Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is a Red Team?

DefinitionA Red Team is a group authorized to emulate a real adversary against the organization, attacking people, processes and technology, to show where an intruder would get in and test whether the defense detects and contains the attack.

How it works

The term comes from military exercises. The NIST glossary, based on CNSSI 4009, defines a Red Team as a group authorized to emulate a potential adversary's attack capabilities. The goal is not to "win" but to demonstrate the impact of a successful attack and show defenders what works and what does not.

A Red Team exercise usually has:

  • A business objective: for example, reaching the payment system or exfiltrating a sensitive database.
  • A broad scope: people, processes and technology, including phishing and social engineering when authorized.
  • Covert operation: few people know about the exercise, so the Blue Team's real reaction can be measured.
  • A longer duration than a pentest, with techniques mapped to references such as MITRE ATT&CK.

Red Team vs pentest

Both use offensive techniques, but they answer different questions. A pentest asks which exploitable flaws exist within a defined scope and aims for coverage. A Red Team asks whether an adversary with a given profile could reach an objective without being detected and contained. That is why a Red Team also evaluates detection and response, not just vulnerabilities.

When it makes sense

If the organization does not yet know its serious flaws, the first step is a pentest. A Red Team makes more sense when vulnerabilities are already fixed regularly and there is a structured defense, such as a SOC, whose effectiveness needs to be measured. The findings feed the Blue Team and, in a collaborative format, become Purple Team exercises.

At Network Secure, the Red Team works together with the Blue, Purple and White teams.

Frequently asked questions

What is the difference between a Red Team and a Blue Team?

The Red Team works on offense: it simulates what an intruder would do to find gaps. The Blue Team works on defense: it monitors the environment, detects and responds to incidents. One shows where the defense fails; the other closes those gaps.

Does a Red Team replace a pentest?

No. A pentest finds and proves flaws within a defined scope; a Red Team tests whether the defense detects and contains a realistic attack. The pentest usually comes first.

Go deeper