skip to content

Designing the Exercise

Picking the instrument and the technique set before anything runs, and the paperwork that stops a test becoming a real incident. Interviewers start here because scope decides what a test can prove.

on this pageshow

explore

questions

12

In a red-team engagement, what is a deconfliction contact and what question do they exist to answer?

level: juniorimportance: must knowfreq 58%

answer

  1. a phone number, not a document
  2. answers one question: was that you?
  3. attribution, never permission
  4. flows in both directions
  5. reachable at 02:00, out of band

basics

~20 s

A named, reachable person on each side of the exercise whose job is to answer one question fast: is this specific activity ours? They attribute or disown observed behaviour. They do not authorise it and they do not order a stand-down.

solid answer

~50 s

Deconfliction is the pre-agreed channel that lets either side ask "was that you?" and get an answer in minutes. An engagement names at least two humans: someone on the red team who holds the operator log and can account for activity, and someone inside the client — usually the exercise sponsor or a trusted agent — who knows the exercise is real and holds the signed authorisation. Both have named alternates and out-of-band phone numbers recorded before the exercise starts, because mail and chat may be the very systems the response has just isolated. Their answer is an attribution: this host, this command, this source address at this time was ours, or it was not. It flows both ways — operators call in when they think they have tripped something expensive or stumbled on a real intruder.

go deeper

for a junior

Be ready to say plainly what a deconfliction contact is: a named human, reachable out of band, who answers whether specific observed activity belongs to the exercise. Know that their answer identifies an actor and does not authorise anything.

for a middle

Explain the mechanics: two contacts plus alternates, details exchanged before the exercise, out-of-band numbers, and an attribution given per host and per timestamp rather than as a blanket "we are testing".

for a senior

Show that you would run the call defensively — call back on a pre-recorded number, ask for details you never disclosed, keep containment until the attribution is specific, and record the whole exchange in the case.

for a principal

Own where the role sits: who in the organisation is a trusted agent, how the SOC reaches them at 03:00, and how you keep that group small enough to preserve the exercise's value while large enough that the estate never gets stuck with an unreachable contact.

## What deconfliction is for An adversary-emulation exercise deliberately puts activity into a production estate that looks, to every sensor and every analyst on shift, exactly like an intrusion. That is the point: if it did not look like one, it would prove nothing. The consequence is that at some hour of some night a defender will be holding evidence they cannot distinguish from a real compromise. **Deconfliction** is the mechanism agreed in advance for answering, quickly and authoritatively, one question about any observed activity: *was that us?* ## The people - **A red-side contact.** An operator or engagement lead who holds the operator log — every host touched, every command run, every source address, with timestamps — and who is reachable for the whole engagement window, not only in business hours. - **A client-side contact.** Usually the exercise sponsor or a designated trusted agent: someone who knows the exercise exists, holds the signed authorisation, and can confirm to a defender that an exercise is genuinely running. This person exists because the red team vouching for its own legitimacy is the weakest possible check. - **Named alternates for both.** One contact with one phone is a single point of failure in the middle of the night, and the failure is expensive: the SOC keeps escalating, wakes an executive, and dials the incident-response retainer whose clock starts on the call. ## Out of band, and recorded in advance Contact details are exchanged before the exercise begins and must not depend on anything in scope. A response can include isolating laptops, disabling accounts, or blocking a mail tenant — so the chat channel or mailbox you planned to use may be precisely what has just been cut off, or may be considered compromised and therefore untrusted. Phone numbers, and a copy in the SOC's own runbook that survives the estate going dark, are the normal arrangement. ## What the answer is, and what it is not The answer is an **attribution**: "yes, at 02:07 our operator ran that on DC02 from 10.4.1.19", or "no, that is not ours." Three things it is not: 1. **Not authorisation.** Permission to run the exercise comes from the signed scope letter and the person with authority over the systems. A deconfliction contact confirms who did something; they do not make it lawful. 2. **Not a stop order and not a close order.** What the defenders do next — release a host, keep hunting, close the case — is the client's decision, taken with their own leadership. 3. **Not a blanket.** "We are testing this week" attributes nothing. A useful answer is per-activity: the host, the timestamp, the process, the account, the source address. ## It runs in both directions Defenders call the red team when an alert might be test traffic. Operators call the client when they believe they have caused harm beyond what was expected, when access has reached something outside scope, when they see evidence of a **real** intruder in the estate, or when they think they have just triggered an expensive response. "We think we have just cost you a retainer callout" is a legitimate deconfliction call, and a mature red team makes it unprompted. ## Why the defender should ask for detail and give none A claim of authorisation is itself a social-engineering technique — "don't worry, that's the red team" is a cheap thing for an intruder to say. So the strong form of deconfliction is the operator stating facts the defender has *not* disclosed: the exact command line, the file written, the account used. The defender's side of the call is questions, not disclosures. And the verification chain has to root in something trusted before the exercise: a number recorded in the runbook, a person whose voice is known, the sponsor — never a callback number offered by the caller. ## Write the call down The call belongs in the case record: who called whom, on which recorded number, at what time, which specific activity was attributed to the exercise and which was not. That record is what turns a 02:00 stand-down into a defensible closure, and it is what the engagement report gets reconciled against afterwards. It also preserves the honest outcome for the exercise itself: the detection fired, the analyst worked it correctly, and only the actor turned out to be authorised.

  • Why must the deconfliction number be out of band rather than a corporate mail alias or chat channel?
    Because the response may have isolated or blocked exactly those systems, and because anything inside a possibly compromised estate is untrusted while the verdict is open. A recorded phone number survives host isolation, account disablement and a distrusted mail tenant, and it gives voice recognition as a weak but real second factor that an alias does not.
  • The red-team contact cannot account for the activity the SOC describes. What has just happened?
    The exercise has just converted a suspected test into an unattributed intrusion, and "not ours" is the highest-value answer a deconfliction contact ever gives. The client's responders keep the case live, keep containment in place and preserve evidence; whether the exercise continues alongside a real investigation is the sponsor's call, not the operators'.
  • Who inside the client organisation should hold the deconfliction role?
    Someone who knows the exercise is running, holds or can reach the signed authorisation, has authority to speak for the sponsor, and has a named 24x7 alternate. Practically it is a small trusted-agent group rather than one person, and the escalation path from the SOC to that group is written down before the exercise starts rather than improvised at 02:00.

It is the range-safety phone at a live-fire exercise: it does not grant permission to shoot and it cannot order a cease-fire, it exists so that anyone hearing a bang can find out in seconds whether it was one of ours.

saying these in an interview costs you the question

  • Thinks the deconfliction contact authorises the test
  • Treats a caller's claim as verification with no callback
  • One contact, no alternate, business hours only
  • Assumes deconfliction only flows from defenders to operators
  • Accepts "we are testing this week" as an attribution
  • Leaves the deconfliction call out of the case record

context

open as a page

A vulnerability scan, a pentest and a red team engagement all test security — what does each actually prove?

level: juniorimportance: must knowfreq 76%

basics

~20 s

A scan proves a weakness is present. A pentest proves an operator could exploit it and how far the chain reaches. A red team proves whether your defenders detect and stop a realistic path to an objective.

open as a page

Why derive an emulation technique set from a threat profile rather than a popularity list?

level: juniorimportance: must knowfreq 68%

basics

~20 s

A popularity list tests the techniques other organisations happen to report; a threat profile tests the ones the adversary interested in you actually uses. Only the second supports a claim about the intrusion you are likely to face.

open as a page

When do you choose atomic single-technique tests over one full-chain emulation campaign?

level: middleimportance: must knowfreq 57%

basics

~20 s

Choose atomic tests when the question is which behaviours you can see, because each result is isolated and diagnosable. Choose a chained campaign when the question is whether people and process turn a realistic sequence into a verdict.

open as a page

A caller says the 02:00 credential-theft alert on your domain controller is red-team activity. How do you verify it?

level: seniorimportance: must knowfreq 50%

basics

~20 s

Treat the claim as unverified until a callback on a pre-recorded number produces a per-activity attribution: this host, this command, this time, this source. Keep containment and evidence collection running while you verify, and reopen anything the operators cannot account for.

open as a page

What must a signed red-team authorisation letter contain for a SOC analyst to act on it at 02:00?

level: middleimportance: should knowfreq 55%

basics

~20 s

Two halves: the legal core — a signatory with authority, in-scope and explicitly out-of-scope systems, a dated window, prohibited actions — and fields a defender can check an alert against: operator source addresses, test markers, out-of-band deconfliction numbers.

open as a page

What is an assumed-breach start, and which detections can it never test compared with earned initial access?

level: middleimportance: should knowfreq 58%

basics

~20 s

An assumed-breach engagement begins with the operator already holding a foothold or valid credentials, so everything up to initial access is skipped. The edge and phishing detections are never exercised, and their silence proves nothing about them.

open as a page

A threat report says the crew phishes OAuth consent for mail-read scope. What turns that into an executable test?

level: middleimportance: should knowfreq 44%

basics

~20 s

A named behaviour is a class, not a test. You must add the procedure: which application, which permission scope, which consent path, which target identity, plus the observable you expect and the criterion that decides pass or fail.

open as a page

An unannounced red team met its objective and no alert ever fired — what does that report actually prove?

level: seniorimportance: should knowfreq 46%

basics

~20 s

It proves one path to the objective existed and went unnoticed by the rules and people on duty that week. It does not say which stage failed, and it measures nothing the operator never attempted.

open as a page

A red-team report says every test artefact was removed. What do you require before accepting that?

level: seniorimportance: nice to knowfreq 34%

basics

~20 s

An itemised inventory of everything planted — files, persistence, accounts, credentials, exclusions — each with host, identifier and evidence of removal; then your own hunt for every item. What you cannot find is a visibility gap.

open as a page

Your SIEM does not ingest the identity provider's consent-grant audit log - do you still emulate that technique?

level: seniorimportance: nice to knowfreq 31%

basics

~20 s

Usually no. Executing a behaviour whose only observation surface is uncollected buys a miss you already predicted. The gap is the finding, recorded at design time, and the slot goes to a technique that can discriminate.

open as a page

One annual red team or continuous automated validation: which do you buy for a one-analyst SOC with an MSSP?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Buy continuous validation first while the detection baseline is unknown: it attributes each miss and catches regressions. Buy the red team once the basics reliably alert, so the engagement spends its money on what automation cannot test.

open as a page