Red Team & Purple Team Australia

Can a real attacker beat your controls?

Vectra Red & Purple Teaming moves beyond finding isolated vulnerabilities. We emulate realistic attacker behaviour, pursue agreed objectives and test whether your people, processes and security technology can detect, contain and respond before the attacker succeeds.

Example mission
“Can an attacker compromise a standard user, move through identity and endpoint controls, and reach a sensitive business system without being stopped?”
Red TeamPursues the objective with realistic attacker tradecraft and limited defender knowledge.
Blue TeamDetects, investigates and responds using the organisation’s real security controls and processes.
Purple TeamBrings both sides together to test specific techniques, understand visibility gaps and improve detections in real time.
Threat informedScenarios mapped to relevant adversary behaviour and MITRE ATT&CK
Objective ledTest whether an attacker can achieve something that matters
Detection focusedValidate telemetry, alerting, investigation, escalation and response
Australian deliveryLocal offensive security specialists and clear rules of engagement
Beyond Penetration Testing

Penetration testing finds weaknesses. Red teaming tests the security system.

A penetration test is usually scoped around an application, network, API or other defined technology surface. Red teaming is broader and objective-driven. The team can chain together technical weaknesses, identity, cloud, social engineering and control gaps to simulate how a capable attacker would actually work toward a target.

Purple teaming takes that same attack behaviour and makes the defensive learning explicit. Offensive and defensive teams collaborate technique by technique to see what was visible, what was detected and what needs to change.

The outcome is not “we found 37 vulnerabilities.” It is “this is how far the attacker got, this is what your defenders saw, and this is what will stop them next time.”

Penetration TestFind and validate vulnerabilities inside a defined technical scope, then provide remediation guidance.
Red TeamSimulate an adversary pursuing agreed objectives across multiple attack surfaces while testing real detection and response capability.
Adversary EmulationModel the tactics, techniques and procedures of a relevant threat profile using MITRE ATT&CK as a common behavioural framework.
Purple TeamRun offensive techniques collaboratively with defenders to test visibility, detections, investigation logic and response procedures.
Assumed BreachBegin from a controlled foothold or compromised identity to spend more time testing lateral movement, privilege and high-value objectives.
Choose the Right Engagement

Different questions need different levels of attacker realism.

Red Team Assessment

Can the attacker achieve the objective?

A realistic, objective-led exercise designed to test the complete defensive environment with limited prior knowledge for operational defenders.

  • Defined target objectives
  • Realistic attack chains
  • Multiple security domains
  • Detection and response measurement
  • Executive and technical debrief
Purple Team Exercise

Can we see and stop each technique?

A collaborative exercise where offensive and defensive teams work together to replay relevant techniques, validate telemetry and improve detection and response.

  • MITRE ATT&CK mapped scenarios
  • Real-time defender observation
  • Detection engineering
  • Response and playbook validation
  • Rapid retesting
Assumed Breach

What happens after the first control fails?

Start from a controlled user, endpoint or identity position and spend the engagement testing internal attack paths instead of the initial foothold.

  • Identity attack paths
  • Privilege escalation
  • Lateral movement
  • Cloud and SaaS access
  • High-value asset objectives
Threat-Informed Adversary Emulation

Emulate behaviour that is relevant to your organisation.

MITRE ATT&CK gives offensive and defensive teams a common language for attacker behaviour. Vectra can use the framework alongside threat intelligence, industry context and the customer’s environment to build scenarios that represent realistic tactics and techniques rather than generic exploit demonstrations.

The exercise does not need to reproduce a named threat actor command-for-command. The objective is to model credible behaviour, safely test the defensive environment and generate useful evidence.

01
DEFINE THE THREATIdentify relevant attacker profiles, business assets, likely entry points and the security outcomes the organisation wants to validate.
02
MAP THE BEHAVIOURSelect appropriate ATT&CK tactics and techniques such as credential access, discovery, lateral movement, persistence and collection.
03
BUILD THE SCENARIOChain techniques into a realistic path toward the agreed objective while defining safety controls and stop conditions.
04
EXECUTERun the scenario using controlled attacker tradecraft across the approved environment.
05
MEASURE DEFENCERecord what generated telemetry, what alerted, what analysts investigated and where response actions interrupted the attack.
06
IMPROVE & RETESTTurn gaps into concrete changes to telemetry, detection logic, policy, playbooks or architecture and validate the improvement.
Modern Attack Surfaces

Today’s attack path rarely stays inside one security product.

A realistic adversary simulation can move across the controls and services an attacker would actually encounter. The exact techniques are agreed during scoping and remain subject to the rules of engagement.

Identity

Credentials & privilege

Authentication, identity attack paths, privilege escalation, service accounts and movement between user and administrative contexts.

Endpoint

Execution & persistence

Test endpoint controls, EDR visibility, malicious execution, persistence opportunities and defender response.

Cloud

Cloud control plane

Where in scope, test cloud identity, exposed services, permissions, secrets and movement into cloud-hosted workloads or data.

Microsoft 365 & SaaS

Modern productivity stack

Test relevant identity, session, application and collaboration attack paths across supported SaaS environments.

Network

Segmentation & movement

Assess whether network controls meaningfully constrain an attacker who already has an approved foothold.

People & process

Escalation & response

Validate whether operational teams recognise attack activity, escalate correctly and coordinate containment across technical owners.

Purple Teaming

Turn every offensive technique into a defensive improvement.

In a purple-team exercise, transparency is the advantage. Red and blue teams work through techniques together so defenders can see the attack, inspect the telemetry, validate the detection and immediately test a change.

This makes purple teaming particularly useful for SOC uplift, detection engineering, SIEM migrations, new EDR deployments and validating the effectiveness of an internal or outsourced security operations function.

ExecuteVectra performs an agreed attacker technique against the controlled target.
ObserveDefenders identify which endpoint, identity, network, cloud or SIEM telemetry captured the behaviour.
DetectValidate whether existing analytics alert with enough context and priority for an analyst to act.
InvestigateAssess whether analysts can reconstruct the activity, understand impact and identify the next attacker action.
RespondTest containment, escalation, communications and the relevant response playbook.
ImproveAdjust telemetry, detection logic, automation or process and replay the technique to prove the gap is closed.
What We Measure

Measure the defence, not the number of attacks performed.

Visibility

Did the required telemetry exist, reach the security platform and contain enough context to investigate?

Detection

Did the activity generate the right alert, at the right severity, before the attacker reached the next objective?

Investigation

Could analysts connect the activity across users, devices, identities and systems quickly enough?

Response

Did the team escalate and contain the incident effectively using the available controls and procedures?

Control effectiveness

Which preventative controls genuinely interrupted the attack and which were bypassed or misconfigured?

Automation

Where could enrichment, containment or workflow automation reduce analyst delay without creating unsafe response actions?

Attack path

How far could the attacker progress and which trust relationships created the largest downstream impact?

Improvement

Can the team prove that remediation changed the defensive outcome when the technique is replayed?

SOC & MSSP Validation

Test the security service under realistic pressure.

If detection and response is delivered by an internal SOC, an MSSP or a combination of both, red and purple teaming can validate the service from end to end.

The exercise can test more than whether a console generated an alert. It can measure whether telemetry arrived, the detection fired, analysts understood the event, escalation reached the right people and the response process actually changed the attacker’s outcome.

Telemetry coverageWas the relevant endpoint, identity, network, cloud or SaaS activity available to defenders?
Detection coverageWhich ATT&CK techniques were detected, missed or generated low-quality alerts?
Analyst handlingWas the activity triaged, contextualised and escalated correctly?
Response authorityDid the service have the access, approval and procedure needed to contain the activity?
Cross-team handoffDid security, identity, endpoint, cloud and IT teams coordinate without losing time or context?
Retest evidenceDid the updated control or process measurably improve the result when tested again?
Safe by Design

Realistic does not mean uncontrolled.

Every engagement operates under agreed rules of engagement. The red team needs enough freedom to behave realistically, while the customer needs clear protections around production availability, sensitive systems and business-critical processes.

ObjectivesDefine the business or security outcome the red team is trying to achieve before activity begins.
In-scope environmentDocument approved systems, users, identities, cloud resources, locations and testing windows.
Permitted techniquesAgree what forms of social engineering, exploitation, persistence, credential use and post-exploitation activity are authorised.
Stop conditionsDefine circumstances where testing must stop or escalate immediately to protect business operations and safety.
Data handlingSet expectations for evidence collection, sensitive-data access, storage, reporting and secure destruction.
Control contactsMaintain a small trusted group able to coordinate safety, deconflict real incidents and authorise changes to scope where needed.
What You Receive

A clear view of the attack path and what to improve next.

Executive attack narrative

What the attacker attempted, how far they progressed, what mattered and the material business impact of the successful paths.

ATT&CK mapping

Map relevant behaviours to MITRE ATT&CK tactics and techniques so offensive and defensive teams share a common language.

Detection findings

Document which actions were visible, alerted, investigated, missed or lacked sufficient context.

Attack-path evidence

Technical evidence showing how weaknesses, trust and controls combined to enable or prevent movement toward the objective.

Improvement backlog

Prioritised changes across prevention, telemetry, detections, playbooks, automation, identity and architecture.

Debrief & retest

Bring offensive and defensive teams together to review lessons and validate agreed improvements where included in scope.

Why Vectra

Offensive testing backed by real defensive operations.

Vectra combines Australian offensive-security capability with practical experience across SOC operations, EDR, SIEM, identity, cloud, incident response and compliance. That makes red and purple teaming especially useful when the goal is not simply to break something, but to improve how the full security system operates.

Australian deliveryLocal scoping, testing, debrief and customer engagement with Vectra security specialists.
CREST testing practiceVectra’s broader penetration testing capability is CREST accredited, with experienced offensive-security practitioners.
Defensive contextExperience across managed SOC, detection engineering, incident response and security operations gives the exercise operational relevance.
Platform depthUnderstand how endpoint, identity, SIEM, cloud, email and network controls interact rather than testing each technology in isolation.
Threat-informed approachUse attacker behaviour and MITRE ATT&CK to design scenarios that map to the organisation’s threat profile and objectives.
Remediation focusConvert findings into a practical backlog of detection, response, architecture and process improvements.
Red & Purple Team FAQs

Understanding adversary simulation.

What is a red team assessment?

A red team assessment is an authorised, objective-led adversary simulation. The red team uses realistic attack techniques to test whether it can achieve an agreed outcome against the organisation’s people, processes and security controls.

What is the difference between red teaming and penetration testing?

Penetration testing normally focuses on finding and validating vulnerabilities within a defined technical scope. Red teaming pursues broader objectives and can chain together multiple weaknesses and attack surfaces to test the effectiveness of the overall defensive environment.

What is purple teaming?

Purple teaming is a collaborative exercise where offensive and defensive teams work through attacker techniques together. The goal is to validate visibility, detection, investigation and response, then improve controls and replay the activity to confirm the gap is closed.

What is adversary emulation?

Adversary emulation uses known attacker behaviours, tactics, techniques and procedures to build a realistic security test. MITRE ATT&CK is commonly used as the framework for describing and mapping those behaviours.

What is an assumed-breach assessment?

An assumed-breach assessment begins from a controlled position that represents an attacker who has already obtained an initial foothold, such as a user identity or endpoint. This allows more engagement time to be spent testing privilege escalation, lateral movement and access to high-value systems.

Can a purple team validate our SOC or MSSP?

Yes. Purple teaming can test whether the required telemetry reaches the SOC, whether detections fire, how analysts investigate and escalate the activity, and whether response processes contain the simulated attack effectively.

Does Vectra use MITRE ATT&CK?

Vectra can map relevant adversary-emulation and purple-team activity to MITRE ATT&CK so offensive and defensive teams have a common language for attacker behaviour and detection coverage.

Can red-team activity include identity, cloud and SaaS?

Yes, where those systems and techniques are explicitly authorised in the rules of engagement. Modern attack paths frequently cross endpoint, identity, cloud, SaaS and network controls, so combined scopes can provide a more realistic assessment.

How do you keep red-team testing safe?

The engagement operates under documented rules of engagement covering scope, approved techniques, testing windows, stop conditions, data handling and trusted control contacts. Destructive or high-risk actions are not performed unless they are explicitly authorised and safely designed.

Test the Defence, Not Just the Technology

Find out how far a real attacker could get—and whether your team would stop them.

Talk to Vectra about a red team assessment, assumed-breach exercise, threat-informed adversary emulation or collaborative purple-team programme.

Plan an Adversary Simulation →
Red and purple team activities are performed only under explicit customer authorisation and agreed rules of engagement. Techniques, attack paths and depth depend on the approved scope, operational risk and safety constraints.