Purple teaming: turn every attack technique into a working detection.
Red and blue at the same table. We execute MITRE ATT&CK techniques one by one, your SOC watches live, and together we log what's seen, what's missing — and which SIEM/EDR rule closes the gap.
Not another report. Rules that fire.
The classic pattern after a red team: a 200-page report, two bugfixes, a year of silence. Purple teaming flips it — every session leaves concrete SIEM/EDR rule proposals, log-source recommendations, and an updated ATT&CK coverage matrix your content team ships the next day.
For DORA-, ISO-27001- and TIBER-relevant organisations, the coverage matrix doubles as the evidence of effective detection that auditors and supervisors want to see.
A purple sprint in 3–5 days.
Day 0: scope
Pick 20–40 ATT&CK techniques (typical focus: identity, cloud, ransomware chain, insider). Log sources and blue-team setup.
Day 1–3: execute
TTP by TTP: our operator executes, your SOC watches SIEM/EDR live, and we jointly log the detection status.
Day 4: gap analysis
Coverage matrix, log-source gaps, concrete Sigma and EDR rule proposals, prioritised by ATT&CK weight.
Day 5: handover
Debrief with CISO/Head of SOC, roadmap for the next sprint, optional rule-tuning support in the following weeks.
Operators who also run real red team operations.
From live ops, not from a catalogue
The TTPs we exercise come from operations, not from blog posts. Purple sprints complement red-team mandates for us — they don't replace them.
Two-language team
German points of contact for BaFin/Bundesbank context; technical delivery in German or English — whichever fits the blue team.
No tool sales
We don't recommend a SIEM platform we earn commission on. Rule proposals are tailored to your existing stack.
Frequently asked questions about purple teaming
What is purple teaming?→
Purple teaming is a planned, joint exercise between the red team (attack) and blue team (defence) where each technique is executed individually and measured live: does the SIEM see it? Does the alert fire? Does the SOC respond? The goal is not "deliver a report" but measurably better detection & response.
Purple teaming vs. red team assessment — what's the difference?→
A red team assessment is covert and goal-oriented — it measures the overall outcome. Purple teaming is open and technique-oriented — it measures every individual TTP. They complement each other: the red team shows what works today; the purple team closes the detection gaps deliberately.
How does a purple teaming session run?→
We pick a set of MITRE ATT&CK techniques (typically 20–40 per sprint). For each: your blue team watches SIEM/EDR, our operator executes, and we jointly log the detection state (no alert / alert / alert + response). Output: a detection coverage matrix and concrete SIEM/EDR rule proposals.
When is purple teaming a good fit?→
When a red team has shown techniques slipping through. When you have introduced a new SIEM/EDR and need to validate content coverage. When regulation (e.g. DORA) requires evidence of effective detection. Not useful if baseline telemetry isn't in place yet.
How often should you run purple teaming?→
For a mid-size organisation: 2–4 sprints per year, 3–5 days each, with clear focus (e.g. identity, cloud, ransomware TTPs). More often than quarterly is rarely worthwhile — you need the gap for detection engineering.
Which frameworks do you use?→
MITRE ATT&CK as the language for techniques, D3FEND and Sigma on the defence side, Atomic Red Team plus our own C2 tooling for execution. Every session leaves an ATT&CK coverage matrix you can use internally and with auditors.
Close detection gaps — not just document them.
A purple sprint can follow a red team engagement or run stand-alone. We'll agree the right focus in a 30-minute call.