

<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
  <title>PurpleTeamAI</title>
  <subtitle>The practitioner&#39;s guide to purple teaming</subtitle>
  <link href="https://purpleteam.ai/feed.xml" rel="self"/>
  <link href="https://purpleteam.ai/"/>
  <updated>2026-09-17T00:00:00Z</updated>
  <id>https://purpleteam.ai/</id>
  <author>
    <name>Hugh McGauran</name>
    <email>hello@purpleteam.ai</email>
  </author>
  
  
  <entry>
    <title>ICS Tabletop Exercises: Why the Lessons Never Transfer to the Plant Floor</title>
    <link href="https://purpleteam.ai/essays/ics-tabletop-exercises-lessons-dont-transfer/"/>
    <updated>2026-09-17T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/ics-tabletop-exercises-lessons-dont-transfer/</id>
    
    <category term="ICS" />
    
    <category term="OT Security" />
    
    <category term="Purple Teaming" />
    
    <category term="Tabletop" />
    
    <category term="post" />
    
    <summary>An IT tabletop finds a process gap and the team rewrites the runbook. An ICS tabletop finds the same gap and the team can do nothing with it, because the person who would have to act on the gap is two floors down, on a different shift, under a different chain of command.</summary>
  </entry>
  
  
  <entry>
    <title>What a Good ICS Detection Looks Like in Practice</title>
    <link href="https://purpleteam.ai/essays/what-a-good-ics-detection-looks-like-in-practice/"/>
    <updated>2026-09-06T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/what-a-good-ics-detection-looks-like-in-practice/</id>
    
    <category term="ICS" />
    
    <category term="OT Security" />
    
    <category term="Detection Engineering" />
    
    <category term="post" />
    
    <summary>There is a lot of advice about ICS detection that talks about MODBUS, DNP3, and the protocol layers. This is the part that comes after the protocol talk: what a good detection actually looks like in the SIEM, and what the SOC analyst does with it</summary>
  </entry>
  
  
  <entry>
    <title>How to Threat-Model a System You Have Never Seen Before</title>
    <link href="https://purpleteam.ai/essays/how-to-threat-model-a-system-you-have-never-seen-before/"/>
    <updated>2026-09-03T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/how-to-threat-model-a-system-you-have-never-seen-before/</id>
    
    <category term="Threat Modelling" />
    
    <category term="Purple Teaming" />
    
    <category term="post" />
    
    <summary>Most threat-modelling advice assumes you have weeks, a working relationship with the engineering team, and a system that is stable. None of those apply when you are walking into a new environment on a Tuesday afternoon. Here is the version that does</summary>
  </entry>
  
  
  <entry>
    <title>How to Build an Insider-Risk Programme That Actually Catches the Bad Cases</title>
    <link href="https://purpleteam.ai/essays/how-to-build-an-insider-risk-programme-that-actually-catches-the-bad-cases/"/>
    <updated>2026-08-27T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/how-to-build-an-insider-risk-programme-that-actually-catches-the-bad-cases/</id>
    
    <category term="Insider Threat" />
    
    <category term="Detection Engineering" />
    
    <category term="Blue Team" />
    
    <category term="post" />
    
    <summary>Most insider-risk programmes are aimed at the wrong target. The detection engineering is theatre. The behavioural analytics are noise. The case management is a black hole. Here is how to build a programme that finds the cases that actually matter</summary>
  </entry>
  
  
  <entry>
    <title>The Detection Rule That Changed How I Think About Fidelity</title>
    <link href="https://purpleteam.ai/essays/the-detection-rule-that-changed-how-i-think-about-fidelity/"/>
    <updated>2026-08-20T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/the-detection-rule-that-changed-how-i-think-about-fidelity/</id>
    
    <category term="Detection Engineering" />
    
    <category term="post" />
    
    <summary>There is one detection rule in my career that genuinely changed how I think about detection fidelity. It was not a clever rule. It was a simple rule. The simplicity is what taught me the most. Here is the rule and what it taught me</summary>
  </entry>
  
  
  <entry>
    <title>What a CISO Actually Does on a Tuesday Afternoon</title>
    <link href="https://purpleteam.ai/essays/what-a-ciso-actually-does-on-a-tuesday-afternoon/"/>
    <updated>2026-08-13T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/what-a-ciso-actually-does-on-a-tuesday-afternoon/</id>
    
    <category term="Purple Teaming" />
    
    <category term="Threat Modelling" />
    
    <category term="post" />
    
    <summary>The CISO job description reads like a strategy role. The actual job is mostly operational. Here is what a competent CISO does on a typical Tuesday afternoon, and what the things look like in practice</summary>
  </entry>
  
  
  <entry>
    <title>How to Hire a Detection Engineer When You Have Never Hired One Before</title>
    <link href="https://purpleteam.ai/essays/how-to-hire-a-detection-engineer-when-you-have-never-hired-one-before/"/>
    <updated>2026-08-06T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/how-to-hire-a-detection-engineer-when-you-have-never-hired-one-before/</id>
    
    <category term="Detection Engineering" />
    
    <category term="Blue Team" />
    
    <category term="post" />
    
    <summary>Most detection engineer hiring fails because the job description is wrong. Here is what to actually look for, what to test in the interview, and the most common mistakes programmes make on the first hire</summary>
  </entry>
  
  
  <entry>
    <title>How to Run a Purple Team Exercise When Nobody Has Done One Before</title>
    <link href="https://purpleteam.ai/essays/how-to-run-a-purple-team-exercise-when-nobody-has-done-one-before/"/>
    <updated>2026-07-30T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/how-to-run-a-purple-team-exercise-when-nobody-has-done-one-before/</id>
    
    <category term="Purple Teaming" />
    
    <category term="post" />
    
    <summary>Most purple team advice is written for teams that have done several. Here is the version for the team that is about to do their first one, in order, with the parts that most programmes get wrong</summary>
  </entry>
  
  
  <entry>
    <title>Tabletop Exercises That Actually Prepare You for an Incident</title>
    <link href="https://purpleteam.ai/essays/tabletop-exercises-that-actually-prepare-you-for-an-incident/"/>
    <updated>2026-07-23T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/tabletop-exercises-that-actually-prepare-you-for-an-incident/</id>
    
    <category term="Purple Teaming" />
    
    <category term="Blue Team" />
    
    <category term="post" />
    
    <summary>Most tabletops are theatre. A senior person reads a scenario, the room talks through what they would do, nobody changes anything, and the postmortem is a one-pager that says &#39;we are well prepared.&#39; Here is how to run one that is not theatre</summary>
  </entry>
  
  
  <entry>
    <title>The Six-Month Build: What a Real Detection Engineering Programme Looks Like</title>
    <link href="https://purpleteam.ai/essays/the-six-month-build-what-a-real-detection-engineering-programme-looks-like/"/>
    <updated>2026-07-16T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/the-six-month-build-what-a-real-detection-engineering-programme-looks-like/</id>
    
    <category term="Detection Engineering" />
    
    <category term="Blue Team" />
    
    <category term="post" />
    
    <summary>Most &#39;detection engineering programmes&#39; are not programmes. They are a person with a Sigma rule and a prayer. Here is what a real six-month build looks like, in order, and what each phase actually costs</summary>
  </entry>
  
  
  <entry>
    <title>Why Most Threat Intelligence Programmes Are Not Worth the Money</title>
    <link href="https://purpleteam.ai/essays/why-most-threat-intelligence-programmes-are-not-worth-the-money/"/>
    <updated>2026-07-09T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/why-most-threat-intelligence-programmes-are-not-worth-the-money/</id>
    
    <category term="Threat Modelling" />
    
    <category term="Purple Teaming" />
    
    <category term="post" />
    
    <summary>Threat intelligence is one of the most expensive parts of a security programme and one of the most under-used. Most programmes pay for feeds they do not read, run platforms they do not use, and produce reports that do not change anything. Here is the honest version of the work</summary>
  </entry>
  
  
  <entry>
    <title>The Red Team Engagement That Changed How I Think About Risk</title>
    <link href="https://purpleteam.ai/essays/the-red-team-engagement-that-changed-how-i-think-about-risk/"/>
    <updated>2026-07-02T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/the-red-team-engagement-that-changed-how-i-think-about-risk/</id>
    
    <category term="Red Team" />
    
    <category term="Purple Teaming" />
    
    <category term="post" />
    
    <summary>There is one engagement in my career that genuinely changed how I think about cybersecurity risk. It was not the most sophisticated operation I have run. It was not the most expensive. It was the one that taught me the most. Here is what it was and what it taught me</summary>
  </entry>
  
  
  <entry>
    <title>What I Look For in a Red Team Report</title>
    <link href="https://purpleteam.ai/essays/what-i-look-for-in-a-red-team-report/"/>
    <updated>2026-06-25T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/what-i-look-for-in-a-red-team-report/</id>
    
    <category term="Red Team" />
    
    <category term="Purple Teaming" />
    
    <category term="post" />
    
    <summary>Most red team reports are unreadable. The good ones are gold. Here is what makes the difference, in order, with the parts that most red teamers get wrong</summary>
  </entry>
  
  
  <entry>
    <title>What a Good Detection Engineer Actually Does All Day</title>
    <link href="https://purpleteam.ai/essays/what-a-good-detection-engineer-actually-does-all-day/"/>
    <updated>2026-06-18T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/what-a-good-detection-engineer-actually-does-all-day/</id>
    
    <category term="Detection Engineering" />
    
    <category term="Blue Team" />
    
    <category term="post" />
    
    <summary>The job description for a detection engineer reads like a software engineer with a security focus. The actual job is more like an editor at a small newspaper. Here is what the work looks like when the title is right and the work is also right</summary>
  </entry>
  
  
  <entry>
    <title>Building a Detection Baseline: The Work Nobody Wants to Do</title>
    <link href="https://purpleteam.ai/essays/building-a-detection-baseline/"/>
    <updated>2026-06-11T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/building-a-detection-baseline/</id>
    
    <category term="Detection Engineering" />
    
    <category term="Blue Team" />
    
    <category term="post" />
    
    <summary>Every detection engineer has been told to build a baseline. Almost nobody has been given a clear answer about what a baseline actually is, what data it needs, or how it connects to the rules the SOC actually runs. Here is the honest version of the work</summary>
  </entry>
  
  
  <entry>
    <title>Purple Teaming at Scale: How It Changes When You Have 20 Blue Team Analysts</title>
    <link href="https://purpleteam.ai/essays/purple-teaming-at-scale/"/>
    <updated>2026-06-04T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/purple-teaming-at-scale/</id>
    
    <category term="Purple Teaming" />
    
    <category term="Detection Engineering" />
    
    <category term="post" />
    
    <summary>Most purple team advice is written for a team of three. If you scale to twenty, the bottlenecks move, the failure modes change, and the programme either matures or quietly dies on contact with reality. Here is what shifts, and what does not</summary>
  </entry>
  
  
  <entry>
    <title>Adversary Emulation vs Penetration Testing: Why the Distinction Matters</title>
    <link href="https://purpleteam.ai/essays/adversary-emulation-vs-penetration-testing/"/>
    <updated>2026-05-28T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/adversary-emulation-vs-penetration-testing/</id>
    
    <category term="Red Team" />
    
    <category term="Purple Teaming" />
    
    <category term="post" />
    
    <summary>You paid €80,000 for a &quot;red team engagement.&quot; The report arrived with 47 findings, a 12-page executive summary, and a heat map of your network that looked like something out of a disaster movie</summary>
  </entry>
  
  
  <entry>
    <title>How to Write a Purple Team Report That Actually Gets Read</title>
    <link href="https://purpleteam.ai/essays/purple-team-report-that-gets-read/"/>
    <updated>2026-05-21T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/purple-team-report-that-gets-read/</id>
    
    <category term="Purple Teaming" />
    
    <category term="Red Team" />
    
    <category term="Blue Team" />
    
    <category term="post" />
    
    <summary>You ran a three-week purple team exercise. Your team worked hard. The red team executed a realistic adversary emulation. Your blue team detected some of it, missed most of it, and the gaps are clear. The debrief went…</summary>
  </entry>
  
  
  <entry>
    <title>Living Off the Land: Why the Best Attackers Don&#39;t Look Like Attackers</title>
    <link href="https://purpleteam.ai/essays/living-off-the-land/"/>
    <updated>2026-05-14T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/living-off-the-land/</id>
    
    <category term="Detection Engineering" />
    
    <category term="Red Team" />
    
    <category term="Blue Team" />
    
    <category term="post" />
    
    <summary>Volt Typhoon maintained access to critical infrastructure networks in the United States for at least five years. Microsoft, Mandiant, and the Five Eyes governments published the technical details in 2024. The…</summary>
  </entry>
  
  
  <entry>
    <title>The Insider Threat Problem Is Not What You Think</title>
    <link href="https://purpleteam.ai/essays/insider-threat-problem/"/>
    <updated>2026-05-07T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/insider-threat-problem/</id>
    
    <category term="Insider Threat" />
    
    <category term="Detection Engineering" />
    
    <category term="Threat Modelling" />
    
    <category term="post" />
    
    <summary>Your insider threat programme is aimed at the wrong target</summary>
  </entry>
  
  
  <entry>
    <title>The 7 Most Pointless Findings in OT Pen Tests</title>
    <link href="https://purpleteam.ai/essays/seven-pointless-ot-pen-test-findings/"/>
    <updated>2026-04-30T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/seven-pointless-ot-pen-test-findings/</id>
    
    <category term="OT Security" />
    
    <category term="Purple Teaming" />
    
    <category term="ICS" />
    
    <category term="Pen Testing" />
    
    <category term="post" />
    
    <summary>If you run enough OT pen tests, you start to notice a pattern. The report arrives, the client is confused, and the findings have a peculiar quality: technically correct, operationally impossible to remediate, and…</summary>
  </entry>
  
  
  <entry>
    <title>Purple Teaming OT: Why &quot;We Can&#39;t Test That&quot; Is No Longer Acceptable</title>
    <link href="https://purpleteam.ai/essays/purple-teaming-ot/"/>
    <updated>2026-04-23T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/purple-teaming-ot/</id>
    
    <category term="OT Security" />
    
    <category term="Purple Teaming" />
    
    <category term="ICS" />
    
    <category term="Critical Infrastructure" />
    
    <category term="post" />
    
    <summary>I keep hearing the same thing in conversations about operational technology security</summary>
  </entry>
  
  
  <entry>
    <title>How to Scope a Red Team Engagement That Tells You Something Real</title>
    <link href="https://purpleteam.ai/essays/scoping-a-red-team-engagement/"/>
    <updated>2026-04-16T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/scoping-a-red-team-engagement/</id>
    
    <category term="Red Team" />
    
    <category term="Purple Teaming" />
    
    <category term="Threat Modelling" />
    
    <category term="post" />
    
    <summary>Most red team engagements produce an impressive document and a set of &quot;critical findings&quot; that the security team could have predicted before the first phishing email was sent</summary>
  </entry>
  
  
  <entry>
    <title>Purple Teaming That Actually Works: A Framework for Real Collaboration</title>
    <link href="https://purpleteam.ai/essays/purple-teaming-that-actually-works/"/>
    <updated>2026-04-09T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/purple-teaming-that-actually-works/</id>
    
    <category term="Purple Teaming" />
    
    <category term="post" />
    
    <summary>You&#39;ve got a red team and a blue team. They hate each other</summary>
  </entry>
  
  
  <entry>
    <title>Why Your Red Team Tests Are Designed to Fail, And You Don&#39;t Know It</title>
    <link href="https://purpleteam.ai/essays/red-team-tests-designed-to-fail/"/>
    <updated>2026-04-02T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/red-team-tests-designed-to-fail/</id>
    
    <category term="Purple Teaming" />
    
    <category term="post" />
    
    <summary>Red team comes in on Monday. They&#39;ve got a scope, a timeline, and a list of techniques to test. By Friday, they&#39;ve &quot;successfully executed&quot; initial access, lateral movement, persistence, and exfiltration</summary>
  </entry>
  
  
  <entry>
    <title>Detection Engineering in a Real Environment: Why Generic Rules Fail</title>
    <link href="https://purpleteam.ai/essays/detection-engineering-real-environment/"/>
    <updated>2026-03-26T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/detection-engineering-real-environment/</id>
    
    <category term="Purple Teaming" />
    
    <category term="post" />
    
    <summary>I walked into a SOC last month where they&#39;d deployed 847 Sigma rules</summary>
  </entry>
  
  
  <entry>
    <title>Your Purple Team Test Failed Because Your Threat Model Is Wrong</title>
    <link href="https://purpleteam.ai/essays/purple-team-threat-model-wrong/"/>
    <updated>2026-03-19T00:00:00Z</updated>
    <id>https://purpleteam.ai/essays/purple-team-threat-model-wrong/</id>
    
    <category term="Purple Teaming" />
    
    <category term="post" />
    
    <summary>You ran a purple team exercise last week. Your red team executed a flawless attack chain: initial access via phishing, lateral movement via Kerberos relay, privilege escalation, and data exfiltration. Picture perfect</summary>
  </entry>
  
</feed>

