Skip to content

Adversary Simulation

Purple Team
Assessment

Operators and your defenders, working the same techniques together

Fixed-scope pricing, no hourly billing. See all pricing →

Get a fixed quote

Reply in one business day

Senior certified testers, manual-first185+ years combined experienceOnboarding within 24 hoursFree retest includedOur methodology

When you need it

When you need a purple team assessment

The situations that bring teams to this engagement, and where it fits alongside the rest of your program.

  • You have a SOC, an EDR, and a detection stack, and you want to know which real attacker techniques they actually catch.
  • A red team found gaps in your detection, and now you want to fix them technique by technique, together.
  • Your detection content has grown for years and nobody has validated it against live tradecraft.
  • You want to improve your blue team fast, not just grade it, with the two sides working the same techniques in one room.
  • You need evidence that detection and response controls work for an auditor, an insurer, or the board, not just that they exist.

Definition

What is a purple team assessment?

A purple team assessment is a collaborative exercise that validates and improves your detection. It is not a separate team, it is a way of working: our operators (the red) run real attacker techniques while your defenders (the blue) watch their own detections fire or fail in real time, and both sides improve on the spot. Purple is what you get when the two colors work together. Buyers also call it a purple team exercise or purple teaming services; they mean the same collaborative engagement.

The goal is different from a red team. A red team stays covert and asks whether a determined attacker would be caught. A purple team is open and asks how to make sure they would be, technique by technique, turning a pass-or-fail test into a training loop that measurably strengthens detection and response. Our guide to red team vs blue team vs purple team lays out the distinction in full.

Comparison

Purple team, red team, or penetration test

Three offensive engagements by the same specialists — different questions, so pick the right one.

Penetration test

Question answered
What vulnerabilities exist in this scope?
Stealth
None; testing is coordinated
Your team
Usually aware, not involved
Main output
A ranked list of findings
Best when
You need depth or compliance evidence

Red team

Question answered
Would a determined attacker be detected and stopped?
Stealth
Central; the operation is covert
Your team
Usually unaware, so the SOC responds for real
Main output
An attack narrative and a detection timeline
Best when
You have monitoring and want it graded honestly

Purple team

Question answered
How do we make sure each technique is detected?
Stealth
None; both sides watch together in real time
Your team
Fully involved, tuning detections as we go
Main output
A coverage map plus detections improved on the spot
Best when
You want to improve detection quickly

Many teams run a red team to grade detection, then a purple team to close the gaps it found.

What we look for

What a purple team assessment validates

A red team asks whether you would be caught. A purple team fixes the answer as it goes. We run techniques across the kill chain and, wherever one runs unseen, your team builds the detection and we prove it fires.

Initial access and execution

Whether the first foothold and the first commands would be seen: the phishing payload, the exposed service, the code that runs on the endpoint.

We test for

  • Phishing and payload execution detection, using the same tradecraft as our phishing campaigns
  • Malicious and living-off-the-land command execution on the endpoint
  • Macro, script, and loader behavior your EDR should flag
  • Exploitation of an exposed service seen at the perimeter
  • The alerts that fire, and the ones that should have

Persistence and defense evasion

Whether an attacker settling in and hiding would trip an alarm, or blend into normal activity.

We test for

  • Persistence mechanisms: scheduled tasks, services, registry, and account creation
  • Defense-evasion techniques against your endpoint and identity monitoring
  • Log tampering and the gaps that would hide it
  • Tooling that is logged but never alerted on
  • The telemetry that would surface each technique

Privilege escalation and credential access

The techniques that turn a foothold into control, and whether your monitoring notices the credential theft that powers them.

We test for

  • Local and domain privilege escalation
  • Credential dumping, Kerberoasting, and token abuse
  • LLMNR, NBT-NS, and relay activity on the wire
  • Detection of anomalous privileged logons
  • The identity signals that would catch escalation early

Lateral movement

The host-to-host movement that spreads an intrusion, and whether it stands out from ordinary administration.

We test for

  • Remote execution, pass-the-hash, and pass-the-ticket
  • SMB, WMI, and remote-service movement
  • Anomalous authentication between hosts
  • Detection of movement toward tier-zero systems
  • The baseline that would make abnormal movement visible

Exfiltration and impact

The end of the kill chain: staging and stealing data, and the ransomware-style impact techniques your detection most needs to catch, the same chain a ransomware readiness assessment walks.

We test for

  • Data staging and exfiltration over common channels
  • Inhibit-system-recovery behavior such as deleting shadow copies (MITRE ATT&CK T1490)
  • Data-encryption-for-impact activity (T1486) short of actual encryption
  • Detection of mass file access and unusual egress
  • The alerts that would stop the chain before impact

The tuning loop

The part that makes it a purple team, not a red team: when a technique runs unseen, your team builds a detection and we run it again to prove it fires.

We test for

  • Detection content written or fixed during the exercise
  • Re-run of missed techniques against the new detections
  • False-positive and coverage checks on the new content
  • A prioritized backlog for the gaps not closed in the room
  • A repeatable process your team keeps after we leave

The tooling

How we run and measure the techniques

Every technique is mapped to MITRE ATT&CK, the knowledge base of adversary techniques based on real-world observations, so your defenders can tie each one to the tactic it belongs to and the telemetry that should catch it. We run a mix of hands-on operator tradecraft and structured technique libraries, so coverage is both realistic and repeatable: frameworks such as MITRE Caldera for automated adversary emulation and Atomic Red Team, the library of small, portable tests that map directly to ATT&CK techniques, alongside the manual techniques a real operator would use.

The value is in the loop, not the tool. When a technique runs and nothing fires, your team writes or fixes the detection while we are still in the room, and we run the technique again to prove it now works. What you keep is not just a report but a set of validated detections and a repeatable process, so the next exercise starts from a higher baseline.

Pricing

How a purple team assessment is priced

There is no fixed catalog price for a purple team, because the scope is the set of techniques and the depth of tuning you want. It is scoped and quoted, and the price is fixed in writing before work begins.

Alongside a red team

The most common shape: a covert red team from $12,500 that grades detection, followed by a collaborative purple-team session to close the gaps it found. See the red team pricing.

As a standalone exercise

A focused engagement against a chosen set of MITRE ATT&CK techniques, scoped by how many techniques you want validated and how much tuning your team wants to do in the room.

As a recurring loop

Some teams run a purple-team exercise each quarter, so new detections are validated as the environment and the threat landscape change. Priced as a recurring engagement.

A purple team needs something to test: it is most valuable once you already have a SOC or an EDR and detection content to validate. If you have neither yet, an internal penetration test or a red team usually delivers more first, and we will say so during scoping.

Methodology

How a purple team assessment runs

Full methodology →

Every engagement follows the Penetration Testing Execution Standard and the relevant OWASP guides.

These are the phases your purple team assessment runs through.

  1. 01

    Plan the techniques

    The threats that matter to you turned into a set of MITRE ATT&CK techniques to run, agreed with your detection team.

  2. 02

    Run in the open

    Our operators execute each technique while your defenders watch the telemetry live, so nothing is hidden.

  3. 03

    Observe and grade

    For each technique we record whether it was detected, logged but not alerted, or invisible, with the evidence.

  4. 04

    Tune and re-run

    Where a technique ran unseen, your team builds or fixes a detection and we run it again to prove it fires.

  5. 05

    Map and report

    A MITRE ATT&CK coverage map, the content improved in the room, and a prioritized backlog for the rest.

How it works

How your engagement runs

From scope through the final retest, your team stays in the loop at every step, with findings tracked live in our platform.

  1. 01

    Scope & kickoff

    Targets, roles, and rules of engagement defined in writing, with a fixed scope and timeline.

  2. 02

    Testing goes live

    Findings post to your live platform dashboard the moment our testers confirm them.

  3. 03

    Track remediation

    Follow every finding from open to fixed, with severity, evidence, and status in one place.

  4. 04

    Report & retest

    Executive and technical reports land, then request a free retest in one click.

Proof

Proof in the field

Every engagement is confidential, so the work below is anonymized to sector and engagement type.

All case studies →

Free

Retest on every penetration test

185+

Years combined experience

14

Senior in-house specialists

24h

Onboarding after signing

Fintech · Payments

Web Application Penetration Test

High risk

Critical: a remote code execution flaw in the application’s web framework that could have given an attacker full control of the server. We escalated it to the development team while the test was still running.

Outcome. The critical RCE was reported and remediated during the engagement via an emergency framework upgrade, which also closed the server-side request forgery, and the remaining findings were retested to confirmation.

1

Critical (RCE)

Mid-test

Critical remediated

2

High

Read the case study

HR & Payroll SaaS

Web Application Penetration Test

High risk

Critical: a file-inclusion flaw that let an attacker read sensitive files from the server through the application itself. High: stored cross-site scripting capable of session theft, insecure direct object references, and an authorization bypass that let an administrator create or delete organization owners.

Outcome. Delivered a remediation plan sequenced by real business impact, critical and high findings first, with a complimentary retest to verify every fix.

28

Findings

1

Critical

5

High

Read the case study

FAQ

Frequently asked questions

What teams most often ask before scoping purple team assessment.

Still have questions? 
01What is a purple team assessment?

It is a collaborative exercise that validates and improves your detection. Our operators run real attacker techniques while your defenders watch their own detections fire or fail in real time, then tune them on the spot and re-run the technique to confirm the fix. Purple is not a third team; it is red and blue working together. The output is a MITRE ATT&CK coverage map of what your monitoring caught, a set of detections improved during the exercise, and a prioritized backlog for the rest.

02How is a purple team different from a red team?

A red team is covert and adversarial: it stays quiet, pursues an objective, and grades whether your team detects and stops it, so most of your organization does not know it is running. A purple team is open and collaborative: both sides work together, technique by technique, to make sure each one is detected. A red team answers "would we be caught?"; a purple team answers "how do we make sure we would be?" Many teams run a red team first to get an honest grade, then a purple team to close the gaps.

03How much does a purple team assessment cost?

It is scoped and quoted rather than sold at a fixed catalog price, because the scope is the set of techniques and the depth of tuning you want. Most often it runs alongside or after a red team, which starts at $12,500, with the collaborative purple-team session added to close the gaps the red team found. A standalone exercise is priced by how many MITRE ATT&CK techniques you want validated. Either way the price is fixed in writing before work begins. The red team pricing page explains the red team tiers, and starting prices for every service are on our pricing page.

04Do we need a SOC or EDR already?

Broadly, yes. A purple team validates and improves detection, so it needs detection to work with: a SOC, an EDR, a SIEM, or the detection content your team maintains. If you have none of that yet, the exercise has little to tune, and a penetration test or a red team usually delivers more value first. We will give you an honest read during scoping rather than sell you an engagement you are not ready for.

05What do we walk away with?

A MITRE ATT&CK coverage map showing, for every technique we ran, whether it was detected, logged but not alerted, or invisible; the detection content your team wrote or fixed during the exercise, validated by a re-run before we left; a prioritized list of the log sources, alerts, and identity controls that would close the remaining gaps; and a repeatable process your team can run again as the environment changes. It is a training outcome, not just a report.

06Which techniques do you run?

A set chosen with your team around the threats that matter to you, mapped to MITRE ATT&CK across the kill chain: initial access and execution, persistence and evasion, privilege escalation and credential access, lateral movement, and exfiltration and impact, including the ransomware-style techniques such as inhibiting system recovery. We use a mix of hands-on operator tradecraft and structured technique libraries so the coverage is both realistic and repeatable, and we agree the exact list before we start.

07How long does a purple team engagement take?

Shorter and more intensive than a red team, because it is not covert. A focused standalone exercise often runs across a handful of days of collaborative sessions, sized by how many techniques you want validated and how much tuning your team wants to do in the room. When it follows a red team, it is scheduled around the debrief so the gaps the red team found are still fresh. We agree the schedule during scoping.

Ready to test your defenses?

Talk to our team about scoping purple team assessment.

Prefer the full scoping questionnaire? 

Get a Fixed-Scope Quote

Tell us what you need tested. We reply within one business day.