Practitioner field notes

The practitioner's guide to purple teaming.

Practitioner-led writing on threat-model discipline, detection engineering, realistic red teaming, and the operational work required to make red and blue teams genuinely effective together.

RED TEAM BLUE TEAM PURPLE
Where offence and defence meet

Archive

All essays, newest first

Offence Defence Where they meet
  1. What a Good ICS Detection Looks Like in Practice

    There is a lot of advice about ICS detection that talks about MODBUS, DNP3, and the protocol layers. This is the part that comes after the protocol talk: what a good detection actually looks like in the SIEM, and what the SOC analyst does with it

    ICS OT Security Detection Engineering

  2. How to Threat-Model a System You Have Never Seen Before

    Most threat-modelling advice assumes you have weeks, a working relationship with the engineering team, and a system that is stable. None of those apply when you are walking into a new environment on a Tuesday afternoon. Here is the version that does

    Threat Modelling Purple Teaming

  3. How to Build an Insider-Risk Programme That Actually Catches the Bad Cases

    Most insider-risk programmes are aimed at the wrong target. The detection engineering is theatre. The behavioural analytics are noise. The case management is a black hole. Here is how to build a programme that finds the cases that actually matter

    Insider Threat Detection Engineering Blue Team

  4. The Detection Rule That Changed How I Think About Fidelity

    There is one detection rule in my career that genuinely changed how I think about detection fidelity. It was not a clever rule. It was a simple rule. The simplicity is what taught me the most. Here is the rule and what it taught me

    Detection Engineering

  5. What a CISO Actually Does on a Tuesday Afternoon

    The CISO job description reads like a strategy role. The actual job is mostly operational. Here is what a competent CISO does on a typical Tuesday afternoon, and what the things look like in practice

    Purple Teaming Threat Modelling

  6. How to Hire a Detection Engineer When You Have Never Hired One Before

    Most detection engineer hiring fails because the job description is wrong. Here is what to actually look for, what to test in the interview, and the most common mistakes programmes make on the first hire

    Detection Engineering Blue Team

  7. How to Run a Purple Team Exercise When Nobody Has Done One Before

    Most purple team advice is written for teams that have done several. Here is the version for the team that is about to do their first one, in order, with the parts that most programmes get wrong

    Purple Teaming

  8. Tabletop Exercises That Actually Prepare You for an Incident

    Most tabletops are theatre. A senior person reads a scenario, the room talks through what they would do, nobody changes anything, and the postmortem is a one-pager that says 'we are well prepared.' Here is how to run one that is not theatre

    Purple Teaming Blue Team

  9. The Six-Month Build: What a Real Detection Engineering Programme Looks Like

    Most 'detection engineering programmes' are not programmes. They are a person with a Sigma rule and a prayer. Here is what a real six-month build looks like, in order, and what each phase actually costs

    Detection Engineering Blue Team

  10. Why Most Threat Intelligence Programmes Are Not Worth the Money

    Threat intelligence is one of the most expensive parts of a security programme and one of the most under-used. Most programmes pay for feeds they do not read, run platforms they do not use, and produce reports that do not change anything. Here is the honest version of the work

    Threat Modelling Purple Teaming

  11. The Red Team Engagement That Changed How I Think About Risk

    There is one engagement in my career that genuinely changed how I think about cybersecurity risk. It was not the most sophisticated operation I have run. It was not the most expensive. It was the one that taught me the most. Here is what it was and what it taught me

    Red Team Purple Teaming

  12. What I Look For in a Red Team Report

    Most red team reports are unreadable. The good ones are gold. Here is what makes the difference, in order, with the parts that most red teamers get wrong

    Red Team Purple Teaming

  13. What a Good Detection Engineer Actually Does All Day

    The job description for a detection engineer reads like a software engineer with a security focus. The actual job is more like an editor at a small newspaper. Here is what the work looks like when the title is right and the work is also right

    Detection Engineering Blue Team

  14. Building a Detection Baseline: The Work Nobody Wants to Do

    Every detection engineer has been told to build a baseline. Almost nobody has been given a clear answer about what a baseline actually is, what data it needs, or how it connects to the rules the SOC actually runs. Here is the honest version of the work

    Detection Engineering Blue Team

  15. Purple Teaming at Scale: How It Changes When You Have 20 Blue Team Analysts

    Most purple team advice is written for a team of three. If you scale to twenty, the bottlenecks move, the failure modes change, and the programme either matures or quietly dies on contact with reality. Here is what shifts, and what does not

    Purple Teaming Detection Engineering

  16. Adversary Emulation vs Penetration Testing: Why the Distinction Matters

    You paid €80,000 for a \"red team engagement.\" The report arrived with 47 findings, a 12-page executive summary, and a heat map of your network that looked like something out of a disaster movie

    Red Team Purple Teaming

  17. How to Write a Purple Team Report That Actually Gets Read

    You ran a three-week purple team exercise. Your team worked hard. The red team executed a realistic adversary emulation. Your blue team detected some of it, missed most of it, and the gaps are clear. The debrief went…

    Purple Teaming Red Team Blue Team

  18. Living Off the Land: Why the Best Attackers Don't Look Like Attackers

    Volt Typhoon maintained access to critical infrastructure networks in the United States for at least five years. Microsoft, Mandiant, and the Five Eyes governments published the technical details in 2024. The…

    Detection Engineering Red Team Blue Team

  19. The Insider Threat Problem Is Not What You Think

    Your insider threat programme is aimed at the wrong target

    Insider Threat Detection Engineering Threat Modelling

  20. The 7 Most Pointless Findings in OT Pen Tests

    If you run enough OT pen tests, you start to notice a pattern. The report arrives, the client is confused, and the findings have a peculiar quality: technically correct, operationally impossible to remediate, and…

    OT Security Purple Teaming ICS Pen Testing

  21. Purple Teaming OT: Why \"We Can't Test That\" Is No Longer Acceptable

    I keep hearing the same thing in conversations about operational technology security

    OT Security Purple Teaming ICS Critical Infrastructure

  22. How to Scope a Red Team Engagement That Tells You Something Real

    Most red team engagements produce an impressive document and a set of \"critical findings\" that the security team could have predicted before the first phishing email was sent

    Red Team Purple Teaming Threat Modelling

  23. Purple Teaming That Actually Works: A Framework for Real Collaboration

    You've got a red team and a blue team. They hate each other

    Purple Teaming

  24. Why Your Red Team Tests Are Designed to Fail, And You Don't Know It

    Red team comes in on Monday. They've got a scope, a timeline, and a list of techniques to test. By Friday, they've \"successfully executed\" initial access, lateral movement, persistence, and exfiltration

    Purple Teaming

  25. Detection Engineering in a Real Environment: Why Generic Rules Fail

    I walked into a SOC last month where they'd deployed 847 Sigma rules

    Purple Teaming

  26. Your Purple Team Test Failed Because Your Threat Model Is Wrong

    You ran a purple team exercise last week. Your red team executed a flawless attack chain: initial access via phishing, lateral movement via Kerberos relay, privilege escalation, and data exfiltration. Picture perfect

    Purple Teaming