A red team engagement is goal-driven rather than checklist-driven. The objective is stated as an outcome — reach the customer database, send mail as the finance team, get a shell on a production host — and the route is left open, which is what makes the result meaningful. A scanner tells you which doors are unlocked; a red team tells you whether someone can get to the safe.
The trade-off is coverage. Because it follows the path of least resistance, it stops once it succeeds, and it will leave whole areas untouched. That is a feature when the question is "are we exposed" and a problem when the question is "is this component sound" — the second is an audit.
Related terms
Purple team
Running the attack and the defence as one exercise, so every fix is verified against the technique that found the hole.
Blue team
The defensive side: hardening the systems, watching them, and handling it when something happens.
Penetration test
An authorised, scoped attempt to break into a system, done to find out what an attacker could actually achieve.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
