Report an Incident Become a Partner Careers Contact
Book a Demo
Offensive security · purple team

What your monitoring
actually sees.

A purple team is not a test you pass or fail. Attackers and defenders work in the same room, techniques are run openly, and the question is not whether we got in — it is what your monitoring saw while we did it.

Exercise · day 2live
T1078Valid accounts, unusual sign-indetected
T1059PowerShell executiondetected
T1114Email collection at volumemissed
T1567Exfiltration to a cloud servicemissed
RULETwo detections written and backtesteddeployed
RERUNSame techniques, same daycaught
What a purple team is

Nothing is hidden,
and that is the point.

A red team exercise is covert: the value is in finding out whether you would notice. A purple team is the opposite, and it is a different purchase entirely.

We run attacker techniques deliberately and announce them as we go, while your monitoring is watched live. Every technique lands in one of three buckets: detected properly, detected but buried in noise, or not seen at all. That list is the deliverable, and it is far more actionable than a report saying somebody got to domain admin.

Because nothing is covert, the loop is short. A technique fires nothing, a detection gets written for it, and the same technique is run again in the afternoon to prove the detection works. Most organisations get more measurable improvement out of two days of that than out of a fortnight of covert testing.

  • Techniques chosen from your threat profile, not from a generic library.
  • Run openly, with your defenders watching the console as it happens.
  • Every technique scored: detected, noisy, or missed.
  • Detections written and backtested during the exercise, not afterwards.
  • Re-run on the same day to prove the gap actually closed.
  • Mapped to MITRE ATT&CK so coverage can be tracked over time.
Red, blue and purple

Three words
for three different purchases.

They get used loosely and sold interchangeably, and the difference decides what you get at the end.

Red

Covert, objective-led

A small team pursues a specific objective without telling your defenders. It answers one question honestly: would you have noticed. The answer is often uncomfortable and always useful, and it is the most expensive of the three.

What you get: a realistic answer about whether you would spot it.

Blue

The defenders

Your security operation: the monitoring, the detections, the people who respond. Not something you buy as an exercise — it is the thing the other two are testing.

What you get: the capability being measured.

Purple

Both, deliberately

Attack and defence working together in the open, technique by technique, with the specific aim of improving detection rather than proving a point. Cheaper than red, faster to produce change, and repeatable.

What you get: measurably better detection, technique by technique.

A useful rule of thumb: buy a purple team when you want your detection to get better, and a red team when you want to know how good it already is. Doing the covert one first usually just buys you an expensive list of things a purple team would have found in two days.

Why it matters who runs it

Most purple teams
are only half a team.

The exercise needs attackers and defenders. Almost every firm selling one brings the red half and expects you to supply the blue.

That works if you have a mature security operation with engineers who can write and deploy a detection the same afternoon. If you do not, the exercise degrades into a red team with commentary: techniques get run, gaps get listed, and the improvement half never happens because nobody in the room can build it.

We run a 24/7 SOC and write detection content as a standing job, so we can staff both sides. When a technique goes unseen, the detection is written, backtested and deployed during the exercise by somebody who does that for a living — and then the technique is run again to prove it fires.

How our SOC writes detections

Detection engineers in the room
Not a tester describing what a detection should look like, but somebody who writes them for production estates every week.
Written against your estate
Tuned to your data sources and your noise, and backtested against your history before deployment rather than pasted from a public rule set.
Proved before anyone leaves
The same technique re-run after the detection is deployed. A gap is only closed when something fires.
Coverage you can track
Mapped to MITRE ATT&CK, so the next exercise measures movement rather than starting the argument again.

If you have your own detection engineers, bring them — the exercise is better with them in the room and we will happily be only the red half.

How it runs

Two or three days,
and a list that moves.

Short, structured and repeatable. The point is change, so the exercise is built around producing it rather than documenting it.

  1. 01

    Pick the techniques

    Drawn from your threat profile, your sector and what is actually being used against organisations like you, rather than working through a library alphabetically.

  2. 02

    Set up the room

    Your defenders on the monitoring, our testers on the keyboard, everybody able to see both. Remote works; in person works better.

  3. 03

    Run and score

    Technique by technique, each one scored detected, noisy or missed, with the telemetry that did or did not appear recorded at the time.

  4. 04

    Close the gaps

    Detections written and backtested for what was missed, and tuning for what fired but drowned. This is the half that makes the exercise worth buying.

  5. 05

    Re-run and report

    The same techniques again to prove the changes work, then a coverage map against MITRE ATT&CK and a plain list of what changed.

Questions

Purple team, answered.

What is the difference between a red team and a purple team?

A red team is covert and objective-led: it tells you whether you would have noticed. A purple team is open and technique-led: attack and defence work together to make detection better. Red measures where you are. Purple moves you.

What is a purple team exercise?

A facilitated session where attacker techniques are run deliberately and announced, while your monitoring is watched. Each technique is scored detected, noisy or missed, detections are written for the gaps, and the techniques are re-run to prove the gaps closed.

How long does one take?

Usually two or three days for a focused set of techniques, plus scoping beforehand and a coverage report afterwards. Longer engagements exist but tend to produce diminishing returns; running a shorter exercise twice a year beats one long one.

Do we need our own detection engineers?

No. That is the half most providers expect you to bring, and where exercises usually stall. We staff both sides, so detections for anything missed are written and deployed during the exercise. If you do have engineers, bring them — it works better with them there.

Do we need a red team first?

Usually the opposite. A covert exercise against an estate with known detection gaps mostly buys an expensive confirmation of those gaps. Close what a purple team finds first, then a red team tells you something you did not already know.

Is it safe to run in production?

Techniques are selected and agreed with you beforehand, and anything with real operational risk is either simulated or run in a window you control. The rules of engagement are written down before anything is executed.

What do we get at the end?

A technique-by-technique score, the detections written during the exercise, the tuning applied to noisy rules, a MITRE ATT&CK coverage map and a plain list of what changed. The detection content is yours either way.

How often should we run one?

Twice a year suits most organisations, and after anything that changes the estate materially — a migration, an acquisition, a new platform. Coverage decays quietly as products update and rules get tuned, so the value is in the trend.

Where to start

Two days, and a list
that actually moves.

Tell us what you are worried about and we will pick the techniques from your threat profile rather than working through a library. Scoping is a conversation, not a form.