Home/Services/Purple Team Assessment
security service

Purple Team Assessment

Purple team assessment across Europe: our attackers and your defenders work side by side against MITRE ATT&CK TTPs to prove and tune detection. Fixed price.

Manual, expert-ledEvidence-based findingsFree remediation retest

A purple team assessment answers a question a normal pentest cannot: when a real attacker runs their playbook against you, does your SOC actually see it, and can your team respond in time? We put our offensive engineers and your defenders in the same room, run adversary techniques step by step, and leave you with detections that fire and analysts who know what to do.

What a purple team assessment actually covers

Red team tests whether an attacker can get in. Blue team tries to stop them. Purple team removes the wall between the two so that every attack is also a lesson: we execute a technique, watch together whether your tooling caught it, and if it did not, we build the detection on the spot and run it again. The goal is not a scorecard. It is a measurable jump in what your defence can see and how fast it responds, technique by technique, with your own analysts doing the work so the improvement stays after we leave.

Adversary emulation mapped to MITRE ATT&CK, from initial access to exfiltration
Detection validation: which techniques your SIEM, EDR and logs actually catch
Live detection engineering: writing and tuning rules against real telemetry, then retesting
Response drill: measuring mean time to detect and to respond across the kill chain
Coverage mapping: a technique-by-technique heat map of visibility gaps and blind spots
Threat-led scenarios modelled on the groups that actually target your sector
Analyst upskilling: your team learns to hunt and write rules during the engagement

How a purple team engagement works

This is collaborative by design. Our offensive engineers, all OSCP or OSWE certified and experienced in adversary emulation, work directly with your SOC or managed detection provider. A red purple team assessment run this way turns each attack into shared knowledge rather than a surprise at the debrief.

Planning and threat modelling

We start by agreeing which adversaries matter to you. A payments company faces different techniques than a hospital or a logistics firm, so we build the emulation plan around the groups and TTPs realistic for your sector, drawn from MITRE ATT&CK and current threat intelligence. Together we set the objectives, the rules of engagement, and the metrics we will measure against.

Emulation and live validation

We execute techniques in a controlled sequence: initial access, execution, persistence, privilege escalation, credential access, lateral movement, and exfiltration. After each one we pause with your defenders and check the evidence. Did the EDR alert? Did the log reach the SIEM? Did a rule fire, or did the activity pass unseen? Every technique is recorded as detected, partially detected, or missed, with the exact telemetry that should have caught it.

Detection engineering in the room

Where a technique was missed, we do not just note it. We work with your team to build or tune the detection against your real telemetry, using the log sources you already have, then rerun the technique to confirm the rule fires without drowning analysts in false positives. This is where a purple team security assessment pays for itself: you leave with detections that work, not a wish list.

Response measurement and reporting

Throughout, we measure how quickly the team detects and responds, and where handoffs stall. The report captures the before-and-after coverage, the new detections, the response timings, and a prioritised plan for the gaps that remain. We walk your leadership and your analysts through it live, so the people who run your defence day to day own the outcome rather than reading about it second-hand.

ATT&CK
every technique mapped and scored
Live
detections built and retested during the engagement
Before/after
measurable coverage improvement

What a purple team assessment reveals

Most organisations discover their real detection coverage is far below what their tooling promised on the datasheet. The gaps cluster in predictable places.

Telemetry that never arrives

Detections cannot fire on data the SIEM never received. We routinely find endpoints without EDR, PowerShell or command-line logging switched off, cloud audit logs disabled, and network segments with no visibility at all. Fixing the pipeline often matters more than writing another rule.

Rules that look right but do not fire

Detection content that was never validated against a live attack tends to fail quietly: a rule scoped too narrowly, a field mapping that broke after a log-format change, or an alert routed to a queue nobody watches. Running the actual technique is the only honest test of whether the rule works.

Alert fatigue and slow response

Sometimes the alert fires and nothing happens, because it is one of a thousand a day. We measure how noise, unclear runbooks and manual handoffs stretch your response time, and we help tune signal-to-noise so the alerts that matter get acted on.

Lateral movement and privilege blind spots

Initial access often gets caught while the far more damaging steps, such as credential dumping, Kerberos abuse and lateral movement, go unseen. We map exactly where along the kill chain an attacker becomes invisible to you, which is the coverage most worth closing.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

Purple, red and blue: which one you need

These are not the same engagement, and buying the wrong one wastes money.

How purple differs from a red team

A red team is covert and goal-driven: get to the crown jewels without being caught, and report how. It is the right choice when you want to test whether you can be breached and how your team reacts to a genuine, unannounced intrusion. A purple team is open and collaborative, optimised for improving detection breadth quickly rather than proving a single attack path.

When purple is the better spend

If you have invested in a SOC, an EDR and a SIEM and want to know what they actually catch, purple team gives you far more coverage improvement per euro than a covert red team. Many clients run a purple team first to raise their baseline, then a red team later to test the improved defence under realistic conditions. We are happy to advise which fits your maturity, and there is no upsell in that advice; the honest answer sometimes is that you are not ready for a red team yet.

Techniques and telemetry we work across

A purple team is only as good as the range of realistic attacker behaviour it exercises and the depth of the telemetry it can reason about. We emulate against the tooling you already run rather than asking you to buy something new.

Attacker techniques we emulate

Typical scenarios include phishing and initial-access payloads, living-off-the-land execution through PowerShell and scripting hosts, credential theft such as LSASS access and Kerberoasting, token abuse, lateral movement over SMB and remote services, defence evasion, and staged data exfiltration. Each is drawn from real intrusion tradecraft and mapped to its ATT&CK technique so nothing is abstract.

Telemetry and tooling we validate

We work with EDR platforms such as Microsoft Defender, CrowdStrike and SentinelOne, SIEMs including Microsoft Sentinel, Splunk and Elastic, plus identity logs from Active Directory and Entra ID and cloud audit trails from AWS, Azure and GCP. The point is to prove and improve detection in your environment, on your licences, with rules your team will maintain after we leave.

Compliance and regulatory drivers

Threat-led and intelligence-led testing is increasingly written into European regulation, and a purple team assessment produces exactly the evidence these frameworks ask for.

DORA and threat-led testing

For financial entities, DORA introduces threat-led penetration testing (TLPT) aligned with the TIBER-EU framework, which expects intelligence-driven emulation of real adversaries and evidence of detection and response capability. Our emulation plans and coverage reporting map directly to that expectation.

ISO 27001, NIS2 and ATT&CK alignment

The results feed ISO 27001 continual-improvement and incident-management controls, support NIS2 obligations on detection and response for essential and important entities, and give you a MITRE ATT&CK coverage baseline you can track over time. Reports are written under NDA and structured for both your board and your auditors.

What you get from the engagement

Knowledge that stays with your team, not just a document.

  • An executive summary with your before-and-after detection coverage and response metrics
  • A technique-by-technique ATT&CK heat map showing what was detected, partially detected or missed
  • The new and tuned detection rules built during the engagement, in your own tooling
  • Prioritised remediation for telemetry gaps, weak rules and response bottlenecks
  • Hands-on upskilling for your analysts in detection engineering and threat hunting
  • A live walkthrough with both your leadership and your SOC

Everything is delivered under NDA, and all engagement data is handled securely and destroyed on request.

Pricing

Pricing depends on scope: how many attack scenarios and ATT&CK techniques, the size of your environment, how many defenders take part, and whether it is a one-off or a recurring programme. Here is the shape of a typical European engagement.

Engagement What’s included Timeline Price
Focused One threat scenario, a defined ATT&CK subset (e.g. endpoint and identity), live validation and detection tuning, coverage report and retest of tuned rules 1–2 weeks from €12,000
Standard Full kill-chain emulation across endpoint, identity, network and cloud, multiple scenarios, detection engineering across your SIEM and EDR, response measurement 2–4 weeks €18,000–€30,000
Advanced Intelligence-led, DORA/TIBER-aligned emulation of sector-specific adversaries across a large estate, with deep detection build-out and analyst training 4–6 weeks €30,000–€60,000
Continuous programme Recurring purple team cycles with tracked coverage improvement quarter over quarter ongoing from €4,000/month
Custom / large estate Multi-region or complex hybrid environments, scoped after a free call on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call — no hourly surprises, and a retest of the tuned detections is included. Get a fixed quote

FAQ

How much does a purple team assessment cost?
Purple team assessment cost starts from €12,000 for a focused single-scenario engagement and rises with the number of scenarios, the size of the environment and how much detection engineering is involved. You get a fixed price after a free scoping call.
How long does a purple team engagement take?
A focused engagement runs one to two weeks; a full kill-chain programme across endpoint, identity, network and cloud is usually two to four weeks. The collaborative format means your team is learning throughout, not waiting for a final report.
What is the difference between a red team and a purple team assessment?
A red team is covert and tests whether an attacker can reach a goal undetected. A purple team is open and collaborative, running techniques alongside your defenders to validate and build detections. Purple usually gives more detection-coverage improvement per euro; many clients do purple first, then red.
Do we need a mature SOC before this is worthwhile?
No, though you do need some detection tooling, such as an EDR and a SIEM or log pipeline, for us to validate and tune. If coverage is thin, that is precisely what the engagement exposes and starts fixing.
Will this help with DORA or TIBER-EU requirements?
Yes. Our intelligence-led emulation and coverage reporting map to DORA threat-led penetration testing and the TIBER-EU framework, and the deliverables also support ISO 27001 and NIS2 detection and response obligations.
Do you use MITRE ATT&CK?
Throughout. Every technique we run is mapped to ATT&CK, and you get a technique-by-technique heat map of what your defences detected, partially detected or missed, which becomes a baseline you can track over time.
Will you actually build detections, or just report gaps?
We build them with you, in your own tooling, against your real telemetry, then rerun the technique to confirm each rule fires cleanly. Leaving you with working detections rather than a list is the point of the exercise.
Is everything kept confidential?
Every engagement runs under NDA. Emulation plans, findings and any telemetry we touch are handled securely and destroyed on request, and results are shared only with the people you name.

Related services

Who needs this

Organisations with a SOC, EDR and SIEM who want to know what their detection actually catches, financial entities preparing for DORA threat-led testing, and security teams looking to raise detection coverage and sharpen response before a real incident.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Purple Team Assessment"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.