The Phases of a Red Team Engagement
Reconnaissance, initial access, foothold, movement, objective, debrief. What happens in each and roughly what share of the weeks it takes — including the phase that produces no findings at all.
A red team runs in phases that look superficially like a penetration test and are weighted completely differently. Most of the calendar goes on the two phases that produce no findings.
1. Reconnaissance — often a third of the engagement
Almost none of it touches you. Staff on professional networks and what their job titles reveal about your stack. Job advertisements, which are the most generous public disclosure most organisations make. Code and credentials in public repositories. Document metadata. Address ranges, subdomains and certificate transparency logs. For physical scope, the building, its entrances, and when people arrive.
This phase regularly produces findings you would rather not have, before anyone has attempted anything.
2. Initial access
Getting a foothold. Teams normally rank several routes by likely success and lowest noise, then try them in order — phishing a person, exploiting something exposed, walking into a building, a supplier, or a credential found in phase one.
Failure here is normal and is not the end. An adversary who fails on Tuesday tries something else on Friday, and a compressed engagement that cannot afford Friday is not simulating anything. See what a red team engagement costs for why duration is the line item that matters most.
3. Establishing the foothold
Making access reliable and quiet: persistence that survives a reboot, communications that look like ordinary traffic, and enough understanding of the environment to move without tripping something.
This is where most exercises get caught, and being caught is a result rather than a failure — it is the answer to the question you paid to ask.
4. Movement toward the objective
Credentials, lateral movement, privilege escalation, and reaching the systems that matter. In a mature environment this is slow and deliberate. In most environments it is faster than anyone expects, usually because of a reused local administrator password or an over-privileged service account.
5. Reaching the objective
Demonstrating it, not exploiting it. Enough evidence to prove the outcome and no more — a row rather than the table, one transaction rather than many.
6. The debrief
The red team and your defenders walking the timeline together. Frequently the most valuable hours of the whole engagement and one of the cheapest line items, which is why it is worth asking for explicitly.
How the weeks divide
As a rough shape: reconnaissance around a third, initial access a variable slice that can consume weeks or an afternoon, movement and objective around a third, reporting and debrief the remainder.
The useful implication is the same as for penetration testing but starker. A large share of a red team produces nothing you could put in a findings table — it is spent watching, waiting and writing. A proposal priced as though every day is an attacking day has either omitted the rest or intends to skip it, and the phase it skips is reconnaissance, which is where the realism lives.
What lands on your desk at the end is in what a red team report contains.
Continue reading
All articles →Choosing a Red Team Provider
Every firm answers yes to every capability question. Six that are harder to answer generically, and what a real answer sounds like.
Red Teaming and SEBI CSCRF
What the Cyber Security and Cyber Resilience Framework asks of regulated entities, where adversarial testing sits within it, and how the tiering decides how much applies to you.
Social Engineering Assessments and the Consent They Require
Testing people is not testing systems. What can be assessed, what must be agreed first, and why individual results should almost never leave the room.