Red Team and Penetration Test: differences and objectives

A good definition of the expression “Red Team” is provided by Joe Vest and James Tubbervill in their book “Red Team Development and Operations”:

“Red Teaming is the process of using tactics, techniques and procedures (TTPs) to emulate a real-world threat, with the goal of measuring the effectiveness of the people, processes and technologies used to defend an environment.”

Althought this definition may refer to the idea of Penetration Test, there are several key aspects that draw a clear line between the two approaches, although both have many points in common, such as the actors involved in the process and some techniques employed. Unfortunately, on the web, the distinction between the two methods is not always clear: this creates a certain confusion that leads to misuse both expressions.

Red Team: process and methodology

To understand what a Red Team is, it is therefore necessary to explain the concept of Penetration Test: it consists of a series of methodologies and techniques, aiming at identifying the greatest possible number of vulnerabilities in a network. It proofs not only how these vulnerabilities may be exploited but also the risks that an organization runs, if  an adequate Vulnerability Patching and Management plan is not applied. A Penetration Test may also be the direct consequence of a Vulnerability Assessment or it may be necessary to support an Audit. Finally, the Penetration Testing activity ugenerates a report, which usually consists of a series of exploited vulnerabilities, misconfiguration and the related Remediation Plan. However, here an essential element is missing, which according to us has become crucial nowadays: the ability of an organization to detect and promptly react to a targeted attack.

Gli attori della simulazione: Red Team, Blue Team e Purple Team

Right there the Red Team comes into play, whose aim is not to detect the greatest number of vulnerabilities anymore, but to compromise and/ or gain access to a specific business asset, previously agreed with the organization requesting this service. The asset set as target of the simulation may be a Server, an e-mail box, a database or even a single file, and it is really important that the content of such assets is considered as critical.

The Red Team, whose target is precisely this asset, will simulates a real attack scenario, which will be carried out by highly qualified experts and will last longer compared to a typical Penetration Test. Another key difference concerns methodologies used to carry out the entire simulation: they are focused on creating an attack that is as transparent as possible, without generating noise or indicators of an ongoing Data Breach. These features are possible thanks to highly advanced and professional tools and techniques, which require greater engagement and study, going beyond the skillset of a normal Penetration-Tester.

 

To correctly simulate all these procedures, and so evaluate the organization’s responsiveness, the Red Team will have to reach its target without being detected by its “opposing” Blue Team, i.e. the staff in charge of protect the organization from cyberattacks.

Once more,  a good definition of this process is provided in “Red Team Development and Operations” by Joe Vest and James Tubberville:

Red Teams are used to measure the effectiveness of the people, processes, and technology used to defend a network, train or measure a Blue Team (defensive security operations), and test and understand specific threats or threat scenarios.”

Moreover, another actor has emerged in the last years, namely the Purple Team.  Its main role is to supervise the two other teams’ activity, in order to optimize the results. This does not only imply being a mediator between the Red Team and the Blue Team, but it also ensures an overall view from a perspective, which is different both from the attacker’s and the defender’s position. Thanks to this less known but not less important methodology, the organization can have a much more clear idea of its exposure to a target attack and of its reaction to it.

Finally, the following chart shows the IPDRR coverage (Identify, Protect, Detect, Respond, Recover), depending on the methodology adopted by the organization.

Schema differenze Red Team, Penetration Test e Vulnerability Assessment

(Red Team Development and Operations by Joe Vest e James Tubberville)

It is important to underline that none of these three methodologies is better or greater than the others. In fact, it is necessary to consider on a case by case basis the optimal approach to adopt, according to the client’s needs and the possibilities.

A new evolution: software-based penetration test

Thanks to its software solution, ZAIUX® Evo, Pikered has decided to make a tool guided by Artificial Intelligence available, which is able to perform automated Internal Penetration Tests, allowing for the assessment of vulnerabilities in IT infrastructures through an ongoing approach. ZAIUX® Evo’s execution mode is comparable to that of a manual Penetration Test, making it unnecessary to manually assess the vulnerabilities, which is required after a Vulnerability Assessment. The techniques employed by ZAIUX® Evo tend to emulate as much as possible a real scenario, the whole being guided and planned by an intelligent engine which optimizes timing and resources. ZAIUX® Evo aims at working alongside Penetration Tester and System Administrators in identifying vulnerabilities, which often may pass unnoticed both by a Vulnerability Assessment and a human Penetration Tester. Furthermore, this solution is meant to be a follow up to manual activities, being them Penetration Test or Red-Team related, in order to ongoingly prove the internal resilience of an IT-Infrastructure.