Purple Teaming That Actually Changes Detections
Purple teaming should be the highest-leverage exercise in security. Too often it's a red team demo, a nodding blue team, and zero new detections a month later. Here's the format that actually ships coverage improvements.
Pick technique, not tool
Anchor every session on a specific ATT&CK sub-technique, not "run this C2 framework." The goal is coverage of a behavior, not a demo of a product.
Run it live, together
Red executes one technique at a time. Blue watches their tooling in real time and calls out what they saw — and what they missed — before red moves to the next technique.
- One technique per round, documented before moving on
- Blue narrates what alerted and what didn't, live
- Red shares exact commands and artifacts immediately, no gatekeeping
Close the loop the same week
Every miss becomes a ticket with an owner and a due date — a new Sigma rule, a log source onboarded, a tuning change. If it's not tracked, it didn't happen.
Measure coverage over time
Track ATT&CK technique coverage release over release. The purple team program's ROI is that number going up, not the exercise report.
Tools mentioned
Purple teaming only works when it produces a diff — a new rule, a new log source, a closed gap. Anything else was just a demo.