> For the complete documentation index, see [llms.txt](https://106-sam.gitbook.io/ejptv2-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://106-sam.gitbook.io/ejptv2-notes/crto/getting-started/engagement-planning/goal-planning.md).

# Goal Planning

Agreeing on engagement goals can be difficult, especially when either yourself or client is new to red teaming. Some points of discussion could include:

* What ability does a threat have to gain physical and/or remote access ?
* What ability does a threat have to gain elevated (local and/or domain admin) access ?
* What ability does a threat have to move freely throughout a network?
* What ability does a threat have to identify and access sensitive information?
* What ability does a threat have to exfiltrate sensitive data?
* How long can a threat go undetected and what must a threat do to initiate a reaction from the organization?
* What are the potential business impacts a threat could realise?

These goals should be geared towards assessing the concerns of the client i.e. what gaps do they have in their protection of their business assets.
