Red Teams Are Not Paid to Hack Things
If the most valuable thing your red team produces is a successful compromise, you are likely optimizing for the wrong outcome.
Hacking is not the Outcome
Hacking is the activity, not the product. The product is eliminating assumptions and reducing risk.
Security is Built on Assumptions
"We assume EDR will catch this." "We assume this network is isolated."
Each of these assumptions build a mental framework for how engineers and security leadership interact with an environment. Consider this when designing objectives.
Red Team the Assumptions
Red Teaming tests these assumptions through an adversarial lens. When moving towards a particular objective, see if these assumptions hold true. This is the core output of a Red Team.
The goal is not to leave behind a ton of findings. The goal is to remove uncertainty.