Defences tested and improved in the same week
Our offensive and defensive teams work with yours, running attack techniques and writing the detections for them as we go.
The challenge
A pentest report lands, gets filed, and nothing in your detection changes. Purple team closes that loop while everyone is in the room.
Scope — included and not included
Included
- Technique selection mapped to ATT&CK
- Live execution with your team watching
- Detection rule development and validation
- Coverage map before and after
- Joint runbook
Not included
- Full adversary emulation with stealth objectives
- Remediation of infrastructure weaknesses
- Ongoing detection operation, that is MDR
How it works
01
Select techniques
ATT&CK techniques chosen for your threat profile.
02
Execute together
We run each technique with your team observing the telemetry.
03
Write detections
Rules written and tuned on the spot, against real signal.
04
Validate and hand over
Re-run to confirm the detections fire; runbook handed over.
What you receive
- →ATT&CK coverage map, before and after
- →Detection rules, written and validated
- →Joint runbook
- →Exercise report
- →Recording of the session
What we need from you
- ·Your SOC or IT team available for the exercise days
- ·SIEM access to write rules
- ·A test environment or agreed production scope
Timeline and engagement
1 to 2 weeks. Fixed scope.
Standards, methods and tooling
MITRE ATT&CKAtomic Red TeamWazuhSigmaPortal hosted in Canada
Frequently asked questions