Skip to content

Red Team Exercise

Definition

A full-scope adversary simulation in which a team of testers uses the full range of attack techniques (technical, social engineering, and physical) over an extended period, typically without most internal staff knowing the exercise is underway. More comprehensive than a standard penetration test; used to test detection and response capability as well as preventive controls.

Scope
Full-spectrum adversary simulation
Methods
Technical, social engineering, physical
Awareness
Most internal staff unaware, unlike a scheduled pentest
Tests
Detection and response, not just prevention

Common questions

How does a red team exercise differ from a standard penetration test in what it actually measures?+

A penetration test typically checks whether specific vulnerabilities can be exploited within a defined scope and timeframe, while a red team exercise simulates a realistic adversary across multiple attack surfaces over an extended period, measuring whether the organisation's defenders can detect and respond, not just whether a hole exists.

Why does keeping most staff unaware of the exercise matter to its value?+

If defenders know an exercise is underway, they tend to watch more closely than they would during a real attack, so limiting awareness to a small trusted group preserves a realistic test of everyday detection and response capability.

Related terms

Attestation Letter
A formal document issued by a qualified assessor, such as a PCI Qualified Security Assessor (QSA) or an ISO 27001 certification body,...
Common Vulnerability Scoring System (CVSS)
A standardised scoring framework that rates vulnerability severity on a 0-10 scale using base metrics (attack vector, complexity, privileges required, user interaction,...
Remediation Verification Test
A targeted re-test conducted after an organisation has applied fixes to vulnerabilities identified in the original penetration test. The re-test confirms that...
Rules of Engagement (RoE)
The written contract or pre-test agreement that defines the authorised scope, permitted techniques, excluded systems, test window, escalation contacts, and emergency stop...
Scope Creep
The unintended expansion of a penetration test beyond the agreed boundaries, either because testers follow a vulnerability chain into an out-of-scope system...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.