The Purple Team brings the functions closer together:
Red Team
And
Blue Team.
The Red Team simulates attack techniques.
The Blue Team is trying to detect them.
The SIEM is then used to determine:
- What events are generated?
- which rules work
- which rules fail
- what data is missing
- How to improve detection.
This approach allows for a gradual improvement in the maturity of detection.