Purple Team Exercise

Plan and run a purple-team detection-validation exercise: a controlled, cooperative test of whether your telemetry and detections would see a chosen set of adversary behaviors, not an attack. Use it to turn a threat profile or an incident into scenarios, pick ATT&CK techniques, map each to public adversary-emulation content by name or ID (Atomic Red Team, MITRE CALDERA, Stratus Red Team, MITRE ATT&CK Evaluations emulation plans), write rules of engagement and a safety and comms plan, define expected telemetry per technique, score each as alerted / logged-only / not-visible, measure time-to-detect, and convert the gaps into a detection backlog. Reach for it when someone says "purple team", "detection validation", "adversary emulation", "run some atomics", "test our detections", "MITRE coverage assessment", "are we detecting X", "validate the SOC", or asks to build a scorecard or an exercise plan. This skill contains no attack commands and never runs the tests; it plans, coordinates, and scores.

ftrout Updated

File contents

ftrout/secops-claude-skills/tree/main/skills/purple-team-exercise commit 06b4cc1e58

Frequently asked questions

npx skillmds@latest add ftrout/purple-team-exercise