TL;DR: Red teams concentrate on cloud initial access, privilege escalation, and endpoint credential access, while real attackers spend more time on discovery, defensive evasion, persistence, and impact, according to Expel’s annual threat report. The gap suggests exercise incentives are rewarding penetration theatre over the attack stages that most often determine real risk, per Expel.
NHIMG editorial — based on content published by Expel: red team activity is drifting from real attacker behaviour
By the numbers:
- Red teams attempted to attain credential access 17 percentage points more often than real-world attackers on endpoints.
- When attackers reached endpoints, 63.9% of the time they deployed malware such as commodity malware and ransomware.
Questions worth separating out
Q: How should security teams make red team exercises more realistic?
A: They should anchor scope to observed attacker behaviour, not to whatever playbooks are easiest to demonstrate.
Q: Why do red team exercises often miss the controls that matter most?
A: Because many programmes reward visible compromise, which pushes teams toward access-centric tactics and away from less theatrical but more realistic stages like discovery, persistence, and exfiltration.
Q: What do security teams get wrong about lateral movement prevention?
A: They often treat lateral movement as a detection problem when it is also a design problem.
Practitioner guidance
- Recalibrate red team scoring to real attacker TTP frequency Weight exercises toward the techniques attackers actually use in cloud and endpoint environments, then deprioritise success criteria that reward access theatre over realistic risk.
- Add cloud discovery to your detection validation plan Test alerts for AWS account enumeration, bucket discovery, exposed-service probing, and similar discovery commands before assuming intrusion coverage is adequate.
- Map red team findings to identity and privilege paths When a red team reports initial access or privilege escalation, trace which human or non-human identity made that path possible, then verify whether the same path exists in production.
What's in the full article
Expel's full article covers the operational detail this post intentionally leaves for the source:
- How Expel segmented red team versus real attacker activity across cloud infrastructure and endpoints
- The specific MITRE ATT&CK tactic differences observed in each environment, including where red teams over-indexed
- The rules-of-engagement discussion that explains why persistence and exfiltration are often excluded from exercises
- The leadership guidance on how to change incentives so red team reports align with measurable risk reduction
👉 Read Expel’s analysis of red team misalignment with real attacker behaviour →
Red team exercises are misaligned with attacker TTPs in cloud and endpoint?
Explore further
Goodhart’s Law creates a red team realism gap: when red teams are rewarded for demonstrable access, they optimise for visible compromise rather than representative attacker behaviour. That incentive distorts exercise design across cloud and endpoint environments and can make a weak control set look stronger than it is. Leaders should treat red team success metrics as governance inputs, not proof that the highest-risk paths were tested.
A question worth separating out:
Q: Should organisations treat red team success as proof that their controls are strong?
A: No. A successful red team can show that an attack path is possible, but it does not prove that the most likely or most damaging attacker path was tested. Organisations should validate whether the engagement model reflects real attacker frequency, realistic objectives, and the identity paths that actually exist.
👉 Read our full editorial: Red team activity is drifting from real attacker behaviour