The Phases of a Red Team Engagement
Reconnaissance, initial access, foothold, movement, objective, debrief. What happens in each, roughly what share of the weeks it takes, and which phase produces no findings at all.
A red team runs in phases that look like a penetration test but are weighted completely differently. Most of the calendar goes on the two phases that produce no findings.
The phases are also not a queue. Teams loop: reconnaissance restarts the moment they are inside, and a burned route sends them back to initial access.
Phase 0: before the clock starts
Three things have to exist before day one, and none of them is testing.
The signed authorisation and the trusted agents. Scope, dates, permitted techniques, stop conditions, and the people who can halt the exercise. It is set out in scoping a red team, and none of it can be agreed while a team is already running.
The adversary being imitated. A red team modelling nobody in particular defaults to whatever its operators find comfortable. Choose a threat actor profile that plausibly targets your sector and map its behaviours to MITRE ATT&CK, so the report has something to be checked against.
Infrastructure. Domains, certificates, mail paths and callback channels that look ordinary to your filters. This carries lead time. Anything bought on the Friday before is something your mail gateway has never seen, and when a start date slips, that is usually why.
1. Reconnaissance: often a third of the engagement
Almost none of it touches you. Staff on professional networks and what their job titles reveal about your stack. Job advertisements, which are the most generous public disclosure most organisations make. Code and credentials in public repositories. Document metadata. Address ranges, subdomains and certificate transparency logs. For physical scope, the building, its entrances, and when people arrive.
This phase regularly produces findings you would rather not have, before anyone has attempted anything.
Two limits on it. Reconnaissance maps what an outsider can see and stops there, so do not read it as an inventory of your estate. And the personnel surface is wider than your payroll: in most Indian enterprises a large share of the people holding credentials are contractor and partner staff who list your organisation publicly, and phase one treats them as yours because an attacker would.
2. Initial access
Getting a foothold. Teams normally rank several routes by likely success and lowest noise, then try them in order: phishing a person, exploiting something exposed, walking into a building, a supplier, or a credential found in phase one.
Failure here is normal. An adversary who fails on Tuesday tries something else on Friday, and a compressed engagement that cannot afford Friday is not simulating anything. See what a red team engagement costs for why duration is the line item that matters most.
That raises the decision most engagements face at least once: what happens when nothing works. Three answers, and the choice is yours.
- Give it more calendar. Honest, and it eats the later phases that produce the report.
- Widen the permitted techniques. Physical entry or telephone pretexting added to a scope that began as external only. The authorisation has to be amended in writing.
- Start from an assumed breach. You hand over a standard workstation and user account, and the exercise begins at phase three. Still real, and it now says nothing about your perimeter or your people, only about what follows a compromise.
Agree which one, and at what point, before the engagement starts.
3. Establishing the foothold
Making access reliable and quiet: persistence that survives a reboot, communications that look like ordinary traffic, and enough understanding of the environment to move without tripping something.
This is where most exercises get caught. Being caught is the answer to the question you paid to ask.
It also has a procedure, and the proposal should name it. A detected route usually means the access is gone and the infrastructure behind it is burned. The trusted agents then choose: let your team run the response as a live test, or declare the exercise, stand them down and re-enter by another route. Settling that at midnight, unrehearsed, is how an exercise becomes an incident.
4. Movement toward the objective
Credentials, lateral movement, privilege escalation, and reaching the systems that matter. In a mature environment this is slow and deliberate. In most environments it is faster than anyone expects, usually because of a reused local administrator password or an over-privileged service account. The mechanics, and the internal weaknesses that make it quick almost everywhere, are in after the foothold.
5. Reaching the objective
Demonstrating it, not exploiting it. Enough evidence to prove the outcome and no more: a row instead of the table, one transaction instead of many.
Which leaves evidence handling, asked about too late. Proving the customer database was reached means the team held some of your customer data, even if it was one row. Settle in the authorisation where it sits, who can open it, how long it is kept after delivery, how it is destroyed and what confirms the destruction. Screenshots included: a redacted image still proves the access.
6. The debrief
The red team and your defenders walking the timeline together. Frequently the most valuable hours of the whole engagement and one of the cheapest line items. Ask for it explicitly.
One practical obstacle. If your monitoring is operated by an outside provider, the people who most need to be in that room work for somebody else, and their attendance is contractual, arranged before the engagement begins. What to do with the timeline afterwards is in what the exercise tells you about detection.
How the weeks divide
As a rough shape: reconnaissance around a third, initial access a variable slice that can consume weeks or an afternoon, movement and objective around a third, reporting and debrief the remainder.
| Phase | What your side does | What it produces |
|---|---|---|
| 0. Preparation | Sign the authorisation, name trusted agents | Scope, rules, a deconfliction route |
| 1. Reconnaissance | Nothing, and you will not notice it | Exposure findings, a ranked route list |
| 2. Initial access | Nothing, unless a stall forces the decision above | A foothold, or a documented failure |
| 3. Foothold | Possibly detect and respond | The first real detection evidence |
| 4. Movement | Possibly detect and respond | Most of the detection timeline |
| 5. Objective | Agree handling and destruction of evidence | Proof, held to a minimum |
| 6. Debrief | Get defenders and providers in the room | Narrative, timeline, owned actions |
The useful implication is the same as for penetration testing but starker. A large share of a red team produces nothing you could put in a findings table. It is spent watching, waiting and writing. A proposal priced as though every day is an attacking day has either omitted the rest or intends to skip it, and the phase it skips is reconnaissance, which is where the realism lives.
What the phases prove outside the security team
Phase 0 is where the firm's credentials are established. Under the Reserve Bank's consolidated Directions of 31 July 2026, ¶156 requires the entity to consider the qualification, professional expertise, credentials and competency of the testing firm and of its assigned personnel, at selection, appointment, engagement and at every renewal. That record is built before work starts. Security Brigade has held CERT-In empanelment continuously since 2008, and every Indian regulator that accepts an audit report accepts it from a CERT-In empanelled auditor.
Red teaming itself sits in the permissive register: ¶162 says red teams may be used, and the equivalents for small finance banks, payments banks and credit information companies use the same word. So the exercise has to argue for itself, and what a board or a supervisor reads is the narrative and the detection timeline out of phase six. Detail in red teaming under the RBI Directions 2026.
When the phase shape says buy something else
Phase two has no fixed duration. If you need a dated deliverable for a committee meeting, that uncertainty is the problem, and a scheduled penetration test gives you the date.
The same applies when the calendar you can offer is short. Compression means cutting reconnaissance, the one phase with no visible output to defend, and that removes the realism you are paying for.
And if nothing downstream is funded, the exercise stops at the debrief. Where the money for collection, rule and response work does not exist yet, spend it on a purple team first: same techniques, your defenders watching, cheaper to act on.
What lands on your desk at the end is in what a red team report contains.
About the author
Siddarth G
Practice Director — Cybersecurity
Leads Security Brigade's offensive security practice with deep expertise in vulnerability research, penetration testing, and red team operations. Ranked Top 80 globally on Bugcrowd.
Continue reading
All articles →Choosing a Red Team Provider
Every firm answers yes to every capability question. Six questions where the generic yes runs out, and what a real answer sounds like.
Red Teaming and SEBI CSCRF
What the Cyber Security and Cyber Resilience Framework asks of regulated entities, where adversarial testing sits within it, and how the tiering decides how much applies to you.
Social Engineering Assessments and the Consent They Require
Testing people is not testing systems. What can be assessed, what must be agreed first, and why individual results should almost never leave the room.