Skip to content
Pentesys
Adversary

Collaborativeattackanddefenceexercisesthatclosedetectiongaps

Red and blue teams work together in real time to execute techniques, tune detections and build a repeatable detection engineering backlog.

Purple teaming is the fastest way to improve detection coverage. Instead of a red team hiding what they did, attackers and defenders work together in real time: one side executes a technique, the other confirms what was seen, and both agree how to close the gap before moving on.

Our purple team exercises are structured around MITRE ATT&CK, focused on the techniques most relevant to your threat model. Every session produces a heatmap of current detection coverage, a list of tuned rules and a prioritised backlog of detection engineering work.

Capabilities

What's included in Purple Team Testing

Everything below is delivered and tracked through the Mirage Portal.

Real-time collaboration

Operators and defenders execute and observe techniques together, with immediate feedback and tuning.

ATT&CK-mapped coverage

Each technique is mapped to MITRE ATT&CK so coverage gaps are visible and measurable.

Detection tuning

Rules, alerts and data sources are adjusted live during the session to improve signal quality.

Coverage heatmap

A clear visual of detected, partially detected and missed techniques across the kill chain.

Engineering backlog

A prioritised list of detection rules, data sources and configuration changes with owners and effort estimates.

Knowledge transfer

Defenders learn how attackers think and what telemetry matters, improving future triage and response.

Coverage

Scope and depth

Exercise types

  • Technique-focused purple team sessions
  • Kill-chain walkthroughs
  • Detection rule tuning workshops
  • Data source validation
  • Assumed-breach detection drills
  • Repeatable purple team playbooks

Outcomes

  • ATT&CK coverage heatmap
  • Tuned detection rules
  • Prioritised detection engineering backlog
  • Telemetry and data source recommendations
  • Joint runbook for future exercises
  • Metrics to measure improvement over time
How it works

Our delivery process

A consistent, transparent methodology from first conversation to verified remediation.

  1. 01

    Plan

    We agree threat model, target techniques, scope, tools and the defenders who will participate.

  2. 02

    Baseline

    Current detection coverage is mapped so progress can be measured.

  3. 03

    Execute

    Techniques are executed one at a time while defenders observe telemetry and confirm detections.

  4. 04

    Tune

    Rules, queries and data sources are adjusted live to close gaps before the next technique.

  5. 05

    Backlog

    A prioritised engineering backlog and heatmap are delivered for ongoing improvement.

What you receive

  • Pre and post-session ATT&CK coverage heatmaps
  • Detection engineering backlog with priorities
  • Tuned rules and queries from the session
  • Telemetry and data source recommendations
  • Purple team runbook for repeatable exercises
  • Executive summary of coverage improvement

Business outcomes

  • Measurable improvement in detection coverage
  • Fewer missed techniques during real incidents
  • Stronger collaboration between offensive and defensive teams
  • A repeatable process for continuous detection improvement
FAQs

Common questions

Do we need a SOC to benefit?

A SOC or detection team helps, but we can also focus on data sources, tooling and runbook development for less mature teams.

How long is a purple team exercise?

Typically one to three days, depending on the number of techniques and the depth of tuning required.

Can this follow a red team engagement?

Yes. Purple team replay after a red team is an excellent way to close the gaps the red team exposed.

Save time and book a call with us

Enterprise-grade penetration testing, built around your business

CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.