Purple Team
A Purple Team combines a Red Team and a Blue Team, allowing insights from attacks to directly improve detection rules.
In a Purple Team, attackers (Red Team) and defenders (Blue Team) collaborate openly. The goal is to test and directly improve detection capabilities step by step.
How it works
The Red Team executes an attack technique, such as reading credentials from memory. The Blue Team observes and checks if an Alert is generated. If not, both teams jointly search for traces in the logs and write a rule. The technique is then repeated until the detection works as intended. These techniques are often selected from the MITRE ATT&CK framework.
For example, a two-day workshop might test 25 techniques commonly used by ransomware groups. Fourteen are detected immediately, six are partially detected, and five are missed completely. New or adapted rules are created for the eleven identified gaps. A retest after four weeks then confirms the improvement.
What to look out for
- Select techniques that are relevant to your threat landscape.
- Test in a realistic environment, not just in a laboratory.
- Document the results for each technique: detected, partially detected, or not detected.
- Schedule a retest to validate the implemented improvements.
Advantages over a Red Team
A Red Team exercise shows whether an attack is detected. A Purple Team also shows why an attack was not detected and fixes the gap immediately. This makes it well-suited for regular, continuous improvement exercises. A Red Team is better for assessing the security state after several improvement cycles.
Typical mistakes
Often, too many techniques are tested in a single session. This leaves insufficient time to close detection gaps properly. Another mistake is writing rules that only match the specific testing tool. They should detect the malicious behaviour, not just a particular file or artefact.
How we implement it
A Purple Team phase is an optional part of our Red Team Assessment, as described on that page. We then translate discovered attack paths into detection rules in the SOC.