# What is a Red Team?

> A red team is an authorized group that emulates the behavior of a plausible adversary to test how well an organization protects important missions, business processes, assets, and data.

- Canonical URL: https://yellowcube.eu/glossary/red-team/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Rather than checking one vulnerability in isolation, a red-team engagement may chain technical, identity, social-engineering, or physical actions to pursue a defined objective and observe prevention, detection, investigation, and response.

The engagement must operate under written rules. Objectives, targets, exclusions, permitted techniques, test windows, safety controls, evidence handling, deconfliction, escalation, cleanup, and stop conditions should be agreed before activity begins. Any testing of people, suppliers, production systems, or physical facilities requires explicit authority appropriate to that scope.

### Key points

- **Threat-informed design:** Choose objectives and behaviors from relevant threat intelligence and realistic attack paths.
- **Operational focus:** Measure whether defenders can observe, understand, contain, and learn from the activity — not simply whether the red team gains access.
- **Control structure:** A designated authority or white team can supervise the exercise, manage safety, and resolve conflicts without directing every operator decision.
- **Useful outputs:** Evidence of reached objectives, control and telemetry gaps, response observations, risk context, and prioritized recommendations.
- **Important limitation:** A red-team result samples particular paths under particular conditions. Success does not prove that every control failed, and failure to reach an objective does not prove the environment secure.

### Related terms

[Purple team](<https://yellowcube.eu/glossary/purple-team/>) · [Penetration testing](<https://yellowcube.eu/glossary/penetration-testing/>) · [Adversary emulation](<https://yellowcube.eu/glossary/adversary-emulation/>) · [Tactics, techniques, and procedures (TTPs)](<https://yellowcube.eu/glossary/tactics-techniques-and-procedures/>) · [Breach and attack simulation (BAS)](<https://yellowcube.eu/glossary/breach-and-attack-simulation/>) · [Hacking and ethical hacking](<https://yellowcube.eu/glossary/hacking-and-ethical-hacking/>) · [Blue team](<https://yellowcube.eu/glossary/blue-team/>)

### Sources

[NIST glossary: Red Team Exercise](https://csrc.nist.gov/glossary/term/red_team_exercise) · [NIST SP 800-53 Rev. 5: Security and Privacy Controls](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) · [MITRE ATT&CK: Adversary Emulation Plans](https://attack.mitre.org/resources/adversary-emulation-plans/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

