COLLABORATIVE VALIDATION / PURPLE TEAM

Turn an attack sequence into measurable detection improvement.

The objective is not simply to prove that a technique can run. Offensive and defensive stakeholders agree the scenario, observe what each control records, tune the relevant logic or process, and execute again. The output is evidence of what changed—not a generic maturity score.

AUTHORIZED ENGAGEMENT MODEL
01Attack02Observe03Tune04Re-test

REQUEST → SCOPE → AUTHORIZE → KICKOFF → EXECUTE

01

ASSESSMENT BOUNDARY

What is being assessed?

The engagement boundary is defined by systems, identities, workflows and restrictions—not only a list of URLs or assets.

  • Telemetry generated by agreed adversary techniques
  • Endpoint, identity, cloud and network visibility in scope
  • Prevention, detection and response behavior
  • Alert logic, investigation context and SOC handoffs
  • Collaborative control and detection tuning
  • Known gaps that require engineering or process change
02 / TEST MODEL

What Botnet tests.

Coverage follows reachable trust decisions and agreed risk, with destructive or disruptive actions excluded unless explicitly authorized.

01

Plan

Select techniques, hypotheses, data sources, expected signals and success criteria.

02

Execute

Run controlled actions with defenders positioned to observe the relevant systems.

03

Observe

Compare endpoint, identity, cloud, network and SIEM evidence available to the team.

04

Tune

Adjust detection logic, context, enrichment or response workflow where the client chooses.

05

Re-test

Repeat the agreed action to determine whether the change produces the intended result.

06

Measure

Record observed coverage, remaining gaps and owners without inventing a universal score.

03 / ENGAGEMENT

How the work progresses.

  1. 01

    Attack

    Execute agreed adversary techniques under defined safety and clean-up controls.

  2. 02

    Observe

    Reconcile offensive evidence with prevention, telemetry, detection and response behavior.

  3. 03

    Tune

    Work collaboratively with customer security and SOC teams to improve controls, detections or workflow where appropriate.

  4. 04

    Re-test

    Repeat the agreed activity and document whether the intended improvement is now observable.

04

EVIDENCE + ACTION

What the customer receives.

  • Technique and hypothesis plan with MITRE ATT&CK mapping where useful
  • Shared execution and observation timeline
  • Evidence of available and missing telemetry
  • Detection/control tuning observations
  • Re-test comparison
  • Prioritized backlog with responsible client stakeholders where agreed
05 / BOTNET APPROACH

Evidence over assumption.

01One evidence timeline for attackers and defenders

02Re-testing built into the collaboration loop

03Focus on observable control behavior instead of generic scores

04Flexible participation across SOC, detection engineering, identity, endpoint and cloud teams

06 / QUESTIONS

Before scoping.

Is a Purple Team engagement the same as a Red Team assessment?

No. Purple Team work is deliberately collaborative and visibility-focused. A Red Team assessment may use a less transparent adversary model and pursues an objective across a broader chain.

Does Botnet work with the SOC during tuning?

Yes. Purple Team engagements are collaborative. Botnet works with the customer’s security or SOC team to identify gaps and tune controls or detections where appropriate; customer-system changes remain controlled by the agreed access model.

Can one control or technique be tested?

Yes. A narrow hypothesis can be more useful than a broad exercise when the objective is to validate a specific telemetry or detection gap.

NEXT STEP

Define the target, constraints and required evidence.

An assessment request starts a scoping conversation. It does not authorize testing. Work proceeds only after scope acceptance, executed authorization/SOW and kickoff.