Red team vs penetration test
A penetration test is bounded by a system.
Consultants map the application, network or device in scope, combine automated scanning with manual testing, and safely exploit what they find so each finding is demonstrated rather than assumed. The output is a vulnerability report with proof of concept, a prioritised remediation roadmap and an executive summary.
A red team engagement is bounded by an objective. Operators follow the tactics, techniques and procedures of the threat actors being simulated, from reconnaissance and initial compromise through persistence and lateral movement to the agreed objective.
Only a small Control Group of senior staff knows the exercise is running, which keeps the test of detection and incident response realistic. The report documents the attack path, maps each step to MITRE ATT&CK and records the gaps in detection and response.
Red teaming suits organisations already running a mature security program with a SOC, incident response or blue team capability to exercise. When the question is which weaknesses in one system need fixing, a penetration test answers it directly.
Purple team vs red team
Both use adversary techniques; the main difference is whether the defenders know.
Red teaming works covertly towards an agreed business objective and tests whether the defences notice. Purple teaming is transparent and collaborative: techniques aligned with MITRE ATT&CK are executed while the blue team monitors, detection successes and misses are fed back as they happen, and attacks are replayed against modified detection rules.
Because the defenders know it is running, a purple team exercise cannot show how the organisation would respond under the pressure of a real incident. Red teaming answers that question.
Purple teaming fits where a SOC or blue team exists to work alongside and the aim is better detection. The two also connect: attacks from a red team engagement can be replayed with the defensive team afterwards to confirm that detections now fire, and that replay is delivered as purple teaming.
A Scattered Spider adversary emulation is a purple team exercise built around one threat group, running around 70 test cases drawn from its published tactics.
Assumed breach vs red team
A red team engagement includes gaining initial access. An assumed breach assessment grants that access up front, such as a compromised endpoint, a set of user credentials or an insider's account, so the whole exercise is spent inside the network: lateral movement, privilege escalation, data access and the response to it.
Starting from assumed access has a limit. The result covers activity after the foothold and cannot establish whether the initial compromise would have been prevented.
Assumed breach fits organisations with mature perimeter defences that need to validate internal security. Two variants start from other footholds: a compromised cloud identity in a cloud assumed breach, and a backdoored software dependency on a developer's device in a supply chain attack assumed breach.
An internal infrastructure penetration test also works inside the network, with a different aim. It targets specific systems to identify and report vulnerabilities, while an assumed breach pursues objectives such as data exfiltration or domain compromise and tests monitoring and incident response along the way.
What CORIE is and who it applies to
CORIE (Cyber Operational Resilience Intelligence-led Exercises) is a framework developed by the Council of Financial Regulators for Australia's financial sector.
A CORIE exercise is an intelligence-led red team engagement: threat intelligence aligned with financial sector threats shapes the scenarios, which simulate the techniques of nation-states, organised cybercrime and advanced persistent threats. The exercise targets technology, personnel and incident response, and tests the resilience of Critical Business Services, the functions whose disruption would significantly affect the confidentiality, integrity or availability of core financial systems.
CORIE applies to banks, insurers and payment providers mandated by the Council of Financial Regulators.
Other financial institutions run it to build resilience against advanced persistent threats ahead of any mandate. Outside the financial sector, a red team engagement tests the same defences without the CORIE framing and reporting.
CREST approval and CORIE capability are separate, and the Council of Financial Regulators does not treat one as evidence of the other.
SilentGrid is a CREST ANZ approved company. Its co-founders executed CBEST in the United Kingdom, the intelligence-led framework CORIE was modelled on, and the team has run CORIE engagements in Australia.
Still deciding
Which security test do you need? asks what you want tested and what you need to find out, then suggests an engagement and explains why it fits. It takes four to nine questions and needs no email.
The hubs list every engagement: adversary simulation and penetration testing.
Tell us what the testing needs to prove
Scoping starts with the objective and the scope, and we will match the engagement to your risk tolerance and defensive maturity.