July 2025

Unleashing Synergy: How BAS Enhances Collaboration Between Red Team and Blue Team

For over 10 years, Red Team operations have been carried out by numerous organisations, using different approaches, to achieve a variety of objectives that sometimes differ from their primary role. These offensive simulations now play a vital role in assessing the defences put in place by the Blue Team, by testing their detection and response capabilities.

However, Breach and Attack Simulation (BAS) solutions are now a strategic complement to Red Teams. In a Purple Team approach, the automation and diversity of attacks enable broader coverage and more frequent security testing, resulting in more effective and regular testing of the defences. In this way, BAS do not replace Red Teams, but amplify their impact by ensuring continuous validation of the defence posture and making investigations more responsive and efficient.

Red Team objectives and development

Red Team operations simulate realistic attacks from the perspective of an advanced adversary, in order to test an organisation’s overall security posture. Their main objective is not to exploit as many vulnerabilities as possible, but to determine whether an advanced threat could reach its targets undetected.

Historically, they have focused on obtaining trophies (management emails, financial reports, HR documents, data from sensitive R&D activities, etc.), thereby demonstrating the feasibility of the attack. To achieve this, the Red Team identifies exploitable attack vectors and bypasses security measures. Its approach is resolutely offensive, as its name suggests.

However, with resources dwindling and vulnerabilities increasing exponentially, it is becoming difficult to identify and rectify every single security flaw one by one. The expansion of the attack surface – driven by the proliferation of software, the increasing complexity of systems and the pressure to innovate rapidly – limits the effectiveness of this traditional approach. It remains relevant, but needs to be complemented by other methods with a broader perspective. If we consider that an adversary always has a chance of exploiting a vulnerability, it is imperative to focus on the next step: optimising the detection and neutralisation of attacks. This is the task of the Blue Team. The link between the Red and Blue Teams is therefore essential: carrying out attacks to evaluate and improve the effectiveness of defences!

Factors influencing the effectiveness of Red Teams

(a) A strong focus on stealth

Many Red Teams prefer a stealthy approach, in line with the oft-repeated adage: «A well-run Red Team is an undetected Red Team». Red Teamers therefore seek to remain discreet and make their actions difficult to detect. However, not all organisations have the detection capabilities to meet this challenge. It is therefore crucial to adjust the intensity of the noise generated in order to assess each defence under appropriate conditions. A step-by-step approach allows detections to be validated against standard signals before the level of stealth is increased. Automated solutions are therefore a valuable ally in this regard, as they offer greater granularity in terms of attack intensity and execution parameters.

(b) Very direct attack paths

Unlike automated solutions that test several variants of an attack, the Red Team follows a precise path, adapting only when an obstacle prevents it from progressing. Once it has reached its objective, it highlights targeted, localised vulnerabilities, offering precise avenues for rectification. However, a real attacker might take a different route, which means that the vulnerabilities discovered do not necessarily cover all possible attack scenarios. To complement this manual approach, BAS’s automated solutions enable you to quickly test several variants of an attack and immediately compare how effectively each is detected.

(c) A penchant for social engineering

Some of Red Team’s operations focus more on social engineering than on technical practices. And yet, Red Team’s expertise is highly sought after when it comes to tackling complex technical issues arising from the behaviour of advanced adversaries; and thus identifying vulnerabilities that go beyond an employee simply clicking on a malicious PDF received by email. The human element remains a critical factor, but it needs to be addressed differently.

(d) Budget optimisation constraints

Although a Red Team is well-equipped, it is carried out by human participants. The time involved is therefore a key factor, and one that the participants seek to optimise. This manual approach imposes certain constraints: it requires rigorous planning, qualified personnel and a significant amount of time to carry out. Nor does it allow for the easy replay of a Red Team campaign to assess changes in the defences deployed. BAS solutions that automate continuous, large-scale testing overcome this limitation. This makes it simpler and less costly to carry out regular control tests.

(e) Towards a hybrid approach

BAS solutions automate the attack (Red) for the benefit of the defence (Blue). They are therefore part of a comprehensive Purple Team approach aimed at assessing and improving detection and response capabilities, as well as training SOC and CERT teams in their investigation and intervention tasks. As MISC magazine points out in its special issue no. 31: «The Purple Team is certainly beneficial for rapidly improving the SOC’s ability to detect the Red Team and better understand the course of attacks». Beyond the cooperation between these dedicated cyber-security teams, exercises conducted with BAS also reinforce processes and reflexes amongst other IT stakeholders, making attack neutralisation faster and more effective.

By implementing a comprehensive Purple Team approach, BAS complements Red Team activities and makes the most of limited budgets by automating tasks. This automation enhances the frequency and depth of security testing, whilst reducing the workload on human teams. Ultimately, this synergy boosts overall security efficiency and the resilience of organisations in the face of modern threats.