Skip to main content

The Phases of a Red Team Engagement

Reconnaissance, initial access, foothold, movement, objective, debrief. What happens in each, roughly what share of the weeks it takes, and which phase produces no findings at all.

By Siddarth G
August 19, 2026 Last updated 6 min read

A red team runs in phases that look like a penetration test but are weighted completely differently. Most of the calendar goes on the two phases that produce no findings.

The phases are also not a queue. Teams loop: reconnaissance restarts the moment they are inside, and a burned route sends them back to initial access.

Phase 0: before the clock starts

Three things have to exist before day one, and none of them is testing.

The signed authorisation and the trusted agents. Scope, dates, permitted techniques, stop conditions, and the people who can halt the exercise. It is set out in scoping a red team, and none of it can be agreed while a team is already running.

The adversary being imitated. A red team modelling nobody in particular defaults to whatever its operators find comfortable. Choose a threat actor profile that plausibly targets your sector and map its behaviours to MITRE ATT&CK, so the report has something to be checked against.

Infrastructure. Domains, certificates, mail paths and callback channels that look ordinary to your filters. This carries lead time. Anything bought on the Friday before is something your mail gateway has never seen, and when a start date slips, that is usually why.

1. Reconnaissance: often a third of the engagement

Almost none of it touches you. Staff on professional networks and what their job titles reveal about your stack. Job advertisements, which are the most generous public disclosure most organisations make. Code and credentials in public repositories. Document metadata. Address ranges, subdomains and certificate transparency logs. For physical scope, the building, its entrances, and when people arrive.

This phase regularly produces findings you would rather not have, before anyone has attempted anything.

Two limits on it. Reconnaissance maps what an outsider can see and stops there, so do not read it as an inventory of your estate. And the personnel surface is wider than your payroll: in most Indian enterprises a large share of the people holding credentials are contractor and partner staff who list your organisation publicly, and phase one treats them as yours because an attacker would.

2. Initial access

Getting a foothold. Teams normally rank several routes by likely success and lowest noise, then try them in order: phishing a person, exploiting something exposed, walking into a building, a supplier, or a credential found in phase one.

Failure here is normal. An adversary who fails on Tuesday tries something else on Friday, and a compressed engagement that cannot afford Friday is not simulating anything. See what a red team engagement costs for why duration is the line item that matters most.

That raises the decision most engagements face at least once: what happens when nothing works. Three answers, and the choice is yours.

  • Give it more calendar. Honest, and it eats the later phases that produce the report.
  • Widen the permitted techniques. Physical entry or telephone pretexting added to a scope that began as external only. The authorisation has to be amended in writing.
  • Start from an assumed breach. You hand over a standard workstation and user account, and the exercise begins at phase three. Still real, and it now says nothing about your perimeter or your people, only about what follows a compromise.

Agree which one, and at what point, before the engagement starts.

3. Establishing the foothold

Making access reliable and quiet: persistence that survives a reboot, communications that look like ordinary traffic, and enough understanding of the environment to move without tripping something.

This is where most exercises get caught. Being caught is the answer to the question you paid to ask.

It also has a procedure, and the proposal should name it. A detected route usually means the access is gone and the infrastructure behind it is burned. The trusted agents then choose: let your team run the response as a live test, or declare the exercise, stand them down and re-enter by another route. Settling that at midnight, unrehearsed, is how an exercise becomes an incident.

4. Movement toward the objective

Credentials, lateral movement, privilege escalation, and reaching the systems that matter. In a mature environment this is slow and deliberate. In most environments it is faster than anyone expects, usually because of a reused local administrator password or an over-privileged service account. The mechanics, and the internal weaknesses that make it quick almost everywhere, are in after the foothold.

5. Reaching the objective

Demonstrating it, not exploiting it. Enough evidence to prove the outcome and no more: a row instead of the table, one transaction instead of many.

Which leaves evidence handling, asked about too late. Proving the customer database was reached means the team held some of your customer data, even if it was one row. Settle in the authorisation where it sits, who can open it, how long it is kept after delivery, how it is destroyed and what confirms the destruction. Screenshots included: a redacted image still proves the access.

6. The debrief

The red team and your defenders walking the timeline together. Frequently the most valuable hours of the whole engagement and one of the cheapest line items. Ask for it explicitly.

One practical obstacle. If your monitoring is operated by an outside provider, the people who most need to be in that room work for somebody else, and their attendance is contractual, arranged before the engagement begins. What to do with the timeline afterwards is in what the exercise tells you about detection.

How the weeks divide

As a rough shape: reconnaissance around a third, initial access a variable slice that can consume weeks or an afternoon, movement and objective around a third, reporting and debrief the remainder.

PhaseWhat your side doesWhat it produces
0. PreparationSign the authorisation, name trusted agentsScope, rules, a deconfliction route
1. ReconnaissanceNothing, and you will not notice itExposure findings, a ranked route list
2. Initial accessNothing, unless a stall forces the decision aboveA foothold, or a documented failure
3. FootholdPossibly detect and respondThe first real detection evidence
4. MovementPossibly detect and respondMost of the detection timeline
5. ObjectiveAgree handling and destruction of evidenceProof, held to a minimum
6. DebriefGet defenders and providers in the roomNarrative, timeline, owned actions

The useful implication is the same as for penetration testing but starker. A large share of a red team produces nothing you could put in a findings table. It is spent watching, waiting and writing. A proposal priced as though every day is an attacking day has either omitted the rest or intends to skip it, and the phase it skips is reconnaissance, which is where the realism lives.

What the phases prove outside the security team

Phase 0 is where the firm's credentials are established. Under the Reserve Bank's consolidated Directions of 31 July 2026, ¶156 requires the entity to consider the qualification, professional expertise, credentials and competency of the testing firm and of its assigned personnel, at selection, appointment, engagement and at every renewal. That record is built before work starts. Security Brigade has held CERT-In empanelment continuously since 2008, and every Indian regulator that accepts an audit report accepts it from a CERT-In empanelled auditor.

Red teaming itself sits in the permissive register: ¶162 says red teams may be used, and the equivalents for small finance banks, payments banks and credit information companies use the same word. So the exercise has to argue for itself, and what a board or a supervisor reads is the narrative and the detection timeline out of phase six. Detail in red teaming under the RBI Directions 2026.

When the phase shape says buy something else

Phase two has no fixed duration. If you need a dated deliverable for a committee meeting, that uncertainty is the problem, and a scheduled penetration test gives you the date.

The same applies when the calendar you can offer is short. Compression means cutting reconnaissance, the one phase with no visible output to defend, and that removes the realism you are paying for.

And if nothing downstream is funded, the exercise stops at the debrief. Where the money for collection, rule and response work does not exist yet, spend it on a purple team first: same techniques, your defenders watching, cheaper to act on.

What lands on your desk at the end is in what a red team report contains.

About the author

Siddarth G

Practice Director — Cybersecurity

Leads Security Brigade's offensive security practice with deep expertise in vulnerability research, penetration testing, and red team operations. Ranked Top 80 globally on Bugcrowd.