Skip to content

Red teaming and purple teaming

Objective-based exercises that test detection and response, and the collaborative loop that actually improves them.

Free on glitchdata advanced 4 lessons 55 min

What you'll learn

  • Decide whether an organisation is ready for a red team exercise
  • Plan objectives and scenarios using threat intelligence and ATT&CK
  • Run a purple-team loop that closes detection gaps during the exercise
  • Measure detection and response rather than counting findings

About this course

A red team exercise answers a question no other test does: can an objective be achieved without the defenders noticing and responding in time?

This course covers when that question is worth asking, how to plan an exercise around threat intelligence and ATT&CK, how to run a purple-team loop that fixes detections while everyone is still in the room, and how to measure the outcome in something other than findings.

Before you start

  • Experience with security testing or security operations
  • Familiarity with detection tooling

Course content

4 lessons · 55 min

  1. 1
    Objective-based testing, and when you are ready for it

    What a red team answers, what it costs, and the signs you should buy something else first.

    Free preview 14 min
  2. 2
    Planning with threat intelligence and ATT&CK

    Choosing scenarios that resemble your actual adversaries, and writing them down as testable techniques.

    14 min
  3. 3
    Running a purple-team loop

    Execute, observe, fix, re-run — improving detection while the people who own it are still present.

    14 min
  4. 4
    Measuring detection and response

    Times, coverage and quality — the numbers that say whether defence improved.

    13 min

What learners say

Sign in and enrol to leave a review.

No reviews yet — be the first once you have worked through it.

More in Cyber security