped reportingTurns anecdotes into detection engineering backlog
Executive tabletop add-onExposes decision-making gaps beyond tooling
Mandatory purple follow-upConverts findings into tuned alerts and controls
  • Write objectives that map to business harm, not vanity flags.
  • Deconflict with IT changes and real incident channels before kickoff.
  • Capture timelines: dwell time, first detection, containment.
  • Require ATT&CK technique IDs in the final report.
  • Fund detection engineering time after the exercise—not only the red contract.
  • Avoid production-destructive techniques unless explicitly approved.
  • Rotate any implanted persistence immediately after the engagement.
  • Measure improvement on the next exercise against the same techniques.

The practical takeaway

A red team simulates adversaries to stress detection and response, not to win a CVE scavenger hunt. Pair every exercise with blue-team coaching and tracked control upgrades.

If the only output is a dramatic “we owned everything” slide, you bought entertainment—not resilience.

Related security terms

Frequently asked questions

What is a red team in simple terms?

It is a friendly attacking squad hired or staffed to act like real adversaries so you can see whether your defenses notice and stop them.

How is red teaming different from a pentest?

Pentests find and prove vulnerabilities in a scope. Red teams pursue mission objectives stealthily and evaluate detection/response, not only patch lists.

Do red teams always start from the internet?

No. Assumed-breach scenarios often start with a laptop, cloud token, or phishing foothold to test internal controls.

Should the blue team know the exercise is running?

Sometimes yes (announced), sometimes no (blind). Hybrid designs keep executives aware while SOC analysts stay uninformed.

What frameworks guide red team TTPs?

MITRE ATT&CK and threat intelligence on relevant adversaries commonly shape scenarios.

Is continuous red teaming realistic?

Some mature orgs run ongoing adversary emulation; many start with periodic exercises plus purple-team follow-ups.

What does success look like for a red team?

Clear evidence of paths to objectives, honest detection gaps, and prioritized defensive improvements—not only “we got domain admin.”

References

Explore authoritative guidance and frameworks related to red team.

Explore every security definition

Return to the glossary to search by term, alias, starting letter, or security category.

Browse glossary