methodatlas
Session Builder

Plan my session

Plan a concrete work block with agenda, roles, preparation, and a copyable result artifact.

Method session1-2 days (1 day preparation, 4-8 h workshop)WorkshopChallenge Findings

Session: Red Teaming

The plan translates the method into a concrete facilitated work block. Your inputs flow directly into the session brief and work artifact.

Derived automatically

Method session with 3-8. The plan uses the existing method logic and the runsheet.

Runsheet
Participation logic
Team round, shared work and alignment

Use the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.

Outcome logic
Finish artifact

The session works directly toward Challenge Findings. After the session, the artifact should be shareable, reviewable, or reusable.

  1. 1

    Phase 1: Red Team preparation

    4-8 h

    Red Team studies the artifact. Generates attack tree or list. Per attack: vector, required capabilities, effect, probability, existing mitigation. Hint: Red Team needs time and distance. Without preparation, Red Teaming becomes discussion round. External people are often more creative than internal ones.

    FacilitatorChallenge Findings
  2. 2

    Phase 2: Context and rules

    30 min

    Moderator briefly presents artifact. Red Team and original team ask understanding questions. Rules clear: original team listens, answers facts, does not defend. Hint: Defense reflex is the most common method error. Clear rule: discussion only in Phase 4.

    FacilitatorRisk Register
  3. 3

    Phase 3: Attack presentation

    2-3 h

    Red Team presents attacks systematically. Per attack: vector, scenario, effect. Original team asks only for understanding, not rebuttal. Hint: If original team interrupts and defends, moderator interrupts back. Presentation must be complete before evaluation starts.

    FacilitatorMitigation Plan
  4. 4

    Phase 4: Evaluation and prioritization

    90 min

    Per attack, evaluate effect, probability and mitigation effort. Original team adds context that changes probability. Top attacks go to risk register as risks. Hint: Probability is subjective. Consensus is not required, but rationale must be documented.

    FacilitatorChallenge Findings
  5. 5

    Phase 5: Mitigations and follow-ups

    60-90 min

    Sketch mitigation per top attack (prevention, detection, response). Owner and deadline. Log changes to artifact. Hint: Mitigation must be concrete. "More monitoring" without detail is not mitigation. Owner mandatory.

    OwnerRisk Register
  6. 6

    Publish artifact

    10 min

    Check the artifact for completeness, define location, set version or status, and name review recipients.

    OwnerChallenge Findings
Usable artifact

Session Brief

For invitations, boards, tickets, PR descriptions, or workshop notes.

session-brief.md

Session Brief: Red Teaming

Goal

Artifact: Challenge Findings

Working Question

Which attack vectors, weaknesses or entry paths overcome the artifact, and which of these vectors are likely enough to justify mitigation?

Context

Provide artifact 2-3 days before workshop; clarify context and assumptions; known attack patterns in domain (security: OWASP; business: competitor moves); time limit for Red Team preparation.

Setup

  • Format: Method session
  • Duration: 1-2 days (1 day preparation, 4-8 h workshop)
  • Mode: Workshop
  • Participants: One Red Team (3-5 people), ideally external to the original team; one original-team representative for understanding questions (not defense); one moderator; one scribe.
  • Owner: One Red Team (3-5 people), ideally external to the original team
  • Participation mode: Team round, shared work and alignment
  • Outcome logic: Finish artifact

Participation Logic

Use the session for shared understanding. Contributions are collected visibly, assumptions are aligned, and open differences remain traceable in the artifact.

Outcome Logic

The session works directly toward Challenge Findings. After the session, the artifact should be shareable, reviewable, or reusable.

Input

Complete documents for the artifact (strategy, architecture, plan); whiteboard or Miro with attack table (attack vector, effect, probability, mitigation); STRIDE/PASTA templates for security if needed.

Preparation

Red Team works autonomously on attack strategies before workshop. Workshop has clear rules: original team does not defend, but listens and notes. Q&A only after complete presentation.

Agenda

  1. Phase 1: Red Team preparation (4-8 h) Owner: Facilitator Action: Red Team studies the artifact. Generates attack tree or list. Per attack: vector, required capabilities, effect, probability, existing mitigation. Hint: Red Team needs time and distance. Without preparation, Red Teaming becomes discussion round. External people are often more creative than internal ones. Output: Challenge Findings

  2. Phase 2: Context and rules (30 min) Owner: Facilitator Action: Moderator briefly presents artifact. Red Team and original team ask understanding questions. Rules clear: original team listens, answers facts, does not defend. Hint: Defense reflex is the most common method error. Clear rule: discussion only in Phase 4. Output: Risk Register

  3. Phase 3: Attack presentation (2-3 h) Owner: Facilitator Action: Red Team presents attacks systematically. Per attack: vector, scenario, effect. Original team asks only for understanding, not rebuttal. Hint: If original team interrupts and defends, moderator interrupts back. Presentation must be complete before evaluation starts. Output: Mitigation Plan

  4. Phase 4: Evaluation and prioritization (90 min) Owner: Facilitator Action: Per attack, evaluate effect, probability and mitigation effort. Original team adds context that changes probability. Top attacks go to risk register as risks. Hint: Probability is subjective. Consensus is not required, but rationale must be documented. Output: Challenge Findings

  5. Phase 5: Mitigations and follow-ups (60-90 min) Owner: Owner Action: Sketch mitigation per top attack (prevention, detection, response). Owner and deadline. Log changes to artifact. Hint: Mitigation must be concrete. "More monitoring" without detail is not mitigation. Owner mandatory. Output: Risk Register

  6. Publish artifact (10 min) Owner: Owner Action: Check the artifact for completeness, define location, set version or status, and name review recipients. Output: Challenge Findings

Closeout

  • Update result artifact: Challenge Findings
  • Define location, version, and review recipients.
  • Define owner, next step, and review date.
Usable artifact

Work artifact

Pre-filled starting point based on the matching template.

work-artifact.md

Challenge Findings: Red Teaming

Working Question

Which attack vectors, weaknesses or entry paths overcome the artifact, and which of these vectors are likely enough to justify mitigation?

Context

Provide artifact 2-3 days before workshop; clarify context and assumptions; known attack patterns in domain (security: OWASP; business: competitor moves); time limit for Red Team preparation.

Participants

  • Owner: One Red Team (3-5 people), ideally external to the original team
  • Participants: One Red Team (3-5 people), ideally external to the original team; one original-team representative for understanding questions (not defense); one moderator; one scribe.

Input

Complete documents for the artifact (strategy, architecture, plan); whiteboard or Miro with attack table (attack vector, effect, probability, mitigation); STRIDE/PASTA templates for security if needed.

Template

Red Teaming Working Template

Goal

Challenge assumptions, expose weak spots, and strengthen the plan, strategy, or design.

Context

When and for what do we use this method?

Input

Which data, observations, decisions, or materials are available?

Working area

  • Scope:
  • Attack points:
  • Weak assumptions:
  • Findings:
  • Mitigations:

Output artifacts

  • Challenge notes:
  • Risk register:
  • Mitigation plan:

Open questions

  • ...

Next step

Owner, date, and success signal.

Completion Check

  • Challenge Findings is complete enough for review:
  • Location:
  • Version / status:
  • Review by:
  • Next step:

Next Step

  • Review result
  • Mark open questions
  • Schedule review or decision
Template base

Red Teaming Working Template

View templateCompact working template for Red Teaming with challenge scope, attack points, findings, and mitigations.
markdown

red-teaming-working-template.md

Compact working template for Red Teaming with challenge scope, attack points, findings, and mitigations.

Red Teaming Working Template

Goal

Challenge assumptions, expose weak spots, and strengthen the plan, strategy, or design.

Context

When and for what do we use this method?

Input

Which data, observations, decisions, or materials are available?

Working area

  • Scope:
  • Attack points:
  • Weak assumptions:
  • Findings:
  • Mitigations:

Output artifacts

  • Challenge notes:
  • Risk register:
  • Mitigation plan:

Open questions

  • ...

Next step

Owner, date, and success signal.

Ready to use when
  • Working question, owner, and target artifact are visible.
  • The result fits Challenge Findings.
  • One entry per Red Team session with date and artifact version. Mitigations tracked separately over time. New Red Team run for major changes to artifact.
  • Open questions are noted as follow-ups.
  • The next review or decision point is scheduled.