By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: ExpelPublished July 27, 2026

TL;DR: Red teams concentrate on cloud initial access, privilege escalation, and endpoint credential access, while real attackers spend more time on discovery, defensive evasion, persistence, and impact, according to Expel’s annual threat report. The gap suggests exercise incentives are rewarding penetration theatre over the attack stages that most often determine real risk, per Expel.


At a glance

What this is: Expel’s annual threat report argues that red team exercises often emphasize attack paths that do not match observed attacker behaviour in cloud and endpoint environments.

Why it matters: That matters because IAM, PAM, and broader security programmes can end up funding the wrong controls if red team outputs overstate access-centric gaps and under-test discovery, persistence, and exfiltration paths.

By the numbers:

  • 32.2%, iggest share of cloud infrastructure incidents, 32.2%, were confirmed as red team activity, even though cloud infrastructure represented only 2.5% of overall incidents.
  • Red teams attempted to attain credential access 17 percentage points more often than real-world attackers on endpoints.
  • When attackers reached endpoints, 63.9% of the time they deployed malware such as commodity malware and ransomware.

👉 Read Expel’s analysis of red team misalignment with real attacker behaviour


Context

Red team programmes are meant to test whether controls fail under realistic pressure, but their value weakens when exercise design rewards visible penetration over faithful attacker behaviour. In this article’s context, the problem is not red teaming itself, but the incentive structure that can push teams toward cloud or endpoint playbooks that generate impressive findings while missing the attack stages that most often drive actual harm.

That gap has an identity dimension as well. Cloud discovery, credential access, and privilege escalation are all mediated by accounts, tokens, and access paths, so IAM and PAM teams can misread exercise results if they treat every successful red team intrusion as an equally relevant control signal. The better question is whether the exercise mirrors the real exposure of service identities, privileged sessions, and cloud access paths in the environment.


Key questions

Q: How should security teams make red team exercises more realistic?

A: They should anchor scope to observed attacker behaviour, not to whatever playbooks are easiest to demonstrate. That means weighting discovery, evasion, persistence, and exfiltration more heavily when those stages dominate real incidents, then using findings to test the controls that would have broken the attack chain earlier.

Q: Why do red team exercises often miss the controls that matter most?

A: Because many programmes reward visible compromise, which pushes teams toward access-centric tactics and away from less theatrical but more realistic stages like discovery, persistence, and exfiltration. The result is a control-testing model that can look rigorous while leaving the highest-risk paths under-tested.

Q: What do security teams get wrong about lateral movement prevention?

A: They often treat lateral movement as a detection problem when it is also a design problem. If internal protocols stay open, control planes stay reachable, and privileged identities stay broad, the attacker still has room to move even when alerts fire. Prevention alone is incomplete unless the network itself limits travel.

Q: Should organisations treat red team success as proof that their controls are strong?

A: No. A successful red team can show that an attack path is possible, but it does not prove that the most likely or most damaging attacker path was tested. Organisations should validate whether the engagement model reflects real attacker frequency, realistic objectives, and the identity paths that actually exist.


Technical breakdown

Why red team exercises over-index on initial access and privilege escalation

Red teams are often scored on whether they can demonstrate penetration, so tactics that visibly prove compromise get overrepresented. Initial access and privilege escalation are easy to translate into a reportable win, especially when the engagement rubric values breadth of access over realism. In cloud environments, though, that can distort the attack story because many real intrusions do not require the same access-building sequence. Practitioners should treat these tactics as engagement artefacts unless the scoring model is tied to realistic attacker objectives, not just access acquisition.

Practical implication: redesign red team scoring so access alone is not treated as success unless it reflects a realistic attack objective.

Cloud discovery and command-and-control show where real attackers spend effort

Cloud attacks frequently begin with a compromised credential or exposed service and then move into discovery, where attackers enumerate accounts, buckets, instances, and reachable services. That reconnaissance matters because cloud estates are broad and often loosely understood by the attacker once inside. Expel’s analysis also notes command-and-control and commodity payloads in real incidents, which indicates that opportunists often aim for fast exploitation rather than elaborate lateral movement. This is a control problem as much as a detection problem, because discovery activity is observable early if logging and alerting are tuned for it.

Practical implication: tune cloud detections for account enumeration, bucket discovery, and exposed-service probing before chasing endpoint-style lateral movement.

Endpoint credential harvesting is less important than credential abuse and persistence

On endpoints, red teams leaned heavily on credential access, but real attackers more often arrived with access already in hand and then focused on evasion, persistence, and malware deployment. That difference suggests the operational choke point is not always credential dumping on the endpoint itself. In many environments, identity compromise happens earlier through phishing, token theft, or reused access paths, then gets converted into endpoint execution. The governance implication is that endpoint defence, IAM, and NHI controls need to be evaluated as a chain, not as isolated layers.

Practical implication: test the full identity-to-endpoint chain, including phishing, token abuse, and persistence, rather than only local credential dumping.


Threat narrative

Attacker objective: The attacker wants to turn a small amount of valid access into profitable control, data theft, or infrastructure abuse before defenders can respond.

  1. Entry often begins with a compromised credential or exposed cloud access path, giving the attacker a foothold without needing a noisy exploit.
  2. Escalation shifts into discovery and selective abuse of cloud permissions, where the attacker maps accounts, buckets, instances, and exposed services to find the fastest route to value.
  3. Impact comes from malware deployment, cryptomining, or data exfiltration, with the attacker pursuing monetisation or operational disruption rather than a demonstrable but unrealistic lateral-movement chain.

NHI Mgmt Group analysis

Goodhart’s Law creates a red team realism gap: when red teams are rewarded for demonstrable access, they optimise for visible compromise rather than representative attacker behaviour. That incentive distorts exercise design across cloud and endpoint environments and can make a weak control set look stronger than it is. Leaders should treat red team success metrics as governance inputs, not proof that the highest-risk paths were tested.

Discovery is the under-tested stage that matters most in cloud environments: attackers do not need endpoint-style lateral movement if a single cloud credential opens broad inventory and data visibility. The article’s data suggests that red teams should spend more time validating whether account enumeration, service discovery, and exposed-resource hunting are detected early. Practitioners should re-rank discovery as a primary control-test objective.

Identity compromise happens earlier than endpoint compromise in many real attacks: the endpoint often receives an already-usable identity, whether through phishing, token theft, or abused non-human credentials. That makes the boundary between human IAM, NHI governance, and endpoint defence operationally important. Security teams should measure whether identity controls collapse the attacker’s path before the endpoint is ever touched.

Exfiltration and persistence are the governance gaps red teams often avoid testing: these stages are harder to simulate safely, but they are also where business harm becomes real. The article shows that realistic attack modelling can stop short of destructive action while still exercising the controls that matter, including offboarding, logging, and containment. Practitioners should insist that engagement scope reflects the attack chain, not just the report template.

What this signals

Discovery-first testing will matter more as cloud estates become more identity-driven: red team exercises that stop at initial access miss the point if production attackers are living off valid identities, enumerating services, and abusing access paths already approved by the business. For IAM and NHI programmes, the signal is to validate logging and alerting around account enumeration, token use, and service discovery, not just login failure events.

Red team realism is becoming an access-governance problem: when a cloud exercise proves compromise but not realistic attacker movement, the issue is not just methodology. It is a mismatch between governance of identities, privileges, and safe testing boundaries. Teams should calibrate exercise scope to the control boundary they actually want to test, then compare it with MITRE ATT&CK Enterprise Matrix techniques that match real incidents.

The practical implication for readers is a sharper separation between what a red team can safely demonstrate and what defenders must validate in production. That means building a feedback loop that uses incident data, identity controls, and cloud telemetry together, rather than treating exercise outcomes as a standalone verdict.


For practitioners

  • Recalibrate red team scoring to real attacker TTP frequency Weight exercises toward the techniques attackers actually use in cloud and endpoint environments, then deprioritise success criteria that reward access theatre over realistic risk. Use incident data to decide which tactics belong in scope, and review those decisions with IAM and SOC stakeholders.
  • Add cloud discovery to your detection validation plan Test alerts for AWS account enumeration, bucket discovery, exposed-service probing, and similar discovery commands before assuming intrusion coverage is adequate. Discovery is often the earliest observable stage after identity abuse, so it should be a first-class test case in cloud monitoring.
  • Map red team findings to identity and privilege paths When a red team reports initial access or privilege escalation, trace which human or non-human identity made that path possible, then verify whether the same path exists in production. Treat service accounts, tokens, and privileged sessions as the governance layer that either enables or blocks the attack.
  • Include persistence and exfiltration in safe engagement boundaries Define rules of engagement that let teams exercise persistence indicators, staged data movement, and containment evidence without harming production systems. That makes the engagement more representative and reduces the chance that the hardest parts of the attack chain remain untested.

Key takeaways

  • Red team programmes can drift into access theatre when incentives reward penetration more than realism.
  • Expel’s data shows cloud and endpoint attackers spend more time on discovery, evasion, persistence, and impact than red teams typically simulate.
  • The fix is to align exercises with real attacker TTPs and the identity paths that make those TTPs possible.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0007 , Discovery; TA0005 , Defense Evasion; TA0003 , Persistence; TA0010 , ExfiltrationThe article compares attacker and red team tactics across these ATT&CK stages.
NIST CSF 2.0DE.CM-1The piece is about whether monitoring reflects real attack behaviour and control gaps.
NIST SP 800-53 Rev 5SI-4Detection and analysis controls are central to catching discovery, evasion, and payload deployment.
CIS Controls v8CIS-8 , Audit Log ManagementRed team realism depends on the logs that reveal discovery, persistence, and exfiltration.

Map red team scope to the tactics most seen in production incidents, not just the easiest to demonstrate.


Key terms

  • Red Team Realism Gap: A mismatch between the attack techniques an internal or external red team uses and the techniques real attackers actually use in production. The gap matters because it can produce impressive reports while leaving the highest-risk behaviours under-tested and poorly governed.
  • Discovery-First Attack Pattern: An attack pattern where the adversary spends early effort enumerating accounts, services, buckets, and reachable resources before attempting impact. In cloud environments this stage can reveal the fastest route to value, and it is often the earliest point where defenders can detect misuse of identity.
  • Identity-To-Endpoint Chain: The sequence linking identity compromise, such as token theft or phishing, to endpoint execution, persistence, or malware deployment. It is a useful model because it shows that endpoint incidents often begin in IAM or NHI control failures rather than on the device itself.
  • Rules of engagement: The commercial and operational boundaries that define who can pursue, own, and support an opportunity. In identity programmes, these rules matter because unclear ownership can create remediation gaps, split accountability, and inconsistent customer support during deployment.

What's in the full article

Expel's full article covers the operational detail this post intentionally leaves for the source:

  • How Expel segmented red team versus real attacker activity across cloud infrastructure and endpoints
  • The specific MITRE ATT&CK tactic differences observed in each environment, including where red teams over-indexed
  • The rules-of-engagement discussion that explains why persistence and exfiltration are often excluded from exercises
  • The leadership guidance on how to change incentives so red team reports align with measurable risk reduction

👉 The full Expel post breaks down the cloud and endpoint tactic gaps, plus the incentive changes leaders should consider.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security practitioners connect identity controls to the broader attack paths their programmes must defend.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org