A Red Team operation gives you a list of "things we need to do." A Purple Team, by contrast, is a learn-by-doing-together session — our offensive team works in the same room as your SOC and defense team.
How it works
- Scenario selection — MITRE ATT&CK techniques tailored to your sector
- Controlled attack — applied unit by unit, step by step
- Real-time detection measurement — what did your SOC see, what did it miss?
- Gap analysis — why was it missed: log, rule, or capability?
- Remediation in place — fix the rule, retest
Typical techniques
- T1059 — Command interpreter abuse
- T1055 — Process injection
- T1078 — Valid account use
- T1486 — Data encryption (ransomware)
- T1071 — C2 over standard application protocols
Deliverables
- MITRE ATT&CK heat-map (detection coverage percentage)
- List of detection rules that were fixed
- Technical capability uplift report for your SOC team