Red Team Exercise
Definition
A full-scope adversary simulation in which a team of testers uses the full range of attack techniques (technical, social engineering, and physical) over an extended period, typically without most internal staff knowing the exercise is underway. More comprehensive than a standard penetration test; used to test detection and response capability as well as preventive controls.
- Scope
- Full-spectrum adversary simulation
- Methods
- Technical, social engineering, physical
- Awareness
- Most internal staff unaware, unlike a scheduled pentest
- Tests
- Detection and response, not just prevention
Common questions
How does a red team exercise differ from a standard penetration test in what it actually measures?+
A penetration test typically checks whether specific vulnerabilities can be exploited within a defined scope and timeframe, while a red team exercise simulates a realistic adversary across multiple attack surfaces over an extended period, measuring whether the organisation's defenders can detect and respond, not just whether a hole exists.
Why does keeping most staff unaware of the exercise matter to its value?+
If defenders know an exercise is underway, they tend to watch more closely than they would during a real attack, so limiting awareness to a small trusted group preserves a realistic test of everyday detection and response capability.
Related terms
- Attestation Letter
- A formal document issued by a qualified assessor, such as a PCI Qualified Security Assessor (QSA) or an ISO 27001 certification body,...
- Common Vulnerability Scoring System (CVSS)
- A standardised scoring framework that rates vulnerability severity on a 0-10 scale using base metrics (attack vector, complexity, privileges required, user interaction,...
- Remediation Verification Test
- A targeted re-test conducted after an organisation has applied fixes to vulnerabilities identified in the original penetration test. The re-test confirms that...
- Rules of Engagement (RoE)
- The written contract or pre-test agreement that defines the authorised scope, permitted techniques, excluded systems, test window, escalation contacts, and emergency stop...
- Scope Creep
- The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...