Red team
In offensive security, a red team is a group that plays the adversary in an objective-driven exercise, testing not just what is vulnerable but whether an organisation detects and responds to a real intrusion. The name comes from military exercises where a red force plays the enemy against a defending blue force.
How it works
A red team exercise starts from an objective (reach a specific system, obtain particular data, demonstrate a business impact) rather than from a list of systems to scan. The red team works towards that goal the way a real adversary would, choosing its own path and staying quiet, while the defenders are usually not told the exercise is happening so their detection and response are measured honestly. Several roles surround it. The blue team is the defence being tested. A small control group, sometimes called the white cell, knows the exercise is running and keeps it safe and deconflicted. A purple team is not a separate group but a collaborative mode in which red and blue work together to turn each finding into a detection improvement.
What goes wrong
The value of a red team is easy to mistake for the value of a penetration test, and the two answer different questions. A penetration test asks what is exploitable across a defined scope, aiming for breadth of coverage. A red team asks a narrower and harder question: if a capable adversary were pursuing this objective, would we see them, and could we stop them? The failures it surfaces are rarely a single vulnerability. They are the detection that existed but never alerted, the alert that fired into an unworked queue, and the response playbook that assumed a step the attacker skipped, which is the ground an adversary emulation explores in the most realistic way.
Where this shows up in an audit
A red team report is written as an intrusion narrative: the objective, the path taken towards it, what the defenders detected, and how they responded, with timings. The finding is the detection or response gap, not the individual technique, and a follow-up replay with the blue team turns each gap into a concrete improvement. Where a regulator requires it, this takes the supervised form of a threat-led penetration test. This is how we run an objective-based engagement.