Purple Team Assessment
Purple team assessment across Europe: our attackers and your defenders work side by side against MITRE ATT&CK TTPs to prove and tune detection. Fixed price.
A purple team assessment answers a question a normal pentest cannot: when a real attacker runs their playbook against you, does your SOC actually see it, and can your team respond in time? We put our offensive engineers and your defenders in the same room, run adversary techniques step by step, and leave you with detections that fire and analysts who know what to do.
What a purple team assessment actually covers
Red team tests whether an attacker can get in. Blue team tries to stop them. Purple team removes the wall between the two so that every attack is also a lesson: we execute a technique, watch together whether your tooling caught it, and if it did not, we build the detection on the spot and run it again. The goal is not a scorecard. It is a measurable jump in what your defence can see and how fast it responds, technique by technique, with your own analysts doing the work so the improvement stays after we leave.
How a purple team engagement works
This is collaborative by design. Our offensive engineers, all OSCP or OSWE certified and experienced in adversary emulation, work directly with your SOC or managed detection provider. A red purple team assessment run this way turns each attack into shared knowledge rather than a surprise at the debrief.
Planning and threat modelling
We start by agreeing which adversaries matter to you. A payments company faces different techniques than a hospital or a logistics firm, so we build the emulation plan around the groups and TTPs realistic for your sector, drawn from MITRE ATT&CK and current threat intelligence. Together we set the objectives, the rules of engagement, and the metrics we will measure against.
Emulation and live validation
We execute techniques in a controlled sequence: initial access, execution, persistence, privilege escalation, credential access, lateral movement, and exfiltration. After each one we pause with your defenders and check the evidence. Did the EDR alert? Did the log reach the SIEM? Did a rule fire, or did the activity pass unseen? Every technique is recorded as detected, partially detected, or missed, with the exact telemetry that should have caught it.
Detection engineering in the room
Where a technique was missed, we do not just note it. We work with your team to build or tune the detection against your real telemetry, using the log sources you already have, then rerun the technique to confirm the rule fires without drowning analysts in false positives. This is where a purple team security assessment pays for itself: you leave with detections that work, not a wish list.
Response measurement and reporting
Throughout, we measure how quickly the team detects and responds, and where handoffs stall. The report captures the before-and-after coverage, the new detections, the response timings, and a prioritised plan for the gaps that remain. We walk your leadership and your analysts through it live, so the people who run your defence day to day own the outcome rather than reading about it second-hand.
What a purple team assessment reveals
Most organisations discover their real detection coverage is far below what their tooling promised on the datasheet. The gaps cluster in predictable places.
Telemetry that never arrives
Detections cannot fire on data the SIEM never received. We routinely find endpoints without EDR, PowerShell or command-line logging switched off, cloud audit logs disabled, and network segments with no visibility at all. Fixing the pipeline often matters more than writing another rule.
Rules that look right but do not fire
Detection content that was never validated against a live attack tends to fail quietly: a rule scoped too narrowly, a field mapping that broke after a log-format change, or an alert routed to a queue nobody watches. Running the actual technique is the only honest test of whether the rule works.
Alert fatigue and slow response
Sometimes the alert fires and nothing happens, because it is one of a thousand a day. We measure how noise, unclear runbooks and manual handoffs stretch your response time, and we help tune signal-to-noise so the alerts that matter get acted on.
Lateral movement and privilege blind spots
Initial access often gets caught while the far more damaging steps, such as credential dumping, Kerberos abuse and lateral movement, go unseen. We map exactly where along the kill chain an attacker becomes invisible to you, which is the coverage most worth closing.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Purple, red and blue: which one you need
These are not the same engagement, and buying the wrong one wastes money.
How purple differs from a red team
A red team is covert and goal-driven: get to the crown jewels without being caught, and report how. It is the right choice when you want to test whether you can be breached and how your team reacts to a genuine, unannounced intrusion. A purple team is open and collaborative, optimised for improving detection breadth quickly rather than proving a single attack path.
When purple is the better spend
If you have invested in a SOC, an EDR and a SIEM and want to know what they actually catch, purple team gives you far more coverage improvement per euro than a covert red team. Many clients run a purple team first to raise their baseline, then a red team later to test the improved defence under realistic conditions. We are happy to advise which fits your maturity, and there is no upsell in that advice; the honest answer sometimes is that you are not ready for a red team yet.
Techniques and telemetry we work across
A purple team is only as good as the range of realistic attacker behaviour it exercises and the depth of the telemetry it can reason about. We emulate against the tooling you already run rather than asking you to buy something new.
Attacker techniques we emulate
Typical scenarios include phishing and initial-access payloads, living-off-the-land execution through PowerShell and scripting hosts, credential theft such as LSASS access and Kerberoasting, token abuse, lateral movement over SMB and remote services, defence evasion, and staged data exfiltration. Each is drawn from real intrusion tradecraft and mapped to its ATT&CK technique so nothing is abstract.
Telemetry and tooling we validate
We work with EDR platforms such as Microsoft Defender, CrowdStrike and SentinelOne, SIEMs including Microsoft Sentinel, Splunk and Elastic, plus identity logs from Active Directory and Entra ID and cloud audit trails from AWS, Azure and GCP. The point is to prove and improve detection in your environment, on your licences, with rules your team will maintain after we leave.
Compliance and regulatory drivers
Threat-led and intelligence-led testing is increasingly written into European regulation, and a purple team assessment produces exactly the evidence these frameworks ask for.
DORA and threat-led testing
For financial entities, DORA introduces threat-led penetration testing (TLPT) aligned with the TIBER-EU framework, which expects intelligence-driven emulation of real adversaries and evidence of detection and response capability. Our emulation plans and coverage reporting map directly to that expectation.
ISO 27001, NIS2 and ATT&CK alignment
The results feed ISO 27001 continual-improvement and incident-management controls, support NIS2 obligations on detection and response for essential and important entities, and give you a MITRE ATT&CK coverage baseline you can track over time. Reports are written under NDA and structured for both your board and your auditors.
What you get from the engagement
Knowledge that stays with your team, not just a document.
- An executive summary with your before-and-after detection coverage and response metrics
- A technique-by-technique ATT&CK heat map showing what was detected, partially detected or missed
- The new and tuned detection rules built during the engagement, in your own tooling
- Prioritised remediation for telemetry gaps, weak rules and response bottlenecks
- Hands-on upskilling for your analysts in detection engineering and threat hunting
- A live walkthrough with both your leadership and your SOC
Everything is delivered under NDA, and all engagement data is handled securely and destroyed on request.
Pricing
Pricing depends on scope: how many attack scenarios and ATT&CK techniques, the size of your environment, how many defenders take part, and whether it is a one-off or a recurring programme. Here is the shape of a typical European engagement.
| Engagement | What’s included | Timeline | Price |
|---|---|---|---|
| Focused | One threat scenario, a defined ATT&CK subset (e.g. endpoint and identity), live validation and detection tuning, coverage report and retest of tuned rules | 1–2 weeks | from €12,000 |
| Standard | Full kill-chain emulation across endpoint, identity, network and cloud, multiple scenarios, detection engineering across your SIEM and EDR, response measurement | 2–4 weeks | €18,000–€30,000 |
| Advanced | Intelligence-led, DORA/TIBER-aligned emulation of sector-specific adversaries across a large estate, with deep detection build-out and analyst training | 4–6 weeks | €30,000–€60,000 |
| Continuous programme | Recurring purple team cycles with tracked coverage improvement quarter over quarter | ongoing | from €4,000/month |
| Custom / large estate | Multi-region or complex hybrid environments, scoped after a free call | on scoping | custom |
Every engagement is fixed-price, quoted after a free 20-minute scoping call — no hourly surprises, and a retest of the tuned detections is included. Get a fixed quote
FAQ
How much does a purple team assessment cost?
How long does a purple team engagement take?
What is the difference between a red team and a purple team assessment?
Do we need a mature SOC before this is worthwhile?
Will this help with DORA or TIBER-EU requirements?
Do you use MITRE ATT&CK?
Will you actually build detections, or just report gaps?
Is everything kept confidential?
Related services
Organisations with a SOC, EDR and SIEM who want to know what their detection actually catches, financial entities preparing for DORA threat-led testing, and security teams looking to raise detection coverage and sharpen response before a real incident.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.