Back to Field Notes
Threat Intelligence/Field Note

Purple Team as a Cycle, Not an Event

A purple team week followed by a 12-month gap is a one-time party. The cyclic version is what changes outcomes.

Author

Aisha Khan

Director, Threat Intelligence

Published

March 8, 2026

Read

9 min

Share
AI-generated illustration of a power grid substation
AI-generated illustration of a power grid substation
Key Takeaways
  • 01A purple-team week is fun and produces a slide deck. The version that actually changes outcomes is cyclic: hypothesis → exercise → gap identification → content build → re-test the following month.
  • 02The cycle: quarterly hypothesis from threat intel + recent incidents, two-week red-emulates / blue-detects exercise, gap identification (specific data sources, queries, rules missing), two-week build, re-test the same technique to measure detection improvement.
  • 03Wrong reasons to run purple team: compliance check-the-box, audience for an external red team, justifying a tool purchase. None produce content improvements; all produce expense. If the cycle does not feed the SOC backlog, do not run it.
  • 04BAS (breach-and-attack simulation) tools accelerate parts of the cycle but do not replace adversarial creativity. Use BAS for breadth and human red team for depth. The combination scales.

A purple-team week is fun. It produces a slide deck and some good war stories. The version that actually changes outcomes is cyclic: a hypothesis, an exercise to test it, identification of detection gaps, content to close them, and a re-test the following month.

The cycle

  • 01Quarterly hypothesis selection — based on threat intel and recent incidents
  • 02Two-week exercise — red emulates the technique, blue tries to detect
  • 03Gap identification — specific data sources, queries, and rules missing
  • 04Two-week build — content, data sources, dashboards
  • 05Re-test — same technique, measure detection improvement

The wrong reasons to run purple team

Compliance check-the-box. Audience for an external red team. Justifying a tool purchase. None of these produce content improvements; all produce expense. If the cycle does not feed the SOC's backlog, do not run it.

Tooling expectations

BAS (breach-and-attack simulation) tools accelerate parts of the cycle but do not replace adversarial creativity. Use BAS for breadth and human red team for depth. The combination scales.

#Purple Team#Detection#Exercise

/WRITTEN_BY

Aisha Khan

Director, Threat Intelligence · Alexa Cybersecurity