RedTeam sessions (Purple)

Service Overview

Red Team and Purple Team sessions at Dognet Technologies simulate real attacks by advanced threat actor against organization as a whole—not only technology, but also people and processes. Unlike a penetration test that assesses the presence of specific technical vulnerabilities, a Red Team operation evaluates the overall defensive capacity of the organization: how long the security team (Blue Team) takes to detect intrusion, to contain the lateral movement, to respond and to eradicate the presence of the attacker.

Sessions RedTeam (Purple)

RedTeam

The Purple Team integrates Red Team (attacks) and Blue Team (defenders) into a collaborative framework: each offensive technique is performed in coordination with defenders, who observe in real time as their detection tools respond, identifying visibility gaps and security control improvement opportunities. This approach maximizes knowledge transfer and accelerates the improvement of defensive posture.

Reference Framework

Operations are structured according to the MITRE ATT&CK framework, which ranks over 400 techniques and sub-techniques used by real APT groups, organized in the 14 tactics of the kill chain: Reconnaissance, Resource Development, Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact. Each technique performed is documented with the ATT& code CK corresponding, allowing the Blue Team to check the coverage of its detection controls against specific techniques.

Steps of Operation Red Team

The Scoping and Threat Modeling phase defines, in accordance with the customer, the objectives of the operation (flag), the operational constraints (engineering rules), the threat actor to simulate (e.g., ransomware group, APT nation-state, insider malicious) and the authorized perimeter. This phase is critical: mal defined operations produce non-actionable results.

Reconnaissance collects information about organization through OSINT techniques—employees on LinkedIn, exposed technologies, IP addresses, domains, SSL certificates, previous breach data—building an organization profile equivalent to what would prepare a motivated attacker in the weeks before an attack.

The Initial Access replicates the initial compromise vectors most used by real attackers: phishing targeted (spear phishing with convincing claims built on OSINT data), exploitation of exposed services (VPN, RDP, web applications), supply chain attacks, and impairment of credentials obtained from public breaches.

Once the first access is obtained, the Lateral Movement simulates the progression of the attacker within the network: privilege escalation, credential dumping, lateral movement towards systems of interest (domain controller, file server, database, backup), maintaining persistence through techniques of evasion of antivirus and EDR systems.

The Objective Achievement checks the achievement of the objectives defined in purposeng: access to sensitive data, possibility of deploying ransomware, compromise of critical systems, exfiltration of data.

Purple Team Sessions

The Purple Team sessions are alongside the Red Team operation with structured workshops in which the Red Team performs an ATT& technique CK specifies while the Blue Team checks whether its instruments (SIEM, EDR, NDR) have detected it. In cases of non-recognition, sessions identify the necessary changes to detection, alert threshold and response playbooks. Each session closes with concrete action items for the security team.

Deliverable

Full operating report with timeline of the operation, every ATT& technique CK used and its outcome (relevated/not detected), analysis of detection and visibility gaps, average detection and response time assessment (MTTD/MTTR), and roadmap improvement of defensive controls. Includes specific technical recommendations for SIEM rules, EDR policies and network segmentation.

EnglishenEnglishEnglish