CYBER THREAT INTELLIGENCE BASED SCOPING OF RED TEAM EXERCISES

Authors

  • Svilen Kamdzhalov IT Department, Nikola Vaptsarov Naval Academy, Varna, Bulgaria
  • Dimitar Nikolov IT Department, Nikola Vaptsarov Naval Academy, Varna, Bulgaria https://orcid.org/0009-0002-8022-9077

DOI:

https://doi.org/10.68302/std2026.vol3.210

Keywords:

Asset classification, contextualized threat intelligence, penetration testing, red team assessments, threat modeling

Abstract

One of the most effective ways to test a company's security posture  is through red team assessments and targeted penetration testing. This article defines one of the most effective approaches for determining the scope of the tests and the stages they go through. The stages include getting to understand the potential attackers, their tactics, techniques and procedures, the modus operandi and the objective with which they operate. The paper also discusses the importance of people, business processes, technology and distinguishing between important and critical assets as part of effective testing. It discusses the best tool for proper scoping is contextualized threat intelligence based analysis and red team assessment frameworks such as TIBER-EU, CBEST and iCAST. This paper describes an approach that can be used to improve the scoping of the mentioned tests and hence increase their value.

Supporting Agencies

This research paper has received funding from Ministry of Education and Science of the Republic of Bulgaria under the National Science Program "SECURITY AND DEFENCE", in implementation of the Decision of the Council of Ministers of the Republic of Bulgaria No: 731/21.10.2021 and according to Agreement No: D01-74/19.05.2022.

Downloads

Download data is not yet available.

References

[1] TechRound, "History of Red Team Exercises." [Online]. Available: https://techround.co.uk/guides/history-red-team-exercises/ [Accessed: March 23, 2026].

[2] Mandiant, "APT1: Exposing One of China's Cyber Espionage Units," 2021. [Online]. Available: https://www.mandiant.com/sites/default/files/2021-09/mandiant-apt1-report.pdf[Accessed: March. 23, 2026].

[3] MITRE ATT&CK, "ATT&CK Framework." [Online]. Available: https://attack.mitre.org/[Accessed: March 26, 2026].

[4] Fortinet, "Red Team Assessment Solution Guide." [Online]. Available: https://www.fortinet.com/content/dam/fortinet/assets/solution-guides/sb-red-team-assessment.pdf [Accessed: March 22, 2026].

[5] CREST, "CBEST Framework." [Online]. Available: https://www.crest-approved.org/membership/cbest/ [Accessed: March 23, 2026].

[6] European Central Bank, "TIBER-EU Red Team Test Plan Guidance," 2025. [Online]. Available: https://www.ecb.europa.eu/pub/pdf/annex/ecb.tiber_red_team_test_plan_guidance_2025.en.pdf [Accessed: March 26, 2026].

[7] Association of Banks in Singapore, "Red Team: Adversarial Attack Simulation Exercises Guidelines." [Online]. Available: https://abs.org.sg/docs/library/abs-red-team-adversarial-attack-simulation-exercises-guidelines-v1-06766a69f299c69658b7dff00006ed795.pdf [Accessed: March 25, 2026].

[8] Hong Kong Monetary Authority, "Intelligence-Led Cyber Attack Simulation Testing (iCAST)." [Online]. Available: https://www.hkma.gov.hk/media/eng/doc/key-information/speeches/s20160518e2.pdf [Accessed: March 28, 2026].

[9] G7, "Fundamental Elements for Threat-Led Penetration Testing," 2018. [Online]. Available: https://www.ecb.europa.eu/paym/pol/shared/pdf/October_2018-G7-fundamental-elements-for-threat-led-penetration-testing.en.pdf [Accessed: March. 26, 2026].

[10] Global Financial Markets Association, "Threat-Led Penetration Testing Guidance." [Online]. Available: https://www.gfma.org/wp-content/uploads/0/83/197/231/fff190cf-305a-44a6-a429-39848f22a48b.pdf [Accessed: March 28, 2026].

[11] Z. Wang, O. D. Adeyemo and E. A. Akinsoto, "Summary of Cyber Threat Intelligence," Int. J. Innov. Res. Multidiscip. Field, Vol. 8, № 3, Mar. 2022. [Online]. Available: https://www.ijirmf.com/wp-content/uploads/IJIRMF202203006.pdf [Accessed: March. 28, 2026].

[12] R. Brown and R. M. Lee, "The Evolution of Cyber Threat Intelligence (CTI): 2019 SANS CTI Survey," SANS Institute, 2019. [Online]. Available: https://www.sans.org/white-papers/38790/ [Accessed: Apr. 02, 2026].

[13] Google Cloud, "Hands-On Introduction to Mandiant Approach to OT Red Teaming." [Online]. Available: https://cloud.google.com/blog/topics/threat-intelligence/hands-on-introduction-to-mandiant-approach-to-ot-red-teaming [Accessed: Apr. 02, 2026].

[14] SANS Institute, "ICS Cyber Kill Chain." [Online]. Available: https://icscsi.org/library/Documents/White_Papers/SANS%20-%20ICS%20Cyber%20Kill%20Chain.pdf [Accessed: Apr. 02, 2026].

[15] Cybersecurity and Infrastructure Security Agency, "Red Team Assessment Reveals Key Cybersecurity Gaps in Critical Infrastructure Organization." [Online]. Available: https://industrialcyber.co/cisa/cisa-red-team-assessment-reveals-key-cybersecurity-gaps-in-critical-infrastructure-organization/ [Accessed: March 28, 2026].

[16] MITRE, "APT3 Adversary Emulation Plan." [Online]. Available: https://attack.mitre.org/docs/APT3_Adversary_Emulation_Plan.pdf [Accessed: March 30, 2026].

[17] Hong Kong Monetary Authority, "Cyber Resilience Assessment Framework (C-RAF)," 2016. [Online]. Available: https://uploads-ssl.webflow.com/59d28ad983887e000196f803/5fecc1fe13498132b4fa835b_HKMA%20CFI%20-%20Cyber%20Resilience%20Assessment%20Framework%20-%20Dec%202016.pdf [Accessed: Apr. 02, 2026].

[18] MITRE ATT&CK, "APT Group G1017." [Online]. Available: https://attack.mitre.org/groups/G1017/ [Accessed: Apr. 02, 2026].

[19] D. Dimitrov and E. Andreev, "China's Strategic Competition in Cyberspace: Volt Typhoon and Salt Typhoon as a Projection of Power, a More Aggressive Posture and a Future Beyond Espionage," Environment. Technology. Resources. Proceedings of the International Scientific and Practical Conference, vol. 2, pp. 115–122, 2025. Available: https://doi.org/10.17770/etr2025vol2.8618 [Accessed: March 26, 2026].

[20] Cybersecurity and Infrastructure Security Agency, "Cybersecurity Advisory AA24-038A." [Online]. Available: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a [Accessed Apr. 04, 2026].

[21] Office of the Superintendent of Financial Institutions, "Intelligence-Led Cyber Resilience Testing (I-CRT) Framework." [Online]. Available: https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/osfis-intelligence-led-cyber-resilience-testing-crt-framework[Accessed: Apr. 04, 2026].

[22] NVISO Labs, "Attack and Defense in OT: Enhancing Cyber Resilience in Industrial Systems with Red Team Operations," Feb. 28, 2025. [Online]. Available: https://www.osfi-bsif.gc.ca/en/guidance/guidance-library/osfis-intelligence-led-cyber-resilience-testing-crt-framework [Accessed Apr. 02, 2026].

Downloads

Published

17.09.2026

How to Cite

[1]
S. Kamdzhalov and D. Nikolov, “CYBER THREAT INTELLIGENCE BASED SCOPING OF RED TEAM EXERCISES”, SysTechDev, vol. 3, pp. 115–119, Sep. 2026, doi: 10.68302/std2026.vol3.210.