✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

What Is a Purple Team, and When Do You Choose One?

Red team versus blue team is often framed as a competition: the attackers try to get in, the defenders try to stop them, and at the end there’s a winner. In practice, that setup produces interesting results, but not always the most learning. A purple team approach flips that around: winning isn’t the point — getting better together, as fast as possible, is.

What a purple team actually is

Purple teaming isn’t a separate team alongside red and blue, but a way of working where attackers (red team) and defenders (blue team) actively collaborate during the exercise, rather than only exchanging a report afterwards. The attacker executes a technique — say, a specific method of lateral movement or command-and-control traffic — and immediately afterwards, together, they look: did the detection team see this? If not, why not, and what’s needed to catch it next time?

The result is a much faster learning process than with a traditional red team exercise, where the defence often only hears what happened weeks later, in the final report.

The difference from a regular pentest and red team

A pentest tests whether vulnerabilities are present. A red team exercise tests whether a realistic attack goes unnoticed, often over a longer period and without the blue team knowing a test is underway. Purple teaming tests a third thing: how well does the collaboration between attack and defence work, and how quickly can it improve? It’s less suited to proving “are we vulnerable”, and much better suited to answering “how well do we see and stop an attack while it’s happening”.

When purple teaming is the best choice

  • You already have a baseline level of detection and monitoring (a SOC, SIEM, or EDR solution) and want to know how effective it actually is against realistic techniques.
  • Previous red team exercises showed gaps exist, but the blue team struggled to act on them concretely without clear, direct feedback.
  • You want to train your team’s detection capability specifically against threats relevant to your sector, rather than a generic scope.
  • Time and budget are limited: purple teaming often delivers usable improvements faster than a long-running, hidden red team exercise.

When a different approach makes more sense

If your organisation doesn’t yet have structural detection capability, a SOC, active monitoring, or an established incident response process, purple teaming doesn’t deliver much yet: there’s simply no one to collaborate with on the blue side. In that case it makes more sense to first invest in basic monitoring, and start with a regular pentest or a Red Team Light engagement to get an initial picture of your main risks.

A real-world example

During a purple team session, a tester executes a commonly used technique to extract credentials from a workstation’s memory. At first, the blue team sees nothing: the existing detection rule was written for an older variant of the technique, and the small tweak the tester used fell just outside it. Instead of reading about that weeks later in a report, the detection rule is adjusted in that same session, and five minutes later the blue team does see the repeated attempt. That direct, iterative improvement process — finding and closing a gap within a single day — is exactly where purple teaming proves its value over a report that only lands on the table afterward.

How MonkeysICT shapes purple team engagements

We work in short, joint sessions: our attackers execute a technique, and immediately afterward we discuss with your detection team what was and wasn’t visible, and why. That delivers concrete, immediately applicable improvements per session, rather than a list of recommendations that only surfaces weeks later.

Scroll to Top