Offer

Free security assessment — you only subscribe if we find a P0 or P1 vulnerability.

Claim free assessment
CyVigilant
All articles
VAPT

What a Red Team Engagement Actually Simulates: Phishing, Pretexting, and Assumed Breach

February 24, 2026·CyVigilant Security Team
VAPTCyVigilant

A red team engagement is categorically different from a penetration test, and the distinction matters when procurement teams or security leaders are deciding which to commission. A penetration test is a systematic assessment of the attack surface — find and exploit every vulnerability possible within the scope, report them all, rank them by severity. A red team engagement is a goal-oriented simulation of a specific, realistic adversary — reach objective X (steal the CFO's emails, extract the customer database, achieve persistence in the production environment) using whatever techniques a real attacker would use, including social engineering, physical access, and operational security tradecraft, without triggering detection. The measure of success is not the number of findings; it is whether the objective was achieved and whether the blue team detected the activity.

The adversary simulation model

Red team engagements are structured around an adversary profile: the TTPs (Tactics, Techniques, and Procedures) of a realistic threat actor relevant to the organisation's industry and risk context. For an Indian financial services firm, the adversary profile might be based on APT group TTPs associated with financially motivated attacks on BFSI targets — using spear-phishing as the initial access vector, living-off-the-land techniques (LOLBAS, PowerShell, WMI) for post-compromise activity, and targeting the SWIFT interface or payment processing infrastructure as the objective. The MITRE ATT&CK framework provides the vocabulary for this — the red team maps their activity to ATT&CK techniques and the final report shows which techniques succeeded, which failed, and which were detected.

Phishing and spear-phishing campaigns

Phishing is the most statistically reliable initial access vector in real-world attacks. In red team engagements, a phishing campaign is typically the first phase after reconnaissance. Reconnaissance here means genuine OSINT: LinkedIn profiles of target employees to identify roles and reporting relationships, company email format analysis, review of recent press releases and LinkedIn posts for context to craft convincing pretexts, and harvesting of any existing credential exposure in breach databases. The phishing payload is custom — not a template from a commercial phishing platform, but a scenario designed around the target's context. A finance team employee receives an email that appears to be from their CFO, referencing a real upcoming audit and asking them to review an attached spreadsheet.

Spear-phishing is the targeted version: a small number of carefully profiled targets receive highly customised messages. The payload may be a macro-enabled Office document, a link to a credential-harvesting page that clones the organisation's SSO login, or a QR code in a printed document left in a common area (physical social engineering). The red team measures click rate, credential submission rate, and whether the payload execution triggered any detection. These metrics are useful for security awareness programme calibration as much as for technical security assessment. Our red team service covers the full social engineering component.

Pretexting and physical social engineering

Pretexting is social engineering via voice or in-person interaction — a call to the helpdesk from someone claiming to be a senior executive locked out of their account, a visit to the reception desk by someone in a hi-vis vest claiming to be from the building maintenance contractor. Pretexting tests whether human controls (call verification procedures, visitor access management, challenge protocols for helpdesk calls) are effective. In the majority of engagements where pretexting is in scope, helpdesk social engineering succeeds within one or two attempts — most organisations do not enforce call-back verification or out-of-band identity confirmation for account reset requests.

Assumed breach: testing detection and response

Assumed breach (sometimes called purple team or detection-focused red team) starts from a different premise: the attacker has already achieved initial access. The engagement tests the organisation's ability to detect and respond to post-compromise activity. The red team is given a foothold — access equivalent to a compromised endpoint — and proceeds through the attack chain: privilege escalation, lateral movement, persistence establishment, data staging and exfiltration. The blue team (internal SOC or MSSP) monitors with their normal tooling, with no prior knowledge of the specific red team activity timeline. The post-engagement debrief maps every red team action to whether it was detected, how quickly, and what the response was.

Assumed breach exercises are increasingly requested by organisations with mature perimeter security who want to test the quality of their detection and response capability rather than their preventive controls. For SEBI MIIs with SOC obligations and large banks with 24x7 security operations, assumed breach exercises provide a realistic assessment of whether the SOC investment is delivering detection capability against realistic adversary behaviour. The MITRE ATT&CK mapping in the final report directly supports improving detection rules and response playbooks.

Red team vs pentest: which to commission

The general principle: commission a penetration test when you want a systematic, comprehensive assessment of your attack surface and a findings report you can remediate. Commission a red team engagement when you want to test whether a determined, realistic adversary can achieve a specific outcome in your environment, and whether your detection and response capability would catch them. Most organisations should establish a solid penetration testing programme first; red team engagements provide the most value when the organisation already has a reasonably mature security posture to test against. Organisations with significant regulatory exposure or a high threat profile — large BFSI entities, critical infrastructure operators, large government contractors — should pursue both.

To explore what a red team engagement looks like in practice, visit our red team service page or talk to an expert about designing an adversary simulation for your environment.

Get started

Put this into action.

Book a 30-minute scoping call with a CERT-In empanelled security expert.

Talk to an Expert