Definition · External Attack Surface Management

What is Red Team?

A red team engagement asks a different question from a penetration test. Rather than “what vulnerabilities exist in this scope”, it asks “can an adversary with these objectives achieve them, and would we notice”. Engagements run for weeks or months, pursue specific goals such as reaching a payment system or exfiltrating a defined data set, and deliberately test the blue team’s ability to detect and respond.

What makes it different from a penetration test

  • Objective-driven rather than coverage-driven — one path to the goal is a success, and unexplored areas are not a gap
  • Stealth matters — avoiding detection is part of the exercise, so activity is slow and deliberate
  • Broad initial access options, typically including phishing, external exploitation, and sometimes physical or supply chain routes
  • Few people are informed, so that the response is genuine rather than rehearsed
  • Adversary emulation, often modelling the tactics of a specific threat group relevant to the organisation

Related formats include purple teaming, where attackers and defenders work together to improve detections in real time, and tabletop exercises that test decision-making without touching production.

Where the engagement starts

Red teams begin where real adversaries begin: outside, with public information. OSINT on staff and suppliers, certificate transparency logs and passive DNS for hostnames, then examination of whatever is exposed. Findings from that phase are usually the least surprising and most actionable part of the report, because they describe things the organisation could have found itself.

When it is worth doing

Red teaming tests a detection and response capability, so it is wasted on an organisation that does not yet have one — unknown internet-facing assets and unpatched edge devices are cheaper to find by other means. The usual sequencing is to establish inventory, vulnerability management, and monitoring first, then use a red team to find out whether that machinery actually works.

Red teaming extends penetration testing into detection and response, emulates the behaviour of a real threat actor, and begins with the same reconnaissance that external attack surface management performs continuously.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.