
A practical guide to planning and executing purple team exercises that actually improve your security.
Traditional pentests work in isolation, attackers find weaknesses, write a report, hand it off. Purple teaming brings offensive and defensive teams together in real-time. The goal isn't just to find gaps; it's to close them during the engagement.
A purple team exercise typically runs for 1-3 days. Attackers execute techniques while defenders watch, detect (or don't), and immediately tune their defences. By the end, you've not only identified gaps but fixed many of them.
Start with relevant threats. Who targets your industry? What techniques do they use? MITRE ATT&CK maps threat groups to TTPs.
| Industry | Threat Groups |
|---|---|
| Financial Services | FIN7, Carbanak |
| Healthcare | Ryuk, Conti |
| Manufacturing | APT41 |
Individual techniques matter less than realistic chains. Attackers don't run one technique in isolation, they chain multiple stages together.
Phishing → Macro execution → PowerShell download → Persistence via scheduled taskValid credentials → RDP → Kerberoasting → Domain adminDomain admin → DCSync → Golden ticket → Data exfiltrationBefore the exercise, document what you expect to detect. This becomes your scorecard.
The war room: attackers and defenders together, learning in real-time.
Everyone sits together: attackers and defenders in the same room. The attacker announces they're about to execute a technique, runs it, then pauses. Did the SOC see it? Did an alert fire? If not, why not?
| Record | Details |
|---|---|
| Technique | ID, description, exact command/tool used |
| Timestamp | When the technique was executed |
| Detection Result | Detected / Partially detected / Missed |
| If Detected | Which alert fired, how quickly |
| If Missed | Why (missing logs, no rule, rule didn't trigger) |
| Remediation | Action taken during exercise |
When detection fails, fix it immediately if possible. Missing a log source? Enable it. Rule threshold too high? Lower it. Detection logic wrong? Update it. Then re-run the technique to verify the fix works.
The debrief is as important as the exercise itself. Structure it around key metrics:
We facilitate purple team exercises that improve your detection capability measurably. Our team brings the attack expertise; your team learns to detect and respond.
One monthly plan, one front door: penetration testing, Cyber Essentials, AI security, training and advice, from £1,500 a month. No hidden costs.