What is Red Teaming?
“Red Teaming” is a step above traditional penetration (pen) testing by simulating real-world attacks by replicating the Techniques, Tactics and Procedures (TTPs) of real-world adversaries.
A red teaming engagement differs from traditional pen testing as it is performed from as close to a zero knowledge perspective as possible, meaning the organization as a whole is not notified ahead of time, nor is the red team supplied with any pre-requisite information up-front.
The role of the red team (which is often independent from the organization, but can also be an internal team) is to simulate an attack on the target organisation, whereas the blue team (typically an internal security team, but can be outsourced) must defend the organization from infiltration against the simulated attack.
The objectives of a red team test is to reflect a real-world attack scenario focusing on revealing potential threats to the critical data from the wider business rather than being confined to a specific subset of assets. It is a deep dive into the risks and vulnerabilities of the business and is also designed to exercise internal teams and their procedures for such an event.