Red Team vs Penetration Test.
A pentest answers, 'how exploitable is this scope?' A red team answers, 'would my SOC notice an adversary working a specific objective against me?'
A pentest answers, 'how exploitable is this scope?' A red team answers, 'would my SOC notice an adversary working a specific objective against me?'
File · Answer first
Pick by the question you actually need answered. If you want to know how exploitable a defined scope is, that is a pentest, and you should buy it first. If you already trust the exposure picture and want to know whether your SOC would catch an adversary working a goal across digital, physical, and human vectors, that is a red team. Run them out of order and the red team mostly returns hygiene findings a pentest would have surfaced cheaper. Below is where each one earns its budget.
File · Where each
File · Related services
Penetration testing · Red teaming · Choosing a pentest vendor
File · FAQ
Q1 Which should I do first?
Pentest first. Red team once your detection and response program is mature enough to learn from it.
Q2 How long is a red team?
In our engagements, red teams run 6 to 12 weeks and pentests run 2 to 6, with the exact window set at scoping against the objective and the surface.
Q3 Can you run both at once?
We can, but the lessons are clearer if they are separated in time.
Talk to an Operator
Real operators. Real attack paths. Real business impact. Talk to us about your security goals.