Turn an attack sequence into measurable detection improvement.
The objective is not simply to prove that a technique can run. Offensive and defensive stakeholders agree the scenario, observe what each control records, tune the relevant logic or process, and execute again. The output is evidence of what changed—not a generic maturity score.
REQUEST → SCOPE → AUTHORIZE → KICKOFF → EXECUTE
ASSESSMENT BOUNDARY
What is being assessed?
The engagement boundary is defined by systems, identities, workflows and restrictions—not only a list of URLs or assets.
- Telemetry generated by agreed adversary techniques
- Endpoint, identity, cloud and network visibility in scope
- Prevention, detection and response behavior
- Alert logic, investigation context and SOC handoffs
- Collaborative control and detection tuning
- Known gaps that require engineering or process change
What Botnet tests.
Coverage follows reachable trust decisions and agreed risk, with destructive or disruptive actions excluded unless explicitly authorized.
Plan
Select techniques, hypotheses, data sources, expected signals and success criteria.
Execute
Run controlled actions with defenders positioned to observe the relevant systems.
Observe
Compare endpoint, identity, cloud, network and SIEM evidence available to the team.
Tune
Adjust detection logic, context, enrichment or response workflow where the client chooses.
Re-test
Repeat the agreed action to determine whether the change produces the intended result.
Measure
Record observed coverage, remaining gaps and owners without inventing a universal score.
How the work progresses.
- 01
Attack
Execute agreed adversary techniques under defined safety and clean-up controls.
- 02
Observe
Reconcile offensive evidence with prevention, telemetry, detection and response behavior.
- 03
Tune
Work collaboratively with customer security and SOC teams to improve controls, detections or workflow where appropriate.
- 04
Re-test
Repeat the agreed activity and document whether the intended improvement is now observable.
EVIDENCE + ACTION
What the customer receives.
- Technique and hypothesis plan with MITRE ATT&CK mapping where useful
- Shared execution and observation timeline
- Evidence of available and missing telemetry
- Detection/control tuning observations
- Re-test comparison
- Prioritized backlog with responsible client stakeholders where agreed
Evidence over assumption.
01One evidence timeline for attackers and defenders
02Re-testing built into the collaboration loop
03Focus on observable control behavior instead of generic scores
04Flexible participation across SOC, detection engineering, identity, endpoint and cloud teams
Before scoping.
Is a Purple Team engagement the same as a Red Team assessment?
No. Purple Team work is deliberately collaborative and visibility-focused. A Red Team assessment may use a less transparent adversary model and pursues an objective across a broader chain.
Does Botnet work with the SOC during tuning?
Yes. Purple Team engagements are collaborative. Botnet works with the customer’s security or SOC team to identify gaps and tune controls or detections where appropriate; customer-system changes remain controlled by the agreed access model.
Can one control or technique be tested?
Yes. A narrow hypothesis can be more useful than a broad exercise when the objective is to validate a specific telemetry or detection gap.
Define the target, constraints and required evidence.
An assessment request starts a scoping conversation. It does not authorize testing. Work proceeds only after scope acceptance, executed authorization/SOW and kickoff.