Saltar al contenido
02 · Auditoría02 · Auditing

Ejercicio de Red TeamRed Team Exercise

Ataque realista prolongado basado en objetivos concretos.Prolonged, realistic attack driven by specific objectives.

TIBER-EU · MITRE ATT&CKTIBER-EU · MITRE ATT&CK 2.1 · Auditorías Técnicas (Hacking Ético)2.1 · Technical Audits (Ethical Hacking)

¿Qué es este servicio?What is this service?

Es un ejercicio de ataque realista y prolongado, orientado a objetivos concretos y no a encontrar todas las vulnerabilidades posibles. Se combinan vectores técnicos, humanos y a veces físicos, con el equipo defensor sin avisar.

A realistic, extended attack exercise driven by specific objectives rather than by finding every possible vulnerability. It combines technical, human and sometimes physical vectors, with the defending team unaware.

¿Para qué se usa?What is it used for?

Responde una pregunta que un pentest no responde: si un atacante decidido va detrás de la información más valiosa de la organización, ¿lo consigue y alguien lo advierte? El objetivo se define de antemano —llegar a la base de datos de clientes, ejecutar una transferencia, sacar el código fuente— y lo que se mide es si se consiguió y cuánto tardó la organización en verlo.

It answers a question a penetration test does not: if a determined attacker goes after the most valuable information the organisation holds, do they get it and does anybody notice? The objective is defined up front — reach the customer database, execute a transfer, exfiltrate source code — and what gets measured is whether it was achieved and how long the organisation took to see it.

Qué beneficios traeBenefits it delivers

  • Mide la detección y la respuesta de verdad, no en un simulacro anunciado.
  • Encuentra cadenas de ataque completas, que es como ocurren los incidentes reales, en vez de hallazgos sueltos.
  • Da a la dirección una respuesta clara y sin tecnicismos a la pregunta de si estamos preparados.
  • Genera casos de detección concretos para mejorar el SOC, que es donde queda el valor permanente.
  • Genuinely measures detection and response, not in an announced drill.
  • Finds complete attack chains, which is how real incidents happen, instead of isolated findings.
  • Gives management a clear, jargon-free answer to whether the organisation is prepared.
  • Produces concrete detection use cases to improve the SOC, where the lasting value sits.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • No es obligatorio en Costa Rica por ninguna norma general.
  • Para entidades supervisadas puede servir como evidencia robusta de gestión del riesgo tecnológico, pero el Acuerdo CONASSIF 5-24 no lo exige con ese nombre.
  • It is not mandatory in Costa Rica under any general rule.
  • For supervised entities it can serve as strong evidence of technology risk management, but CONASSIF Agreement 5-24 does not require it by that name.

InternacionalInternational

  • DORA exige pruebas de penetración dirigidas por amenazas a las entidades financieras europeas que sean identificadas para ello.
  • TIBER-EU es el marco europeo de referencia para ese tipo de ejercicio.
  • Fuera de esos casos, el red team es voluntario: ningún marco general lo impone.
  • DORA requires threat-led penetration testing from the European financial entities identified for it.
  • TIBER-EU is the European reference framework for that kind of exercise.
  • Beyond those cases, red teaming is voluntary: no general framework mandates it.

Requisitos mínimosMinimum requirements

  • Madurez previa: si no hay capacidad de detección, el ejercicio solo confirma lo evidente y conviene hacer un pentest primero.
  • Objetivos definidos y aprobados por la dirección, con un grupo reducido de personas informadas.
  • Reglas de compromiso muy detalladas y una carta de autorización que el equipo pueda mostrar si lo detienen.
  • Un canal de emergencia para detener el ejercicio si compromete la operación.
  • Prior maturity: without detection capability the exercise only confirms the obvious, and a penetration test should come first.
  • Objectives defined and approved by management, with a small group of informed people.
  • Very detailed rules of engagement and an authorisation letter the team can show if stopped.
  • An emergency channel to halt the exercise if it threatens operations.

Plazo típico de entregaTypical delivery time

6 a 12 semanas 6 to 12 weeks rango habitual del mercado usual market range

El rango habitual del mercado va de seis a doce semanas, contando inteligencia previa, ejecución sigilosa e informe. Es más largo que un pentest a propósito: la lentitud es parte del realismo, porque un atacante real no tiene prisa. Los ejercicios bajo marcos regulatorios pueden extenderse a seis meses o más.

The usual market range runs from six to twelve weeks, covering prior intelligence, stealthy execution and reporting. It is deliberately longer than a penetration test: slowness is part of the realism, because a real attacker is not in a hurry. Exercises under regulatory frameworks can extend to six months or more.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

Red TeamRed Team
El equipo que ataca simulando a un adversario real, con objetivos y sin avisar al defensor. The team that attacks simulating a real adversary, objective-driven and without warning the defenders.
Blue TeamBlue Team
El equipo que defiende, detecta y responde. The team that defends, detects and responds.
MITRE ATT&CKMITRE ATT&CK
Base de conocimiento pública de tácticas y técnicas usadas por atacantes reales. Public knowledge base of tactics and techniques used by real attackers.
TIBER-EUTIBER-EU
Marco europeo para ejercicios de red team dirigidos por inteligencia de amenazas en el sector financiero. European framework for intelligence-led red team exercises in the financial sector.
C2C2
Command and control: la infraestructura desde la que el atacante controla los equipos comprometidos. Command and control: the infrastructure from which the attacker controls compromised machines.
PentestPentest
Prueba de intrusión: se ataca el sistema con autorización previa y por escrito, para encontrar lo que encontraría un atacante real. Penetration test: the system is attacked with prior written authorisation, to find what a real attacker would find.
CVSSCVSS
Escala estándar para puntuar la severidad de una vulnerabilidad, de 0 a 10. Standard scale for scoring vulnerability severity, from 0 to 10.
RoERoE
Reglas de compromiso: el documento que define qué se puede atacar, cuándo, con qué técnicas y a quién avisar. Rules of Engagement: the document defining what may be attacked, when, with which techniques and who to notify.
RetestRetest
Segunda prueba, después de que el cliente corrige, para verificar que la corrección funcionó. A second test after the client remediates, to verify the fix actually worked.