Purple Teaming & Detection Validation
Attack and defense, together, on detection
Attack and defense work side by side: we check whether your detection catches real attack techniques, and fix it on the spot.
This is collaboration, not an assessment. With your monitoring, detection and response staff, looking at the same records at the same time, we reproduce attack techniques in a controlled way and see how detection, alerts and logs respond. Where something is missed, we adjust detection rules, alert thresholds and protections together, and check again.
Does our detection really catch the attacks we believe we are ready for? Reviewed
We set out, technique by technique, what was detected, what we changed, and the gaps that remain.
When it fits
- Detection has been built or changed
You want to know whether new detection rules, security tools or a new monitoring setup catch real attack techniques.
- A red team assessment left gaps
You want to close what an assessment found missed, together with your defense team, and confirm it.
- You need to show what you can detect
You want to set out, technique by technique, what you detect and what you do not yet.
How it differs from a red team assessment
The two are used one after the other: a red team assessment finds the gaps, purple teaming closes them, and then they are checked again.
| Aspect | Red Team Assessment | Purple Teaming & Detection Validation |
|---|---|---|
| How it runs | The defense team is not told, or only a few people are | Attack and defense work openly together from the start |
| The question | In a real attack, would the objective be reached, and how did the organization respond? | Does our detection catch this technique, and if not, how do we fix it? |
| The defense team's role | Assessed: its response is observed and recorded | A partner: adjusting on the spot and trying again |
| What you get | Attack paths and timeline, and an assessment of the response | Detection by technique, the rules and settings changed, and the gaps that remain |
What we look at together
We lay the attack side and the defense side over the same events, and adjust from what was missed.
- Detection rules and alerts
Whether an alert fires for each technique, and whether its threshold is right.
- Logs and records
Whether the records needed for detection and investigation are kept, with no gaps in what is collected.
- Security tool settings
Whether tools such as EDR, NDR and SIEM are set up as intended.
- Alert quality
Misses and false alarms, and places where too many alerts bury the ones that matter.
- The first step of response
What the person who receives an alert checks, and to whom they pass it.
How it runs
Agree techniques and scope
We agree the techniques to check, the target systems, who takes part and the safety conditions. Techniques can come from threat intelligence or from red team assessment results.
Prepare together
With the defense team we check logs, alerts and detection tools, and agree how things will be recorded.
Reproduce and check
The attack side reproduces a technique in a controlled way; the defense side checks detection, alerts and records on the spot.
Tune and check again
Where something is missed, we adjust detection rules, alert thresholds and protections together, and run the same technique again.
Write it up
Results by technique, what was changed, and the gaps and next steps that remain.
When it runs on live systems, the scope, methods and stop conditions are agreed first so that operations are not affected.
What you receive
Detection by technique
Detected, partly detected or missed, for each technique checked.
Rules and settings changed
What was changed during the work, and why.
Remaining gaps and priorities
What still cannot be detected, and what to address first.
What to check again
Techniques and criteria to check again after changes, so the next round starts from here.