Vectra Red & Purple Teaming moves beyond finding isolated vulnerabilities. We emulate realistic attacker behaviour, pursue agreed objectives and test whether your people, processes and security technology can detect, contain and respond before the attacker succeeds.
“Can an attacker compromise a standard user, move through identity and endpoint controls, and reach a sensitive business system without being stopped?”
A penetration test is usually scoped around an application, network, API or other defined technology surface. Red teaming is broader and objective-driven. The team can chain together technical weaknesses, identity, cloud, social engineering and control gaps to simulate how a capable attacker would actually work toward a target.
Purple teaming takes that same attack behaviour and makes the defensive learning explicit. Offensive and defensive teams collaborate technique by technique to see what was visible, what was detected and what needs to change.
The outcome is not “we found 37 vulnerabilities.” It is “this is how far the attacker got, this is what your defenders saw, and this is what will stop them next time.”
A realistic, objective-led exercise designed to test the complete defensive environment with limited prior knowledge for operational defenders.
A collaborative exercise where offensive and defensive teams work together to replay relevant techniques, validate telemetry and improve detection and response.
Start from a controlled user, endpoint or identity position and spend the engagement testing internal attack paths instead of the initial foothold.
MITRE ATT&CK gives offensive and defensive teams a common language for attacker behaviour. Vectra can use the framework alongside threat intelligence, industry context and the customer’s environment to build scenarios that represent realistic tactics and techniques rather than generic exploit demonstrations.
The exercise does not need to reproduce a named threat actor command-for-command. The objective is to model credible behaviour, safely test the defensive environment and generate useful evidence.
A realistic adversary simulation can move across the controls and services an attacker would actually encounter. The exact techniques are agreed during scoping and remain subject to the rules of engagement.
Authentication, identity attack paths, privilege escalation, service accounts and movement between user and administrative contexts.
Test endpoint controls, EDR visibility, malicious execution, persistence opportunities and defender response.
Where in scope, test cloud identity, exposed services, permissions, secrets and movement into cloud-hosted workloads or data.
Test relevant identity, session, application and collaboration attack paths across supported SaaS environments.
Assess whether network controls meaningfully constrain an attacker who already has an approved foothold.
Validate whether operational teams recognise attack activity, escalate correctly and coordinate containment across technical owners.
In a purple-team exercise, transparency is the advantage. Red and blue teams work through techniques together so defenders can see the attack, inspect the telemetry, validate the detection and immediately test a change.
This makes purple teaming particularly useful for SOC uplift, detection engineering, SIEM migrations, new EDR deployments and validating the effectiveness of an internal or outsourced security operations function.
Did the required telemetry exist, reach the security platform and contain enough context to investigate?
Did the activity generate the right alert, at the right severity, before the attacker reached the next objective?
Could analysts connect the activity across users, devices, identities and systems quickly enough?
Did the team escalate and contain the incident effectively using the available controls and procedures?
Which preventative controls genuinely interrupted the attack and which were bypassed or misconfigured?
Where could enrichment, containment or workflow automation reduce analyst delay without creating unsafe response actions?
How far could the attacker progress and which trust relationships created the largest downstream impact?
Can the team prove that remediation changed the defensive outcome when the technique is replayed?
If detection and response is delivered by an internal SOC, an MSSP or a combination of both, red and purple teaming can validate the service from end to end.
The exercise can test more than whether a console generated an alert. It can measure whether telemetry arrived, the detection fired, analysts understood the event, escalation reached the right people and the response process actually changed the attacker’s outcome.
Every engagement operates under agreed rules of engagement. The red team needs enough freedom to behave realistically, while the customer needs clear protections around production availability, sensitive systems and business-critical processes.
What the attacker attempted, how far they progressed, what mattered and the material business impact of the successful paths.
Map relevant behaviours to MITRE ATT&CK tactics and techniques so offensive and defensive teams share a common language.
Document which actions were visible, alerted, investigated, missed or lacked sufficient context.
Technical evidence showing how weaknesses, trust and controls combined to enable or prevent movement toward the objective.
Prioritised changes across prevention, telemetry, detections, playbooks, automation, identity and architecture.
Bring offensive and defensive teams together to review lessons and validate agreed improvements where included in scope.
Vectra combines Australian offensive-security capability with practical experience across SOC operations, EDR, SIEM, identity, cloud, incident response and compliance. That makes red and purple teaming especially useful when the goal is not simply to break something, but to improve how the full security system operates.
A red team assessment is an authorised, objective-led adversary simulation. The red team uses realistic attack techniques to test whether it can achieve an agreed outcome against the organisation’s people, processes and security controls.
Penetration testing normally focuses on finding and validating vulnerabilities within a defined technical scope. Red teaming pursues broader objectives and can chain together multiple weaknesses and attack surfaces to test the effectiveness of the overall defensive environment.
Purple teaming is a collaborative exercise where offensive and defensive teams work through attacker techniques together. The goal is to validate visibility, detection, investigation and response, then improve controls and replay the activity to confirm the gap is closed.
Adversary emulation uses known attacker behaviours, tactics, techniques and procedures to build a realistic security test. MITRE ATT&CK is commonly used as the framework for describing and mapping those behaviours.
An assumed-breach assessment begins from a controlled position that represents an attacker who has already obtained an initial foothold, such as a user identity or endpoint. This allows more engagement time to be spent testing privilege escalation, lateral movement and access to high-value systems.
Yes. Purple teaming can test whether the required telemetry reaches the SOC, whether detections fire, how analysts investigate and escalate the activity, and whether response processes contain the simulated attack effectively.
Vectra can map relevant adversary-emulation and purple-team activity to MITRE ATT&CK so offensive and defensive teams have a common language for attacker behaviour and detection coverage.
Yes, where those systems and techniques are explicitly authorised in the rules of engagement. Modern attack paths frequently cross endpoint, identity, cloud, SaaS and network controls, so combined scopes can provide a more realistic assessment.
The engagement operates under documented rules of engagement covering scope, approved techniques, testing windows, stop conditions, data handling and trusted control contacts. Destructive or high-risk actions are not performed unless they are explicitly authorised and safely designed.
Talk to Vectra about a red team assessment, assumed-breach exercise, threat-informed adversary emulation or collaborative purple-team programme.