Offensive Security

Purple Team Exercises

Collaborative attack-and-defend exercises that sharpen detection.

What it is

Attack and defence in the same room. We execute known adversary techniques against your environment while your defenders watch their console, and after each one you learn immediately whether it alerted, whether it was logged, or whether it passed completely unseen. Every gap becomes a detection before we leave.

How we do it

  1. 1

    Technique selection

    We agree the ATT&CK techniques to exercise, chosen for relevance to your sector and your current coverage.

  2. 2

    Baseline coverage review

    Existing detections reviewed so the exercise targets genuine uncertainty rather than confirming the obvious.

  3. 3

    Collaborative execution

    Each technique executed with the blue team watching live, timestamped so telemetry can be correlated exactly.

  4. 4

    Immediate gap analysis

    Technique by technique: alerted, logged but silent, or invisible.

  5. 5

    Detection engineering

    Rules written and deployed during the exercise for the gaps found.

  6. 6

    Re-test

    The technique is run again to confirm the new detection actually fires.

What's included

  • Attack and defence working together, not against each other
  • ATT&CK-mapped technique execution
  • Live telemetry review per technique
  • Detections written during the engagement
  • Immediate re-test to prove they work
  • Knowledge transfer to your analysts throughout

Who needs it

  • Organisations with a SOC wanting to measure real coverage
  • Teams that invested in detection tooling and want it validated
  • Security leaders needing evidence of detection capability

Deliverables

  • ATT&CK coverage heat map, before and after
  • Detection rules built during the exercise
  • Per-technique results with timestamps
  • Prioritised list of remaining telemetry gaps

Compliance relevance

NIST CSFISO 27001SOC 2

Frequently asked questions

A red team is covert and tests whether you detect a real adversary. A purple team is openly collaborative and optimises for learning per hour. If your detection coverage is unknown, purple first is usually better value.
No — less experienced teams often gain the most, because the exercise doubles as training with their own tooling and their own environment.
Typically three to five days. Each technique needs execution, review, detection engineering and a re-test, and rushing that cycle removes most of the value.
New to managed detection?

Our guide covers how SOC, MSSP, MDR and SIEM actually differ, build vs buy, and the metrics that matter.

Read the guide

Related services

Red Team Operations

Goal-based adversary emulation testing people, process, and technology.

Learn More

SOC Services

24/7 monitoring, detection, and response from our managed SOC.

Learn More

Threat Hunting

Hypothesis-driven hunts surfacing threats that evade automated tooling.

Learn More