Cybersecurity glossary
What is a Red Team?
Learn what a red team is, how red teaming differs from penetration testing, typical objectives and TTPs, and how organizations use findings to harden detection and response.
Definition
A red team is an authorized group that simulates real-world adversaries to test an organization’s people, processes, and technology—pursuing specific objectives such as domain dominance or data theft—while measuring whether defenses detect and stop the intrusion path.
Why red teams exist
Patching CVEs does not prove your SOC can catch a patient intruder. A red team stresses the whole control stack—identity, endpoint, network, people, and process—against goal-driven adversary behavior.
The scoreboard is not “number of vulns.” It is whether the organization prevented, detected, and responded before the mission succeeded.
Anatomy of a red team exercise
Define adversary and objectives
Pick a threat persona and crown-jewel goals: email access, SAP, cloud admin, OT pivot.
Establish rules of engagement
Legal scope, prohibited actions, deconfliction, and emergency stop procedures.
Gain and expand access
Phishing, perimeter exploits, or assumed breach—then escalate and move laterally.
Operate toward objectives
Stay within stealth goals while collecting evidence of control failures.
Debrief with defenders
Replay the path, detection misses, and prioritized purple-team improvements.
Red team vs neighboring functions
Red team
Objective-based adversary simulation across tech and process.
Penetration test
Scoped discovery and exploitation of weaknesses in defined targets.
Blue team
Detect, respond, and harden based on telemetry and playbooks.
Threat intel
Informs which adversary behaviors are worth emulating.
Designing exercises that change outcomes
| Design choice | Effect |
|---|---|
| Blind vs announced | Tests real SOC readiness vs collaborative learning speed |
| Assumed breach | Focuses on internal detection when perimeter is already imperfect |
| ATT&CK-mapped reporting | Turns anecdotes into detection engineering backlog |
| Executive tabletop add-on | Exposes decision-making gaps beyond tooling |
| Mandatory purple follow-up | Converts findings into tuned alerts and controls |
- Write objectives that map to business harm, not vanity flags.
- Deconflict with IT changes and real incident channels before kickoff.
- Capture timelines: dwell time, first detection, containment.
- Require ATT&CK technique IDs in the final report.
- Fund detection engineering time after the exercise—not only the red contract.
- Avoid production-destructive techniques unless explicitly approved.
- Rotate any implanted persistence immediately after the engagement.
- Measure improvement on the next exercise against the same techniques.
The practical takeaway
A red team simulates adversaries to stress detection and response, not to win a CVE scavenger hunt. Pair every exercise with blue-team coaching and tracked control upgrades.
If the only output is a dramatic “we owned everything” slide, you bought entertainment—not resilience.
Related security terms
Blue Team
Defenders who detect and respond to red team activity.
Purple Team
Collaborative model that joins red and blue learning loops.
Penetration Testing
Scoped vulnerability exploitation that is usually narrower than red teaming.
Attack Path
Sequences of steps red teams chain toward objectives.
Exploit Chain
Technical combinations often used inside red team campaigns.
Frequently asked questions
What is a red team in simple terms?
It is a friendly attacking squad hired or staffed to act like real adversaries so you can see whether your defenses notice and stop them.
How is red teaming different from a pentest?
Pentests find and prove vulnerabilities in a scope. Red teams pursue mission objectives stealthily and evaluate detection/response, not only patch lists.
Do red teams always start from the internet?
No. Assumed-breach scenarios often start with a laptop, cloud token, or phishing foothold to test internal controls.
Should the blue team know the exercise is running?
Sometimes yes (announced), sometimes no (blind). Hybrid designs keep executives aware while SOC analysts stay uninformed.
What frameworks guide red team TTPs?
MITRE ATT&CK and threat intelligence on relevant adversaries commonly shape scenarios.
Is continuous red teaming realistic?
Some mature orgs run ongoing adversary emulation; many start with periodic exercises plus purple-team follow-ups.
What does success look like for a red team?
Clear evidence of paths to objectives, honest detection gaps, and prioritized defensive improvements—not only “we got domain admin.”
References
Explore authoritative guidance and frameworks related to red team.
Explore every security definition
Return to the glossary to search by term, alias, starting letter, or security category.