Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

8 Commits
 
 
 
 
 
 

Repository files navigation

Awesome Purple Teaming Awesome

YouTube Reddit

GitHub   YouTube   My Awesome Lists

📖 Contents

What is a Purple Team?

Purple Teams vs. Red Teams vs. Blue Teams

Purple Team: Summary by Phase

Phase Objective Key activities Recommended tools Primary output
1. Scope and authorize Establish safe and measurable exercise boundaries Define objectives, authorized systems, test windows, responsibilities, rules of engagement and stop conditions VECTR, PlexTrac, AttackForge, Jira, Azure DevOps Approved exercise plan and rules of engagement
2. Model threats Identify adversary behaviors relevant to the organization Review threat intelligence, select attack scenarios and map tactics, techniques and procedures MITRE ATT&CK, ATT&CK Navigator, Control Validation Compass Prioritized ATT&CK techniques and threat scenarios
3. Prepare the environment Create a controlled environment and confirm visibility Configure test systems, accounts, logging, time synchronization, SIEM ingestion, backups and recovery procedures DetectionLab, Splunk Attack Range, GOAD, AutomatedLab, CloudGoat, Kubernetes Goat Test environment with verified telemetry
4. Run atomic tests Validate one technique or security control at a time Execute small, controlled tests and verify prevention, telemetry and alert generation Atomic Red Team, Invoke-AtomicRedTeam, PurpleSharp, Stratus Red Team Pass or fail result for each tested technique
5. Emulate adversaries Test defenses against realistic, multi-step attack chains Execute scenarios involving discovery, execution, persistence, privilege escalation and lateral movement Apache CALDERA, SCYTHE, Prelude Operator, Infection Monkey, MITRE emulation plans End-to-end attack narrative and control-validation results
6. Collect telemetry Verify the availability of endpoint, network, identity and cloud data Collect process events, authentication records, network activity, packets and cloud audit logs Sysmon, Velociraptor, Zeek, Suricata, Security Onion, Wazuh, Arkime Searchable evidence and telemetry-coverage map
7. Validate detections Determine whether simulated behaviors are detected correctly Run detection queries, review alerts and investigate false positives and false negatives Sigma, YARA, Chainsaw, Hayabusa, Zircolite, KQL, SPL, Elastic Detection Rules Validated analytics and documented detection gaps
8. Validate response Test analyst workflows and automated response capabilities Triage alerts, enrich evidence, create cases, isolate systems and execute response playbooks TheHive, Cortex, Shuffle, Microsoft Sentinel, Microsoft Defender XDR, SOAR platforms Incident timeline and response-performance results
9. Analyze attack paths Identify routes that could enable broader compromise Analyze identity relationships, excessive privileges, exposed services and cloud permissions BloodHound, AzureHound, Adalanche, PingCastle, Purple Knight, CloudFox, Cartography Prioritized identity and infrastructure attack paths
10. Measure and report Convert technical results into actionable measurements Record prevention, visibility, detection and response outcomes; assign remediation owners VECTR, ATT&CK Navigator, DefectDojo, PlexTrac, Grafana Coverage dashboard, findings report and remediation backlog
11. Remediate and tune Close identified security gaps Improve logging, change configurations, create detections, adjust controls and refine response playbooks Sigma, SIEM and EDR platforms, configuration-management tools, Jira, Azure DevOps Updated controls, detections and response procedures
12. Retest continuously Verify remediation and prevent security regressions Repeat failed tests, schedule recurring validation and monitor coverage over time Atomic Red Team, Apache CALDERA, VECTR, BAS platforms, CI/CD pipelines Verified remediation and security-maturity trends

Purple Team Tools

Scope and authorize

Model threats

Prepare the environment

Run atomic tests

Emulate adversaries

Collect telemetry

Validate detections

Validate response

Analyze attack paths

Measure and report

Remediate and tune

Retest continuously

AI-powered Purple Team Assistant Tools

My Other Awesome Lists

You can access the my other awesome lists here

Contributing

Contributions of any kind welcome, just follow the guidelines!

Contributors

Thanks goes to these contributors!

🔼 Back to top

About

Awesome Purple Teaming

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Contributors