Scoping questions / Adversary simulation

Red team scoping questions

The questions asked when scoping a red team or adversary simulation, and why each one matters. Answer them online or in a fillable PDF.

22 questions · Fillable PDF · No email required to download

These are the questions a SilentGrid consultant asks when scoping a red team or adversary simulation. Answering them first makes the call shorter and the plan more accurate.

"Not sure" is a fine answer. Several of these are decided together on the call.

Questions marked Sizing help us prepare an accurate quote.

Objective

  1. Why we ask: this becomes the exercise objective. "Approve a fraudulent payment" tests far more than "get domain admin".

  2. Why we ask: it shapes the tools and techniques used, and how the attack path is mapped to MITRE ATT&CK.

  3. Why we ask: CORIE sets its own phases and reporting, which changes the plan.

  4. Why we ask: a result for an investment case needs different evidence from one used to train the security team.

Starting position

  1. Sizing

    Why we ask: initial access can take weeks. Assumed breach spends that time inside the network instead.

  2. Why we ask: phishing and phone pretexting need explicit approval.

  3. Sizing

    Why we ask: physical entry needs separate authorisation letters and planning for each site.

  4. Why we ask: supply chain scenarios need the right starting access, and sometimes the supplier's agreement.

  5. Sizing

    Why we ask: the size of the environment sets how long reconnaissance and movement take.

Control Group

  1. Why we ask: that group becomes the Control Group. Everyone outside it, including the security operations team, is part of what is being tested.

  2. Why we ask: a real incident, or a response that goes too far, needs one call to resolve.

  3. Why we ask: the check has to be quiet, or the defenders learn the answer.

  4. Why we ask: some managed security contracts require notice. Otherwise the provider's response is part of the test.

Rules of engagement

  1. Why we ask: these become the exclusions in the rules of engagement.

  2. Why we ask: the exercise is planned around them.

  3. Why we ask: demonstrating access, or taking a screenshot or test file, proves the point without touching real data.

  4. Why we ask: cloud and hosting providers may need notice before testing.

Detection and response

  1. Why we ask: it decides which moments are recorded and timed.

  2. Why we ask: findings can then separate "not logged" from "logged but missed".

  3. Why we ask: replaying the attack with defenders turns missed detections into working ones. It is scoped separately.

After the exercise

  1. Why we ask: it shapes the debriefs and the report.

  2. Why we ask: follow-up work is agreed at scoping, not assumed.

Send your answers

Your answers go to the consultant who will run the scoping call. Leave out credentials, internal addresses and other sensitive detail: general descriptions are enough.

Unanswered questions are fine; the call covers them. Handled under the privacy policy. The form is protected by Cloudflare Turnstile, which sets no cookies (Cloudflare privacy policy).