Red / Purple Teaming Services
Full-scope adversary simulation. TTPs based on threat intelligence. Tests detection, response, and recovery across people, process, and technology. Not a pentest — a test of your entire defensive posture.
What Is Red / Purple Teaming?
Red teaming is full-scope adversary simulation. Unlike penetration testing, which focuses on finding vulnerabilities, red teaming tests whether your organisation can detect, respond to, and recover from a determined, skilled attacker operating across multiple domains — network, social engineering, physical, and application.
Purple teaming is the collaborative version. Red and blue teams work together in real time — the attacker executes techniques while the defender observes, detects, and tunes controls. The output is improved detections and validated controls, not just findings.
Note: This service replaces what was previously called “Black Teaming.” Since social engineering and physical intrusion are already covered as standalone services, Red / Purple Teaming focuses on adversary simulation, detection, and response across the full attack lifecycle.
Scope of Red / Purple Teaming
Full-scope. Adversary-realistic. Objective-driven.
Objective-Driven Attacks
Red teaming is goal-oriented. Compromise a specific asset, exfiltrate defined data, achieve domain admin, or reach a sensitive system. The objective defines the engagement — not a checklist of vulnerabilities.
TTP-Based Simulation
Techniques, Tactics, and Procedures derived from real threat intelligence. We replicate the behaviour of specific threat actors targeting your industry — not generic attacks, but the actual playbooks used against organisations like yours.
Purple Team Collaboration
Red and blue teams work together in real time. Attack techniques are executed while defenders observe detection alerts. Immediate feedback: what was detected, what was missed, and how detection coverage can be improved.
Full Attack Lifecycle
Initial access, execution, persistence, privilege escalation, defence evasion, credential access, discovery, lateral movement, collection, exfiltration, and impact. Every stage of the MITRE ATT&CK framework.
Detection & Response Metrics
Mean time to detect (MTTD), mean time to respond (MTTR), alert quality, coverage gaps, and false positive rates. We measure whether your SOC can see what matters and respond effectively.
People, Process, Technology
Red teaming tests all three. Not just whether the technology works, but whether the people know what to do when it matters, and whether the processes support them. Technical findings are only part of the picture.
How Red / Purple Teaming Works
Adversary simulation. Realistic, measured, and documented.
Planning & Threat Modelling
Define engagement objectives, rules of engagement, success criteria, and the threat actor profile to simulate. We align the scenario to your industry, threat landscape, and the specific risks that keep your security team awake.
Execution
Live adversary simulation. Initial compromise, establishment of foothold, lateral movement, objective achievement. For purple teaming: real-time collaboration with defenders, executing specific techniques and immediately evaluating detection response.
Detection Assessment
For each technique executed: was it detected? Did it trigger an alert? Did the SOC respond? Was the response effective? We map executed techniques to MITRE ATT&CK and evaluate detection coverage across the framework.
Detailed Debrief
Full timeline reconstruction. Attack narrative, detection gaps, response deficiencies, and actionable recommendations for improving detection rules, response procedures, and security architecture. Executive and technical audiences.
Our Technical Expertise
The difference between a pentest and a red team operation.
MITRE ATT&CK Mapping
Every technique executed is mapped to the MITRE ATT&CK framework. You get a coverage heat map showing exactly where your detections work and where the blind spots are. No ambiguity — just data.
Stealth Operations
We operate as a real adversary would — avoiding detection, using living-off-the-land techniques, blending into normal traffic patterns. If your defences catch us, that's a genuine win. If they don't, you need to know.
Threat Intelligence Driven
We base scenarios on current threat intelligence — the TTPs used by ransomware groups, nation-state actors, and industry-specific threats targeting your sector. Not theoretical, not generic. Real.
Purple Team Outcomes
In purple team engagements, the output isn't a list of vulnerabilities. It's improved detections, validated alert rules, tuned SIEM use cases, and a blue team that has observed real attack techniques first-hand. Capability building, not just assessment.
Request a Red / Purple Team Engagement
Tell us about your defensive posture. We'll design an adversary simulation that tests it.