Red team refers to attackers simulating real-world threats; blue team refers to defenders detecting and responding to those simulated attacks.
Red team vs. blue team exercises test an organization's real detection and response capability under realistic conditions, often revealing gaps that theoretical reviews miss.