PurpleTeamAI is a publication by Hugh McGauran. It exists because most public security content is either vendor marketing, generic framework worship, or theatre dressed as strategy — and the practitioners running real programmes deserve sharper thinking than that.

What this publication is

  • Threat-model driven analysis, not checklist security. Generic MITRE ATT&CK checklists don't tell you anything about your environment. Threat-driven analysis does.
  • Detection engineering grounded in baseline and environment. What's normal here, before what's anomalous here.
  • Practical writing for teams that run real programmes. Operational detail, not strategy-deck bullet points.

What this publication isn't

  • No vendor fluff. No sponsored content without disclosure.
  • No generic frameworks presented as if they were new methodology.
  • No theatre dressed up as strategy.

About the author

Hugh McGauran is a cybersecurity practitioner working across enterprise security operations, purple team methodology, and detection engineering. He writes here because most public security content is either vendor marketing, generic framework worship, or theatre dressed as strategy — and the practitioners running real programmes deserve sharper thinking than that.

You can reach Hugh McGauran at hello@purpleteam.ai. They're on Twitter and LinkedIn.