Red-team is a structured adversarial simulation practice where a designated team, operating under formal authorization, assumes the role of an opponent or attacker to probe a target system, process, or organization for vulnerabilities and defensive gaps. Parameters: (1) a clearly authorized red team with defined scope and rules of engagement, (2) a defined target system or process under test, (3) adversarial methodology mirroring likely attacker tactics and techniques, (4) a formal reporting mechanism documenting findings and recommendations for remediation. Persistence mechanism: institutional practice sustained through security frameworks, military doctrine, and organizational governance protocols. [formal: red-capitulum | substrate: behavior | horizon: a life | explicit: yes | epoch: 0.01]
Accepted ontology entry
red-team
Red-team is a structured adversarial simulation practice where a designated team, operating under formal authorization, assumes the role of an opponent or attacker to probe a target system, process, or organization for vulnerabilities and…
Definition
Why it is in scope
A human-made adversarial simulation practice in which a team is authorized and directed to act as an opponent or attacker against a system, organization, or process to test and expose its defenses, vulnerabilities, and weaknesses. Created through formal authorization, structured methodologies, and persisted as an institutional practice within security, military, and organizational frameworks.
Names and aliases
- red-teamen · CANONICAL
Relations from this entry
- cmrhnc65902098aehuxnv9f0wSERVES →
A red-team exists for the sake of security — its designed purpose is to test and improve security posture through adversarial simulation. Law 8d: for whose sake? servant (red-team) → master (security). The note shows purpose by design, not incidental benefit.
- cmruhobs801cnr671yev1kr8fINSTANCE_OF →
A red team exercise is a specific kind of adversarial simulation — it simulates an attacker's behavior to test defenses. A competent speaker would say 'red teaming is a kind of simulation.' The simulation is of hostile action; the red team is the method of running that simulation.
- cmrviplrr01a42cei2qsm3jjzDEPENDS_ON →
Red-teaming is an adversarial evaluation practice that depends on assessment methodology — the systematic evaluation of security posture. Remove assessment as a practice and red-teaming loses its evaluation framework. Direction correct (assessment older at 0.03 vs red-team at 0.09).
- cmrviplrr01a42cei2qsm3jjzINSTANCE_OF →
Correcting the misfiled DEPENDS_ON (struck): red-teaming is not a thing that depends on assessment — it IS a specific kind of assessment. Under assessment's accepted definition (the structured practice of gathering information to characterize a system, with parameters: target, criteria, methods of information gathering — explicitly including 'testing' — and a resulting characterization), red-teaming instantiates it with method = simulated adversarial attacks and output = a vulnerability/security-posture characterization. It is a subset/kind, so identity is not dependency (Law 8c); the correct edge is INSTANCE_OF. Nearest kind: no security-assessment or adversarial-testing entry exists, so 'assessment' is the nearest available kind (Law 11e). Pinned sense: adversarial evaluation as a species of information-gathering assessment.
Relations to this entry
No accepted relations in this direction.
Record identity
- Created
- Jul 28, 2026, 7:03 PM UTC
- Content hash
- 7d9ac9a3c5d4e00644fd82f2ae81966da68bf929127558c2535a2bc3cba54d7d