SOC

Red Team

A Red Team simulates a realistic attack to test an organisation's detection and response capabilities under real-world conditions.

A Red Team simulates a realistic attack against an organisation, as real attackers would conduct it. The goal is to test the overall detection and response, not to simply list individual vulnerabilities.

How it works

The Red Team receives an objective, such as accessing payment data. To achieve this, it uses phishing, vulnerabilities, physical access or stolen credentials. It operates covertly over several weeks, unlike a penetration test. Only a small group within the organisation is aware of the exercise. A final report details the attack path, detected and missed steps, and recommendations.

For example, a Red Team gains access to a laptop via a phishing email. It then moves to the accounting servers using a poorly secured service account. The SOC detects this move to the server only after two days. The subsequent analysis shows which detection rule was missing.

What to look out for

  • Define objectives and boundaries in writing, including prohibited actions.
  • Appoint a small, informed group that can stop the test if necessary.
  • Only conduct a Red Team exercise if basic security measures and monitoring are in place.
  • Plan sufficient time to implement the findings.

Switzerland and regulation

For larger EU financial institutions, DORA requires threat-led penetration testing. This is equivalent to a Red Team exercise. In Switzerland, FINMA (Swiss Financial Market Supervisory Authority) expects regular cyber resilience tests. It does not, however, prescribe a specific format.

How it differs from other tests

A pentest seeks as many vulnerabilities as possible within a fixed scope. A Red Team tests if a realistic attack is detected and stopped. In a Purple Team exercise, attackers and defenders work together openly.

Typical mistakes

A common mistake is when a Red Team report is produced but not acted upon. Another error is defining a scope that is too narrow. This excludes realistic attack paths.

How we implement it

We offer Red Team engagements as a dedicated service, described on our 'Red Team Assessment' page. Their findings are incorporated into our SOC's detection and response processes.

How ANOMAL implements this