The Purple Team brings the functions closer together:

Red Team

And

Blue Team.

The Red Team simulates attack techniques.

The Blue Team is trying to detect them.

The SIEM is then used to determine:

  • What events are generated?
  • which rules work
  • which rules fail
  • what data is missing
  • How to improve detection.

This approach allows for a gradual improvement in the maturity of detection.

Categories: