purple team

Deconstructing Logon Session Enumeration
Purple TeamingHow we define and create test cases for our purple team runbooksIntroIn our purple team service, we try to take a depth and quality approach and run many different functionally diverse test ...

Part 13
On Detection: Tactical to FunctionalWhy a Single Test Case is InsufficientIntroductionIn my previous post, I explored the idea that different tools can implement the same operation chain (behavior) in various ways. I ...

To Infinity and Beyond!
Increasing our understanding of EDR capabilities in the face of impossible odds.IntroductionI recently had a discussion with our chief strategist, Jared Atkinson, about purple teaming. We believe that large quantities of procedures ...

Reactive Progress and Tradecraft Innovation
Detection as PredictionThe overarching goal of a security operations program is to prevent or mitigate the impact of an attacker gaining unauthorized access to an IT environment. In service of this mission, ...

Leveraging Wargaming Principles for Cyberdefense Exercises
Wargames are an excellent way to ensure your cyberdefense plans are solid and your processes are current ...

BSidesKC 2021 – David Evenden’s ‘Emulating The Adversary While Training The Defenders: Purple Teaming With MITRE ATT&CK’
Our thanks to BSidesKC for publishing their outstanding BSidesKC 2021 videos on the Conferences’ YouTube channel. Permalink ...

Threat Hunting Framework: Three Steps to Translate Threat Reports into Actionable Steps
Thanks to Sally Vincent and Dan Kaiser from the LogRhythm Labs team for developing the process and guiding content described in this post. Threat research can be an invaluable asset to security ...

WebApp Security, ‘My Experience Leading A Purple Team’
A terrific Red & Blue (in reality - Purple's the Word, in this case) Teaming Leadership post (via Robert A., posting on the Web Application Security Consortium List) detailing his experience leading ...

The Purple Team Pentest
It’s not particularly clear whether a marketing intern thought he was being clever or a fatigued pentester thought she was being cynical when the term “Purple Team Pentest” was first thrown around ...

Navigating the "Pentest" World
The demand for penetration testing and security assessment services worldwide has been growing year-on-year. Driven largely by Governance, Risk, and Compliance (GRC) concerns, plus an evolving pressure to be observed taking information ...