Skip to content

Home Expertise / Penetration testing

PEN / PEN-09

Purple teaming and control validation

Joint work between testers and defenders to verify that simulated malicious behaviour produces the expected signals and responses.

WHEN IT HELPS

A focused response
to a defined need.

SOC lead or CISO; new tools, insufficiently tested rules or a need to demonstrate detection coverage.

AT A GLANCE

Family
Penetration testing

Engagement
Testing

Reference
PEN-09

SCOPE & OUTCOMES

What the engagement covers.

Scope

  • Non-destructive scenarios
  • supervised execution
  • analysis of logs, alerts, observed timing and response procedures

Deliverables

  • Scenario-signal-alert matrix
  • tuned rules where included
  • revalidation evidence and remaining blind spots

Acceptance evidence

Each scenario has expected and observed results; gaps are retested after contractually included changes.

DELIVERY

How the work is structured.

Approach

Obtain authorisation and rules of engagement; prepare accounts and backups; perform controlled tests; debrief, clean up and arrange retesting.

Prerequisites & responsibilities

Customer: written authorisation, asset ownership, third-party permission, stop contacts and scope. Provider: bounded testing, minimal evidence and critical-finding notification.

Scope factors

Applications, roles, APIs, networks, business complexity, supplied access, depth and authorised windows. Black/grey/white box and retesting affect effort; price after scoping.

Questions to clarify

Which scenarios matter most? Do logs reach the SOC? Who can change rules and approve response actions?

IMPORTANT BOUNDARIES

Results apply to executed scenarios, not every attack; defender availability is essential.

No denial of service, destruction, real exfiltration or social engineering without explicit authorisation. Third parties are not tested merely at a customer’s request. Untested scope remains unassessed.

IN PRACTICE

Illustrative situations.

These examples describe possible engagements and target outcomes. They are not customer references or achieved results.

Scenario 01

A company has EDR, but alerts do not reach its SIEM. Project: replay a benign suspicious-behaviour simulation. Target outcome: fix the connector and confirm an analyst can work a usable incident.

Scenario 02

An internal SOC detects an alert, but nobody responds on call. Project: a coordinated exercise including escalation. Target outcome: correct contact lists and responsibilities; technical detection alone does not validate the response chain.

Technology and reference context

MITRE ATT&CK, SIEM, EDR and approved simulation tools.

The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.

CONNECTED SERVICES

Build the next step.

These services can complement the engagement. They are not automatically included.

START A CONVERSATION

Make the scope clear.

We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.