Skip to content

Glossary

Purple team

A purple team is not a separate standing unit but a way of working in which the offensive and defensive sides collaborate openly and in real time to measure and improve detection capability.

The method is iterative: a specific adversary technique is selected, normally from the MITRE ATT&CK catalog, executed in a controlled way at an agreed time, while defenders watch whether it was recorded in telemetry, whether it raised an alert, and whether that alert was clear enough to act on. The detection is then fixed or extended and the technique is repeated to confirm the improvement.

It differs from red teaming in that there is no stealth and no surprise. The aim is not to test the realism of a full attack chain but to close detection gaps quickly and transfer knowledge between the two sides. The feedback loop is therefore far shorter and cheaper, and the exercise carries less risk for production environments.

The main deliverable is a detection coverage matrix by technique, together with a list of gaps — missing telemetry, missing or excessively noisy rules, insufficient log retention — plus the corrected rules and handling procedures. This approach is often used to prepare for a red team exercise or as the systematic follow-up to one.

Back to glossary

Ready to strengthen security across your organization?

Contact us to see how our turnkey solutions can build a safer, more resilient organization.