Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Red team exercises are misaligned with attacker TTPs in cloud and endpoint


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 17031
Topic starter  

TL;DR: Red teams concentrate on cloud initial access, privilege escalation, and endpoint credential access, while real attackers spend more time on discovery, defensive evasion, persistence, and impact, according to Expel’s annual threat report. The gap suggests exercise incentives are rewarding penetration theatre over the attack stages that most often determine real risk, per Expel.

NHIMG editorial — based on content published by Expel: red team activity is drifting from real attacker behaviour

By the numbers:

Questions worth separating out

Q: How should security teams make red team exercises more realistic?

A: They should anchor scope to observed attacker behaviour, not to whatever playbooks are easiest to demonstrate.

Q: Why do red team exercises often miss the controls that matter most?

A: Because many programmes reward visible compromise, which pushes teams toward access-centric tactics and away from less theatrical but more realistic stages like discovery, persistence, and exfiltration.

Q: What do security teams get wrong about lateral movement prevention?

A: They often treat lateral movement as a detection problem when it is also a design problem.

Practitioner guidance

  • Recalibrate red team scoring to real attacker TTP frequency Weight exercises toward the techniques attackers actually use in cloud and endpoint environments, then deprioritise success criteria that reward access theatre over realistic risk.
  • Add cloud discovery to your detection validation plan Test alerts for AWS account enumeration, bucket discovery, exposed-service probing, and similar discovery commands before assuming intrusion coverage is adequate.
  • Map red team findings to identity and privilege paths When a red team reports initial access or privilege escalation, trace which human or non-human identity made that path possible, then verify whether the same path exists in production.

What's in the full article

Expel's full article covers the operational detail this post intentionally leaves for the source:

  • How Expel segmented red team versus real attacker activity across cloud infrastructure and endpoints
  • The specific MITRE ATT&CK tactic differences observed in each environment, including where red teams over-indexed
  • The rules-of-engagement discussion that explains why persistence and exfiltration are often excluded from exercises
  • The leadership guidance on how to change incentives so red team reports align with measurable risk reduction

👉 Read Expel’s analysis of red team misalignment with real attacker behaviour →

Red team exercises are misaligned with attacker TTPs in cloud and endpoint?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 16123
 

Goodhart’s Law creates a red team realism gap: when red teams are rewarded for demonstrable access, they optimise for visible compromise rather than representative attacker behaviour. That incentive distorts exercise design across cloud and endpoint environments and can make a weak control set look stronger than it is. Leaders should treat red team success metrics as governance inputs, not proof that the highest-risk paths were tested.

A question worth separating out:

Q: Should organisations treat red team success as proof that their controls are strong?

A: No. A successful red team can show that an attack path is possible, but it does not prove that the most likely or most damaging attacker path was tested. Organisations should validate whether the engagement model reflects real attacker frequency, realistic objectives, and the identity paths that actually exist.

👉 Read our full editorial: Red team activity is drifting from real attacker behaviour



   
ReplyQuote
Share: