# Red team

> The offensive side: people whose job is to get in, using whatever an actual attacker would use.

A red team engagement is goal-driven rather than checklist-driven. The objective is stated as an outcome — reach the customer database, send mail as the finance team, get a shell on a production host — and the route is left open, which is what makes the result meaningful. A scanner tells you which doors are unlocked; a red team tells you whether someone can get to the safe.

The trade-off is coverage. Because it follows the path of least resistance, it stops once it succeeds, and it will leave whole areas untouched. That is a feature when the question is "are we exposed" and a problem when the question is "is this component sound" — the second is an audit.

## Related terms

- https://dfieldsolutions.com/en/glossary/purple-team.md
- https://dfieldsolutions.com/en/glossary/blue-team.md
- https://dfieldsolutions.com/en/glossary/penetration-test.md

---

Source: https://dfieldsolutions.com/en/glossary/red-team
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
