Skip to main content
Home/Services/Purple Team Engagements
Security Testing

Purple Team Engagements

Red and blue working together to measurably improve detection

SOC 2 NIST CSF PCI-DSS ISO 27001
engagement log Purple Team Engagements testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingATT&CK tactics with zero detection coveragecritical
day 03findingAlerts firing too late in the kill chainhigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
3-6 weekstypical duration $22,000fixed scope, from 6deliverables 6methodology stages
Scope

What this engagement covers

The service

Collaborative engagements where our offensive team executes realistic adversary behavior while your defensive team observes, tunes, and validates detections in real time.

What we test

Controlled execution of MITRE ATT&CK techniques across your environment, paired with real-time detection validation and tuning by your SOC or our MDR analysts.

Method

How we run it

Scoped ATT&CK technique library, paired execution sessions, live detection scoring, and a delivery package including signed runbooks, test artifacts, and a detection coverage report.

01

Scoping and technique selection

02

Environment readiness check

03

Paired live execution sessions

04

Real-time detection validation

05

Tuning iteration

06

Coverage report and re-test

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • ATT&CK-mapped technique catalog
  • Live execution sessions
  • Per-technique detection scoring
  • Tuned detections deployed by end of engagement
  • Coverage heatmap report
  • Re-test validation pass
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

ATT&CK tactics with zero detection coverage Alerts firing too late in the kill chain High false-positive detections being ignored Missing telemetry blocking detection Playbook gaps for confirmed detections
Fit

Who this is for

Mature SOCs wanting measurable improvement
Post-EDR-rollout validation
Teams preparing for red-team engagements
Organizations needing ATT&CK coverage evidence
Standards this supports

Findings are mapped to SOC 2, NIST CSF, PCI-DSS, ISO 27001, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!