- What is a red team attack scenario?A realistic, objective-based simulation of how a specific adversary would attack your organization, run to test whether your team detects and responds.
- What are the most important red team scenarios to simulate?AI-powered phishing, cloud privilege escalation and lateral movement, EDR evasion via living-off-the-land tactics, SaaS compromise via OAuth token abuse, and data exfiltration via DNS tunneling.
- How many scenarios should a red team engagement cover?Typically 1–3 per engagement, chosen by business risk - depth beats breadth. Learn more about scope examples.
- What's the difference between a red team scenario and an objective?The objective is the goal (e.g. "reach the payment system undetected"); the scenario is the adversary and attack path used to get there. Learn more about red team objectives.
- Who decides which red team scenarios to run?The CISO and red team define them together during scoping, informed by the organization's threat model and crown jewels.