Awesome Purple Teaming 
What is a Purple Team?
Purple Teams vs. Red Teams vs. Blue Teams
| Phase | Objective | Key activities | Recommended tools | Primary output |
|---|---|---|---|---|
| 1. Scope and authorize | Establish safe and measurable exercise boundaries | Define objectives, authorized systems, test windows, responsibilities, rules of engagement and stop conditions | VECTR, PlexTrac, AttackForge, Jira, Azure DevOps | Approved exercise plan and rules of engagement |
| 2. Model threats | Identify adversary behaviors relevant to the organization | Review threat intelligence, select attack scenarios and map tactics, techniques and procedures | MITRE ATT&CK, ATT&CK Navigator, Control Validation Compass | Prioritized ATT&CK techniques and threat scenarios |
| 3. Prepare the environment | Create a controlled environment and confirm visibility | Configure test systems, accounts, logging, time synchronization, SIEM ingestion, backups and recovery procedures | DetectionLab, Splunk Attack Range, GOAD, AutomatedLab, CloudGoat, Kubernetes Goat | Test environment with verified telemetry |
| 4. Run atomic tests | Validate one technique or security control at a time | Execute small, controlled tests and verify prevention, telemetry and alert generation | Atomic Red Team, Invoke-AtomicRedTeam, PurpleSharp, Stratus Red Team | Pass or fail result for each tested technique |
| 5. Emulate adversaries | Test defenses against realistic, multi-step attack chains | Execute scenarios involving discovery, execution, persistence, privilege escalation and lateral movement | Apache CALDERA, SCYTHE, Prelude Operator, Infection Monkey, MITRE emulation plans | End-to-end attack narrative and control-validation results |
| 6. Collect telemetry | Verify the availability of endpoint, network, identity and cloud data | Collect process events, authentication records, network activity, packets and cloud audit logs | Sysmon, Velociraptor, Zeek, Suricata, Security Onion, Wazuh, Arkime | Searchable evidence and telemetry-coverage map |
| 7. Validate detections | Determine whether simulated behaviors are detected correctly | Run detection queries, review alerts and investigate false positives and false negatives | Sigma, YARA, Chainsaw, Hayabusa, Zircolite, KQL, SPL, Elastic Detection Rules | Validated analytics and documented detection gaps |
| 8. Validate response | Test analyst workflows and automated response capabilities | Triage alerts, enrich evidence, create cases, isolate systems and execute response playbooks | TheHive, Cortex, Shuffle, Microsoft Sentinel, Microsoft Defender XDR, SOAR platforms | Incident timeline and response-performance results |
| 9. Analyze attack paths | Identify routes that could enable broader compromise | Analyze identity relationships, excessive privileges, exposed services and cloud permissions | BloodHound, AzureHound, Adalanche, PingCastle, Purple Knight, CloudFox, Cartography | Prioritized identity and infrastructure attack paths |
| 10. Measure and report | Convert technical results into actionable measurements | Record prevention, visibility, detection and response outcomes; assign remediation owners | VECTR, ATT&CK Navigator, DefectDojo, PlexTrac, Grafana | Coverage dashboard, findings report and remediation backlog |
| 11. Remediate and tune | Close identified security gaps | Improve logging, change configurations, create detections, adjust controls and refine response playbooks | Sigma, SIEM and EDR platforms, configuration-management tools, Jira, Azure DevOps | Updated controls, detections and response procedures |
| 12. Retest continuously | Verify remediation and prevent security regressions | Repeat failed tests, schedule recurring validation and monitor coverage over time | Atomic Red Team, Apache CALDERA, VECTR, BAS platforms, CI/CD pipelines | Verified remediation and security-maturity trends |
You can access the my other awesome lists here
Contributions of any kind welcome, just follow the guidelines!
