Red Team Operations
Red team operations are authorized security assessments that emulate realistic adversary behavior to test how well an organization detects, responds to, and learns from an intrusion.
itOffensive security and application security | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic: Red Team Operations
A red team operation is a permitted attempt to reach an agreed objective while watching the defense respond. It is not a contest to collect the most exotic tool output, although tools are very capable of producing souvenirs when left unsupervised. The useful question is whether people, processes, and technology work together when an adversary-shaped problem arrives.
Before this kind of operation, a vulnerability scan can identify possible weaknesses and a penetration test can validate selected ones. Both remain useful. The red-team-sized complication is the objective: an observable, business-relevant condition that tells the team when enough has happened. Without it, activity expands to fill the available curiosity, which is a very large container.
The first anchor is authorization. Rules of engagement define scope, timing, permitted and prohibited actions, contacts, evidence handling, and stop conditions. Technical ability does not amend that document. The second is an adversary model: relevant behavior expressed through MITRE ATT and CK tactics, which explain why an adversary acts, and techniques, which describe how. ATT and CK is a vocabulary, not a scavenger hunt.
The surprising part is that reaching the objective is not the whole result. The operation also asks what defenders saw, how they investigated, where the response worked, and what evidence supports each conclusion. A blocked action can be a successful control, not an embarrassing interruption to the plot.
Read the Intro for the operational cycle and the roles that keep it controlled. Use the Slides when the relationships between objective, authority, evidence, and feedback need to fit on one mental page. Keep the Cheatsheet nearby when designing rules, evidence records, findings, and safety decisions. The Field Notes covers the operational judgments that tend to arrive late, usually carrying a bill.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf
Supports
- Planning, execution, analysis, and reporting for technical security assessments
- Assessment plans, rules of engagement, logistics, data handling, and incident response
- Penetration testing phases, evidence collection, mitigation analysis, and retesting
- The limits of assessment results and the need to interpret findings in context
- https://csrc.nist.gov/pubs/sp/800/115/final
Supports
- Official publication identity, scope, date, authors, and current download
- Security testing as a process for finding vulnerabilities and verifying requirements
- https://www.cisa.gov/sites/default/files/publications/VM_Assessments_Fact_Sheet_RTA_508C.pdf
Supports
- Red team assessment as a comprehensive evaluation of an information technology environment
- Threat simulation and measurable events used to evaluate people, processes, and technology
- Adversary emulation tied to business-level risk and defensive response
- https://attack.mitre.org/tactics/
Supports
- Tactics as the reason an adversary performs an action
- Enterprise tactic names and their role in describing adversary goals
- https://attack.mitre.org/techniques/enterprise/
Supports
- Techniques as ways adversaries achieve tactical goals
- Enterprise technique and sub-technique knowledge for behavior mapping
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-059a
Supports
- A red team assessment that tested detection and response capabilities
- Mapping observed activity to MITRE ATT&CK tactics and techniques
- Turning assessment observations into monitoring, hardening, and control-validation recommendations
- The value of regular assessments and testing defensive processes
- https://github.com/sindresorhus/awesome
Supports
- Awesome Hacking as a curated list in the security section
- https://github.com/carpedm20/awesome-hacking
Supports
- Discovery of Nmap, Metasploit, Wireshark, and OWASP ZAP as relevant security tools
- https://nmap.org/book/man.html
Supports
- Nmap host discovery, port scanning, service detection, scripting, timing, and output
- Nmap as a network exploration and security auditing tool
- https://docs.rapid7.com/metasploit/
Supports
- Metasploit workflow for target data, vulnerability validation, controlled exploitation, evidence, cleanup, and reporting
- https://www.wireshark.org/docs/wsug_html_chunked/
Supports
- Wireshark packet capture, display filters, protocol analysis, and statistics
- https://www.zaproxy.org/docs/
Supports
- ZAP desktop, automation, API, and web application testing documentation
- https://www.cisa.gov/sites/default/files/2024-11/aa24-326a-enhancing-cyber-resilience-insights-from-cisa-red-team-assessment_0.pdf
Supports
- Red team assessment findings on the limits of endpoint-only detection coverage
- Network segmentation, network-layer controls, and unmanaged hosts as contributors to persistent access
- https://www.cobaltstrike.com/product/pricing-plans
Supports
- Cobalt Strike licensing, collaborative red team use, post-exploitation simulation, reporting, and configurable command-and-control
- https://docs.metasploit.com/
Supports
- Metasploit Framework as an open-source offering and Metasploit Pro as a commercial offering
- https://www.coresecurity.com/products/core-impact
Supports
- Core Impact guided penetration testing, exploitation validation, and integration with Cobalt Strike and Metasploit
- https://www.attackiq.com/products/flex/
Supports
- AttackIQ Flex packaged breach-and-attack simulations, detection validation, and free and paid usage options
- https://www.safebreach.com/breach-and-attack-simulation
Supports
- SafeBreach breach-and-attack simulation for continuous validation of security controls and ATT&CK-informed scenarios
- https://plextrac.com/
Supports
- PlexTrac evidence capture, attack-path reporting, remediation tracking, and retesting workflows
