9 min read

What I Look For in a Red Team Report

Most red team reports are unreadable. The good ones are gold. Here is what makes the difference, in order, with the parts that most red teamers get wrong

Red Team Purple Teaming

Most red team reports are unreadable. The reports are written for the red teamer who wrote them, not for the CISO who is going to read them. The reports are full of technical detail that the red teamer is proud of and the CISO does not understand. The reports are missing the parts that the CISO actually needs.

The good red team reports are gold. The good red team reports are the reports that the CISO reads and then takes to the board. The good red team reports are the reports that drive the operational changes. The good red team reports are the reports that are worth the money.

Here is what makes the difference, in order, with the parts that most red teamers get wrong.

The first paragraph

The first paragraph is the most important paragraph. The first paragraph is the paragraph that the CISO is going to read. The first paragraph is the paragraph that the CISO is going to remember. The first paragraph is the paragraph that the CISO is going to take to the board.

The first paragraph should answer the four questions. The first question is what the red team did. The first paragraph should say, in plain language, what the red team did. The first question is the most important question. The first question is the question that the CISO is going to be asked first. The first question is the question that the first paragraph should answer first.

The second question is what the red team found. The first paragraph should say, in plain language, what the red team found. The second question is the second most important question. The second question is the question that the CISO is going to be asked second.

The third question is what the red team recommends. The first paragraph should say, in plain language, what the red team recommends. The third question is the third most important question. The third question is the question that the CISO is going to be asked third.

The fourth question is what the red team's findings mean for the business. The first paragraph should say, in plain language, what the red team's findings mean for the business. The fourth question is the fourth most important question. The fourth question is the question that the CISO is going to be asked fourth. The fourth question is the question that the board is going to be asked.

The first paragraph should be short. The first paragraph should be four sentences. The first paragraph should be the four sentences that answer the four questions. The first paragraph should be the four sentences that the CISO is going to read and remember.

The executive summary

The executive summary is the section that the CISO is going to read. The executive summary is the section that the CISO is going to take to the board. The executive summary is the section that the CISO is going to use to brief the leadership.

The executive summary should be one page. The executive summary should be the one page that the CISO can read in five minutes. The executive summary should be the one page that the CISO can use to brief the leadership in five minutes.

The executive summary should have four parts. The first part is the summary of the red team's findings. The first part should be the summary of the red team's findings in plain language. The second part is the summary of the red team's recommendations. The second part should be the summary of the red team's recommendations in plain language. The third part is the summary of the red team's assessment of the risk. The third part should be the summary of the red team's assessment of the risk in plain language. The fourth part is the summary of the red team's assessment of the operational impact. The fourth part should be the summary of the red team's operational impact in plain language.

The executive summary should not have technical detail. The executive summary should not have screenshots. The executive summary should not have tool output. The executive summary should be the high-level summary that the CISO can use to brief the leadership.

The kill chain

The kill chain is the section that the SOC analyst is going to read. The kill chain is the section that the detection engineer is going to read. The kill chain is the section that the CISO is going to skim. The kill chain is the section that is the most important for the operational team.

The kill chain should be in plain language. The kill chain should be a narrative. The kill chain should be a story of what the red team did, in the order that the red team did it. The kill chain should be a story of what the red team found, in the order that the red team found it.

The kill chain should include the specific actions the red team took. The kill chain should include the specific timestamps. The kill chain should include the specific systems that were involved. The kill chain should include the specific evidence that the red team collected. The kill chain should be specific enough that the SOC analyst can use the kill chain to write the detection rules.

The kill chain should not be a list of the techniques the red team used. The kill chain should be a story. The kill chain should be a story of what happened. The kill chain should be a story that the SOC analyst can read and understand.

The detection gap

The detection gap is the section that is the most important for the SOC. The detection gap is the section that is the most important for the detection engineering function. The detection gap is the section that the SOC and the detection engineering function are going to use to write the new detection rules.

The detection gap should be specific. The detection gap should be a list of the specific places where the SOC should have seen the red team's actions and did not. The detection gap should be a list of the specific alerts that should have fired and did not. The detection gap should be a list of the specific rules that should have caught the red team's actions and did not.

The detection gap should be prioritised. The detection gap should be a prioritised list. The detection gap should be the prioritised list that the SOC and the detection engineering function are going to use to write the new detection rules.

The detection gap should be honest. The detection gap should be honest about the places where the SOC and the detection engineering function failed. The detection gap should not be a list of the places where the SOC and the detection engineering function succeeded. The detection gap should be a list of the places where the SOC and the detection engineering function failed.

The recommendations

The recommendations are the section that the CISO is going to take to the board. The recommendations are the section that the CISO is going to use to brief the leadership. The recommendations are the section that the CISO is going to use to make the case for the budget.

The recommendations should be specific. The recommendations should be a list of the specific changes that the CISO is going to make. The recommendations should be a list of the specific changes that the CISO is going to fund. The recommendations should be a list of the specific changes that the CISO is going to track.

The recommendations should be prioritised. The recommendations should be a prioritised list. The recommendations should be the prioritised list that the CISO is going to take to the board. The recommendations should be the prioritised list that the CISO is going to fund.

The recommendations should be honest. The recommendations should be honest about the cost of the recommendations. The recommendations should be honest about the time that the recommendations are going to take. The recommendations should be honest about the operational impact of the recommendations.

The operational summary

The operational summary is the section that the SOC and the detection engineering function are going to use. The operational summary is the section that is the most under-appreciated. The operational summary is the section that is the most important for the operational team.

The operational summary should be a list of the specific things that the SOC and the detection engineering function are going to do as a result of the engagement. The operational summary should be a list of the specific detection rules that the detection engineering function is going to write. The operational summary should be a list of the specific runbooks that the SOC is going to update.

The operational summary should be the part of the report that the operational team uses to drive the changes. The operational summary should be the part of the report that the operational team uses to track the changes. The operational summary should be the part of the report that the operational team uses to measure the changes.

The honest answer

The honest answer is that most red team reports are unreadable. The honest answer is that the unreadable reports are the reports that the CISO does not read, that the SOC does not use, that the detection engineering function does not act on. The honest answer is that the unreadable reports are the reports that are not worth the money.

The honest answer is that the good red team reports are gold. The honest answer is that the good red team reports are the reports that the CISO reads and takes to the board. The honest answer is that the good red team reports are the reports that drive the operational changes. The honest answer is that the good red team reports are the reports that are worth the money.

The honest answer is that the difference between the unreadable and the good is the first paragraph, the executive summary, the kill chain, the detection gap, the recommendations, and the operational summary. The honest answer is that the difference is the work. The honest answer is that the work is the writing. The honest answer is that the writing is the report.

If you are writing a red team report, write the report. If you are writing a red team report, write the report that the CISO is going to read. If you are writing a red team report, write the report that the SOC is going to use. If you are writing a red team report, write the report that the detection engineering function is going to act on. The report is the work. The work is the writing. The writing is the report.