Offensive security is a reality test (opens in new tab)
Distilling what a Red Team does can be difficult at times, because frequently people focus on the tactical findings: this vulnerability, that misconfiguration, some control that didn’t work or doesn’t exist. Those are all valuable and important aspects of the work, no doubt, and they’re the common artifacts of operations. But they’re not the essence.
I like Andy’s characterization of red teaming as a truth-finding function, and it’s very close to how I’ve been describing the work as well. Taking a contrarian position to a given claim (“Our data is secure.”) and then working to validate that hypothesis, to find the truth.