SSQ.AISSQ.AI

Purple Teaming & Detection Validation

Attack and defense, together, on detection

Attack and defense work side by side: we check whether your detection catches real attack techniques, and fix it on the spot.

This is collaboration, not an assessment. With your monitoring, detection and response staff, looking at the same records at the same time, we reproduce attack techniques in a controlled way and see how detection, alerts and logs respond. Where something is missed, we adjust detection rules, alert thresholds and protections together, and check again.

Does our detection really catch the attacks we believe we are ready for? Reviewed

We set out, technique by technique, what was detected, what we changed, and the gaps that remain.

Detection ATTACK Reproduce a technique DEFENSE Check detection TOGETHER Tune together RETEST Check again
Reproduce a technique, check detection, tune it together, and check again, as many times as it takes.

When it fits

  • Detection has been built or changed

    You want to know whether new detection rules, security tools or a new monitoring setup catch real attack techniques.

  • A red team assessment left gaps

    You want to close what an assessment found missed, together with your defense team, and confirm it.

  • You need to show what you can detect

    You want to set out, technique by technique, what you detect and what you do not yet.

How it differs from a red team assessment

The two are used one after the other: a red team assessment finds the gaps, purple teaming closes them, and then they are checked again.

AspectRed Team AssessmentPurple Teaming & Detection Validation
How it runsThe defense team is not told, or only a few people areAttack and defense work openly together from the start
The questionIn a real attack, would the objective be reached, and how did the organization respond?Does our detection catch this technique, and if not, how do we fix it?
The defense team's roleAssessed: its response is observed and recordedA partner: adjusting on the spot and trying again
What you getAttack paths and timeline, and an assessment of the responseDetection by technique, the rules and settings changed, and the gaps that remain

What we look at together

We lay the attack side and the defense side over the same events, and adjust from what was missed.

the same events, reviewed together ATTACK Attack team what was done DEFENSE Defense team what was seen missed events Adjust detection run again to confirm update rules Detected Missed
Attack records and defense records laid over the same events; adjustment starts from what was missed.
  • Detection rules and alerts

    Whether an alert fires for each technique, and whether its threshold is right.

  • Logs and records

    Whether the records needed for detection and investigation are kept, with no gaps in what is collected.

  • Security tool settings

    Whether tools such as EDR, NDR and SIEM are set up as intended.

  • Alert quality

    Misses and false alarms, and places where too many alerts bury the ones that matter.

  • The first step of response

    What the person who receives an alert checks, and to whom they pass it.

How it runs

  1. Agree techniques and scope

    We agree the techniques to check, the target systems, who takes part and the safety conditions. Techniques can come from threat intelligence or from red team assessment results.

  2. Prepare together

    With the defense team we check logs, alerts and detection tools, and agree how things will be recorded.

  3. Reproduce and check

    The attack side reproduces a technique in a controlled way; the defense side checks detection, alerts and records on the spot.

  4. Tune and check again

    Where something is missed, we adjust detection rules, alert thresholds and protections together, and run the same technique again.

  5. Write it up

    Results by technique, what was changed, and the gaps and next steps that remain.

When it runs on live systems, the scope, methods and stop conditions are agreed first so that operations are not affected.

What you receive

Detection by technique

Detected, partly detected or missed, for each technique checked.

Rules and settings changed

What was changed during the work, and why.

Remaining gaps and priorities

What still cannot be detected, and what to address first.

What to check again

Techniques and criteria to check again after changes, so the next round starts from here.