Rather than checking one vulnerability in isolation, a red-team engagement may chain technical, identity, social-engineering, or physical actions to pursue a defined objective and observe prevention, detection, investigation, and response.
The engagement must operate under written rules. Objectives, targets, exclusions, permitted techniques, test windows, safety controls, evidence handling, deconfliction, escalation, cleanup, and stop conditions should be agreed before activity begins. Any testing of people, suppliers, production systems, or physical facilities requires explicit authority appropriate to that scope.
Key points
Threat-informed designChoose objectives and behaviors from relevant threat intelligence and realistic attack paths.
Operational focusMeasure whether defenders can observe, understand, contain, and learn from the activity — not simply whether the red team gains access.
Control structureA designated authority or white team can supervise the exercise, manage safety, and resolve conflicts without directing every operator decision.
Useful outputsEvidence of reached objectives, control and telemetry gaps, response observations, risk context, and prioritized recommendations.
Important limitationA red-team result samples particular paths under particular conditions. Success does not prove that every control failed, and failure to reach an objective does not prove the environment secure.