A red team operation tells you what the defenders missed. A purple team exercise makes sure they do not miss it again. Attackers and defenders sit at the same table: a technique is executed, the defenders look for it in their tools, and if it is not there, a rule is written and the technique is executed again.
The exercise is built from the techniques of the adversaries relevant to your sector. Nothing is hidden and nobody is scored. Success is measured by the number of techniques that went from invisible to detected while the exercise lasted.
01Scope
What we test
Selection of techniques used by the adversaries relevant to your sector
Execution on workstations, servers, identity systems and cloud
Telemetry: whether the activity is recorded at all
Detection: whether a rule fires, how late and with what context
Response: triage, containment, escalation
Tuning of rules and reduction of false positives
Test scripts handed over for regression
02Approach
How the work is done
01
Planning
Adversaries and techniques are selected together with your defenders. The environment is agreed: production systems with production telemetry wherever possible.
02
Execution
Techniques are executed one at a time and announced in advance. Destructive effects are simulated, never produced.
03
Detection review
After each technique the defenders check what their tools recorded. Missing telemetry and missing rules are fixed on the spot and the technique is repeated.
04
Report
A coverage matrix shows every technique before and after the exercise, with the rule that now detects it.
Structure of threat-led red team tests: threat intelligence, red team phase, closure.
European Central Bank
06Questions
Questions about this service
How does it differ from a red team operation?
A red team operation is covert and driven by an objective; it tests the organisation as a whole. A purple team exercise is open and driven by techniques; it improves detection. The exercise often follows an operation to close the gaps the operation found.
Monitoring is outsourced to a provider. Can they take part?
Yes, and they should. The exercise shows what your provider actually sees, which is rarely visible from the contract.
Is the exercise run in production?
Where possible, because that is where detection has to work. Techniques are selected and configured so that they cause no harm; anything destructive is simulated.