← See all resources
Red Team
🔴Red/Blue/Purple

Red Team

Functions and methodologies used by Red Teams to simulate real-world attacks.

Tags

Red TeamPentestingOffensive SecurityAdversary Simulation
Download infographic

File: SecPro-red-team.gif

What is a Red Team?

It is the team that simulates a real adversary against an organization, with a specific objective and without warning the defenders. Unlike a penetration test, its priority is not finding the most vulnerabilities but reaching the objective while avoiding detection, in order to measure real detection and response capability.

Red Team, Blue Team and Purple Team

The Red Team attacks, the Blue Team defends and detects, and the Purple Team is the exercise where both work together sharing information in real time. The point of a Purple Team is not to win, but to turn every offensive technique into a verified detection rule.

How an exercise is structured

Objectives and rules of engagement are defined in writing, the reconnaissance, initial access, persistence, lateral movement and actions-on-objective phases are executed, and it closes with a joint session contrasting the attack timeline against what the defenders actually detected. That contrast is the real deliverable.

More from Red/Blue/Purple

Explore more infographics

View full catalog

Need help with your cybersecurity? 💬