Red team
group tasked with providing security feedback to an organization by playing the role of an enemy or opponent

A red team is a group that simulates an adversary, attempts a physical or digital intrusion against an organization at the direction of that organization, then reports back so that the organization can improve their defenses. Red teams work for the organization or are hired by the organization. Their work is legal, but it can surprise some employees who may not know that red teaming is occurring, or who may be deceived by the red team. Some definitions of red team are broader, and they include any group within an organization that is directed to think outside the box and look at alternative scenarios that are considered less plausible. This directive can be an important defense against false assumptions and groupthink. The term red teaming originated in the 1960s in the United States.
Technical red teaming focuses on compromising networks and computers digitally. There may also be a blue team, a term for cybersecurity employees who are responsible for defending an organization's networks and computers against attack. In technical red teaming, attack vectors are used to gain access, and then reconnaissance is performed to discover more devices to potentially compromise. Credential hunting involves scouring a computer for credentials such as passwords and session cookies, and once these are found, can be used to compromise additional computers.
“Red team” enters the record as group tasked with providing security feedback to an organization by playing the role of an enemy or opponent. Crown Archives preserves that source wording while asking what team, group and tasked can confirm, complicate or overturn.
Why this record matters
“Red team” is worth following because a concise public description often conceals a longer documentary argument. Here, team, group and tasked provides the most credible route into that argument.
The record creator and administrative purpose are central evidence, because official documentation reflects both action and institutional priorities. The source revision retrieved here is dated Sep 9, 2026. The linked authority identifier is Q7305396. None of the 0 selected statements returned an explicit reference.
Institutional narratives can privilege the records that survived while minimizing voices that were never formally collected. The source lead contains qualifying language; that uncertainty should survive quotation, summary and reuse. Authority statements aid reconciliation but still require their own references, qualifiers and ranks to be checked.
How to read it
Compare institutional narratives with records created by participants and affected communities. Dates and formal titles are useful anchors, but not substitutes for context.
- Event chronology
- Institutional context
- Locating named record creators
Contemporary correspondence, government or organizational records, oral histories and cited historical scholarship.
Three-step research path
- Establish the record: confirm the title “Red team”, its source revision and the description used here.
- Expand the search: follow Red team primary sources, Red team archive and team research across catalogues and specialist indexes.
- Test the account: compare the strongest cited source with the responsible institution’s current record and note any disagreement.
Questions for further research
- Which source most directly establishes the central claim about “Red team”?
- Who created the surviving record, and for what administrative purpose?
- What chronology connects this entry to wider political or social change?
Search terms from this dossier
This entry incorporates text from “Red team” on English Wikipedia. Contributors are listed in the page history. Text is available under the Creative Commons Attribution-ShareAlike 4.0 License. Selected authority identifiers and statements are retrieved from Wikidata under CC0; their references and qualifiers remain part of the verification path.