Skip to main content

Practising what counts on the day

Purple team, red team and crisis exercise. We run the attack step by step and hold up beside it what your detection saw of it.

Angriffsschritte gegen das, was bemerkt wurde Sechs Schritte eines Angriffs auf einer Zeitachse. Darunter, was die Verteidigung davon gesehen hat und was nicht. ATTACK DETECTED 2 OF 6 EXERCISE · RED, BLUE, PURPLE
Trusted by
The starting position

A dashboard shows hits, not gaps

EDR and SIEM report what was detected. What got through does not appear there, in the nature of things, and that is the number that counts. No tool can answer that question by itself, because it has nothing to compare against.

An exercise turns it round. We run an attack step by step, log every one, and hold up beside it what your team saw. At the end there is a list: these steps were visible, these were not, and these are the reasons.

Two detected steps out of six is not a bad result. It is the starting point for the four missing rules.

Three formats

From checking a rule to the real thing

Which format fits depends on what you want to test: the technology, the team, or the decision paths.

Purple team

Attack and defence at the same table. We run techniques from MITRE ATT&CK one at a time, your team watches and hunts alongside. The fastest route to new detection rules, because the finding and the fix come about in the same room.

Red team

An attack with no warning against an objective fixed beforehand, over weeks rather than days. Tests the whole chain of detection, triage and response under real conditions.

Crisis exercise

A scenario at the table, for management, communications, legal and IT together. Tests the decisions, not the technology: who may shut things down, who speaks to the regulator, and when the reporting clock starts.

What comes out of it

The gap is the result, not the number of hits

Angriffsschritte gegen das, was bemerkt wurde Sechs Schritte eines Angriffs auf einer Zeitachse. Darunter, was die Verteidigung davon gesehen hat und was nicht. ATTACK DETECTED 2 OF 6 EXERCISE · RED, BLUE, PURPLE

We log every step executed, with a timestamp, a technique identifier from ATT&CK and the artefacts produced. Your team logs independently what arrived in the tools. The two side by side make the map.

For every step not detected we establish why: there was no log, there was a log and no rule, there was a rule and it was too narrow, or there was an alert and nobody worked on it. Those are four different problems with four different solutions.

The report ends with concrete rules you can adopt, along with the events they fire on.

How it runs

How a purple team exercise works

Two to five days, depending on scope.

1

Set the objectives

Which techniques do you want to test, and why. Usually that follows from what actually occurs in your sector, not from the complete ATT&CK matrix.

2

Execute and record

We work through the techniques one at a time, announced and traceable. Every step gets a timestamp and an identifier, so that it can be found again later.

3

Compare

What arrived in the SIEM, in the EDR and with the team. Together at the screen, not as a report two weeks later.

4

Write the rules

For the gaps that can be closed, detection rules come about during the exercise itself. The retest shows the same day whether they fire.

Where the scenarios come from

From incidents, not from a catalogue

Our scenarios come from what we actually see in penetration tests and in monitoring, and from the analysis of public incidents. For attacks on supply networks, for instance, we work with the analyses of the Polish CERT and with what is documented from Ukraine.

For exercises that are meant to run on real technology without touching your operations, we have rigs of our own. What is possible on them is set out under the demonstrators.

Common questions

Common questions about exercises

No. A penetration test looks for as many weaknesses as possible in a defined area and reports them. A red team pursues an objective and may take any route, but leaves much untested. If you want to know where the gaps are, take the test. If you want to know whether the detection holds, take the exercise.

For a purple team, yes, that is the point. For a red team only a small circle knows, so that the response is real. We fix in writing beforehand who is informed and how the exercise gets called off.

That is the normal case on a first exercise and the reason to hold one. A result of two detected steps out of six describes the rules that are still missing.

Yes, and it is often the best way in. A tabletop with management and communications takes half a day and regularly reveals that the reporting chain hangs on a phone number nobody has any more.

Credentials

Certifications and memberships.

Certifications held in the team
Memberships
eco – Verband der Internetwirtschaft
networker NRW
Next step

Talk to us.

A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.

Telephone
0231 39814905
Mon–Fri · 9am–5pm CET
Email
info@yekta-it.de
PGP key available
Location
Dortmund
Ruhrallee 9 · 44139