Resources / Checklists /
Compliance / GRC
DOCX

C-Suite Red Team Engagement Checklist: A Full Kill-Chain Methodology

More than 330 red team tasks across 13 stages, from signed Rules of Engagement to post-report quality assurance, so a security leader knows exactly what an adversary simulation involves.
Format:
DOCX
Last updated:
September 15, 2026
Read time:
5
min
Talk to an Expert
White arrow pointing diagonally upward to the right on a black square background.White arrow pointing diagonally upward to the right on a black square background.

A red team engagement is not a penetration test with a scarier name. It is a goal-driven adversary simulation across the full kill chain, from reconnaissance to exfiltration, cleanup, and reporting. This checklist lays out that methodology as a task list a C-suite sponsor can read and a red team can execute against.

Every row is one task, grouped by phase, with its specific subtasks and techniques. It starts before any packet is sent, with scope authorization and infrastructure setup, and ends after the report, with cleanup, MITRE ATT&CK mapping, and quality assurance.

Key Takeaways

  • The engagement is authorized before it begins: Pre-Engagement covers Rules of Engagement, scope boundaries, off-limits systems, testing windows, and 24/7 escalation contacts.
  • Reconnaissance and Intelligence Gathering is the largest phase at 73 tasks, spanning OSINT, technical recon, web application assessment, cloud, and wireless.
  • Initial access is tested across every realistic vector: phishing, vishing, smishing, and 30 physical and perimeter tasks including badge cloning, tailgating, lock bypass, and CCTV blind spots.
  • The methodology does not stop at exploitation. It includes evasion and anti-forensics, cleanup and system restoration, MITRE ATT&CK mapping, and a quality assurance phase that validates findings before the report ships.

What's Inside

Every row is one task, grouped into the 13 phases of a red team engagement.

  • Pre-Engagement and Planning: scope authorization, team structure, attack infrastructure.
  • Reconnaissance and Intelligence Gathering: OSINT, technical recon, web, cloud, and wireless.
  • Initial Access and Weaponization: phishing, vishing, smishing, physical and perimeter.
  • Initial Access in the Network: NAC bypass, MitM bridging, host discovery, foothold recon.
  • Active Directory Kill Chain Execution: Kerberos attacks, NTLM relay, privilege escalation, lateral movement, persistence, credential access.
  • Post-Exploitation and Data Exfiltration, Command and Control, Evasion and Anti-Forensics.
  • Documentation and Evidence Collection, Cleanup and Remediation, Reporting and Analysis.
  • MITRE ATT&CK Mapping and Quality Assurance and Validation.

Each task carries the specific subtasks, techniques, or tooling that define it.

How to use it

01
Pick your phase. Filter to the phase you are planning or reviewing, or read all 13 for the complete methodology.
02
Read the task and its subtasks. Each row names the task and the specific techniques or details it covers.
03
Use it to scope and govern. As a sponsor, use the phases to define what is in and out of scope; as a red team, use it as the running checklist for the engagement.
04
Planning an adversary simulation? Payatu's red team runs this methodology as a scoped engagement mapped to your crown-jewel assets. Talk to a Payatu red team lead about scope.
Subscribe to our newsletter
Reviewed by
Red circular logo with four overlapping curved segments forming a hollow diamond shape at the center.
Red Team Researchers