Purple Team Exercise

Run an AUTHORIZED, collaborative purple-team exercise — turn each attack technique into a detection hypothesis, detonate it minimally and marked, and measure whether the blue side prevented it, detected it, or missed it entirely. Use this whenever the user wants to validate detection coverage, test whether a control or alert actually fires, close the loop between offensive testing and defensive telemetry, map findings to MITRE ATT&CK, or plan/run/write up a purple exercise. Trigger even when the user only says "did our SIEM catch this", "test our detections", "validate this control", "what's our coverage for technique X", "run a purple exercise", or hands over red-team findings and asks "would we have seen it". This skill measures and specifies detection; it does NOT author vendor rule syntax (that's the detection-engineering sibling) and does NOT generate turnkey exploits (detonations are minimal, marked, non-destructive).

annatchijova 4c8eabb 9.6 KB Updated

File contents

annatchijova/SKILLS/tree/main/purple-team-exercise commit 4c8eabbcd0

Frequently asked questions

npx skillmds@latest add annatchijova/purple-team-exercise