Detection Alchemy - The Purple Team Way
ID: bb5bfa1c-db30-5eed-806a-88ad8dd65096
STIX ID: report--bb5bfa1c-db30-5eed-806a-88ad8dd65096
Feed Name: TrustedSec blog
TrustedSec's document explains the concept, goals, and execution of purple team engagements — combining offensive (red) and defensive (blue) activities to build high-fidelity detections, tune SIEM/EDR telemetry, and improve organizational defensive posture. It outlines TrustedSec's methodology, the 3D evaluation (detection, deflection, deterrence), phases of an engagement (control evaluation, attack execution and detection crafting, validation/tuning, analyst instruction), and uses Kerberoasting as an illustrative detection/use-case example.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
