Explore RIFT.

22 pages
Two analysts comparing an exercise event with defensive observations.
Purple teaming

Make the exercise a shared investigation.

Purple teaming is a structured collaboration between offensive and defensive teams designed to strengthen detection and response capabilities. Rather than treating red and blue teams as adversaries, this approach treats the exercise as a shared investigation. The focus is on understanding how attacks unfold, what defenders observe, and where gaps exist. This page explains how to plan, execute, and learn from such an exercise with intellectual honesty and practical discipline.

LONG-FORM / 9 MIN READDEFINED SCOPE · USEFUL EVIDENCE
Keep the output useful

What the conversation should produce.

  • A written objective statement that defines what the defensive team wants to learn
  • A scope document listing allowed and off-limits techniques, systems, and credentials
  • An observation plan mapping scenario stages to expected signals and responsible observers
BRIEFING / 01

Decide what defenders want to learn from collaboration

Before any exercise begins, the defensive team must articulate what it hopes to discover. This is not a request for the offensive team to simply demonstrate capability. It is a deliberate statement of what the defenders need to understand about their own environment. The question is practical: which attack techniques, which systems, which detection gaps matter most right now? Writing these objectives down prevents the exercise from drifting into unstructured play.

The objectives should be specific enough to guide decisions but flexible enough to accommodate unexpected findings. A defensive team might want to learn whether its monitoring captures lateral movement, whether alerts fire at the right time, or whether responders follow the right procedures. Each objective becomes a lens through which the exercise is designed, observed, and evaluated. Vague goals produce vague results and little useful learning.

BRIEFING / 02

Agree the scenario, expected signals and participant roles

A scenario is the shared narrative that gives the exercise structure. It describes the attacker's starting point, the techniques they will attempt, and the systems they will touch. The defensive team states what signals it expects to see at each stage. This agreement is not a script that forces the offensive team to perform predetermined actions. It is a framework that keeps both sides aligned on what is being tested and why.

Participant roles must be defined before the session starts. The offensive team knows the scope and the techniques it may use. The defensive team knows what it is monitoring and what it will do when it observes activity. Observers understand their documentation responsibilities and the agreed route for raising concerns; anyone assigned pause authority must be able to use it. Everyone understands that the exercise has boundaries, that certain systems or techniques are off-limits, and that the goal is learning, not proving superiority.

BRIEFING / 03

Prepare telemetry and observation before the session

Identify the telemetry and rules needed for the selected learning objective before the session. Check what is available, who can observe it and which limitations are already known. A session may intentionally investigate a telemetry gap; in that case the gap should be part of the question rather than an accidental surprise. Preparation helps participants use the time well, but it does not require pretending that all monitoring is complete before collaborative work can begin.

Preparation also means deciding what will be observed and how observations will be recorded. The defensive team should document which logs it is watching, which dashboards it will monitor, and who is responsible for noting each observation. This discipline turns raw data into evidence that can later be compared against the expected signals. Without it, the exercise produces impressions rather than findings.

BRIEFING / 04

Compare expected and observed defensive behaviour without blame

The core of the exercise is a calm comparison between what the defensive team expected to see and what it actually observed. This comparison must be conducted without blame. The purpose is not to judge individuals but to understand the system. When a detection fails to fire, the question is not who missed it but why the detection did not trigger. When a response was delayed, the question is not who was slow but which workflow step broke down.

This comparison should be documented as observed facts, hypotheses, and untested areas. An observed fact is something that can be verified from logs or records. A hypothesis is a plausible explanation for a gap that still needs testing. An untested area is a part of the scenario that was not observed at all. Distinguishing these categories prevents the report from presenting speculation as evidence.

BRIEFING / 05

Adjust detections and workflows in a controlled feedback loop

The findings from the comparison should feed directly into adjustments. A detection rule that failed to fire might be revised. A workflow that caused confusion might be clarified. A telemetry source that was missing might be added. These adjustments are not permanent commitments. They are controlled experiments that can be tested again. The exercise is not a one-time event but a cycle of observation, adjustment, and retesting.

Each adjustment should be documented with the reason it was made and the evidence that supports it. This creates a traceable record of why a detection was changed and what the team expected to improve. It also helps teams notice overlapping changes and coordinate them before drawing conclusions from a repeat observation. A controlled feedback loop turns a single exercise into sustained improvement.

BRIEFING / 06

Preserve outcomes, limitations and repeatable next checks

The outcomes of the exercise must be preserved in a form that can be revisited later. This means a written record of the objectives, the scenario, the observations, the comparisons, and the adjustments. It also means a clear statement of what was not tested and what the exercise cannot establish. An exercise reveals weaknesses in the specific scenario it covers. It does not prove that other weaknesses do not exist.

The record should include repeatable next checks: specific techniques or systems that can be tested again in a future exercise to confirm whether adjustments worked. These checks turn the exercise from a single investigation into a structured program. Each cycle builds on the last, and each record makes the next cycle more focused and more useful.

Illustrative scenario / Not a client case study

Illustrative scenario: detecting lateral movement after initial access

This scenario is illustrative and describes an illustrative situation. A defensive team wants to learn whether its monitoring captures an attacker who has gained initial access to a workstation and then moves laterally to reach a server. The offensive team agrees to attempt lateral movement using techniques that are within scope. The defensive team expects to see log entries for authentication events, network connections between workstations, and alerts for unusual access patterns. Observers document each observation without intervening. The scenario is not a test of whether the attacker succeeds. It is a test of whether the defenders observe and respond to the movement.

  1. Which authentication logs and network connection logs will be monitored, and who is responsible for watching each source during the exercise
  2. Whether the offensive team may attempt credential reuse or whether it must use only the credentials provided at the start
  3. What the defensive team will do when it first observes lateral movement, and who makes that decision in real time

This scenario establishes that a purple team exercise is defined by what the defenders want to learn, not by what the offensive team wants to demonstrate. It does not establish that the defensive team's monitoring is adequate in general, only that the exercise reveals whether it captures this specific pattern.

Useful decision table for planning a purple team exercise

QuestionWhat to establishUseful output
What does the defensive team want to learn?A written statement of the specific techniques, systems, and detection gaps the exercise will addressA one-page objective statement signed by both teams before preparation begins
What is in scope and what is not?A list of allowed techniques, systems, and credentials, and a list of off-limits systems and techniquesA scope document that the offensive team references when choosing actions and the defensive team references when observing
What signals are expected and who records them?A mapping of each scenario stage to the logs and alerts the defensive team expects, and the observer responsible for eachAn observation plan that turns raw monitoring into structured evidence

Scroll the table horizontally on smaller screens.

Useful questions.

Does a successful purple team exercise prove our defenses are adequate?

No. An exercise tests a specific scenario against the defenses that are in place at a specific time. It reveals what the defenders observed and what they missed in that scenario. It does not prove that other scenarios would be detected, that other systems are protected, or that the defenses will hold against techniques not attempted. The exercise is evidence of one investigation, not a guarantee of overall security.

Can we reuse the same scenario in a follow-up exercise?

You can, but the purpose of reusing a scenario should be clear. If the goal is to confirm whether an adjustment worked, then retesting the same scenario is useful. If the goal is to learn something new, a different scenario is more valuable. Each exercise should state whether it is a confirmation test or an investigation, and the record should reflect which it was.

Further reading: MITRE ATT&CK: adversary behaviour knowledge base. This independent resource provides background; no affiliation, certification or endorsement is implied.

The next useful question

What do you need
the evidence to tell you?

Start with the decision, the environment and the constraints. Create a scope brief you can download, review with your team and refine before any engagement is considered.

Build your scope brief ↗