Purple Team Exercise

Attackers and defenders in one room: live attacks, live detection tuning, live improvement β€” no months-long report cycle.

Why this matters: Red teams find gaps; blue teams fix them β€” months later. A purple team collapses that cycle: we execute attacks while your defenders watch, tune detections live, and leave with rules that already work. It is the fastest way to turn β€œwe would probably catch that” into β€œwe caught that.”

What we cover

  • Attack techniques chosen from threats relevant to your stack
  • Live execution with your SOC watching each step
  • Detection rule tuning during the exercise
  • Coverage mapping against MITRE ATT&CK
  • Alert-quality review: would an analyst act on it?
  • A repeatable playbook your team keeps

How we test

1Threat selection

We pick attack techniques from actors and campaigns that actually target your industry.

2Live attack & detect

Each technique executed one at a time β€” your team hunts it with us in the room.

3Tune & retest

Detections adjusted immediately and re-run until they fire cleanly with useful context.

4Handover

Coverage map, tuned rules, and a playbook to continue the practice internally.

What you get

  • ATT&CK coverage map: before vs. after
  • Detection rules tuned and tested live
  • A repeatable exercise playbook
  • Prioritized backlog of remaining gaps

The engagement at a glance

πŸ“ž Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote β€” no obligation.

✍️ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

⏱️ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

πŸ” Retest included

A verification pass over everything you fix β€” included in the price, not an add-on.

See the full engagement process β†’ and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

What do we need to have in place?

A SIEM or equivalent logging, and one or more people who can join the sessions. We scope techniques to whatever visibility you actually have.

How long does an exercise run?

One to three days is typical β€” enough for a focused technique set with real tuning, without pulling your team off the floor for a week.

Red team or purple team β€” which should we do first?

If detection quality is the concern, purple first β€” it improves what you have. If you need an honest independent answer about whether an attacker succeeds, that is red team.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement β€” the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation β€” a researcher replies.

Start the conversation β†’