Skip to content
Macksofy Technologies
Red + Blue · MITRE ATT&CK · Detection Validation

Purple Team Exercises in India & UAE.

Collaborative red + blue team exercises that validate your detection and response capability against real adversary TTPs — running side-by-side with your SOC analysts so every missed alert becomes a tuned rule before the engagement closes.

5–15
working days
Live
SOC in the loop
Shipped
rules, not tickets
30 days
retest of the rule set
In short

What is purple teaming?

Purple teaming runs offensive (red) and defensive (blue) teams together so every simulated attack immediately becomes a validated detection and response improvement. Macksofy executes MITRE ATT&CK techniques against your SOC, measures what your SIEM catches, and closes the gaps — turning red-team findings into lasting detection coverage.

The distinction people buy wrong

A red team tells you what got missed. Purple makes it stop being missed.

Covert
Red team
Blue knows
No — that is the point
Output
What got missed
Rules shipped
None during the engagement
Best when
You need to know if you would survive
Collaborative
Purple team
Blue knows
Yes — they are in the room
Output
Detection rules, tuned and validated
Rules shipped
During the engagement, in your repo
Best when
You have a SOC and want it measurably better

Both are worth buying — in that order. If you have never run a red team, you may not yet know which detections matter. Red team operations is the covert version of this work.

The mechanic

Execute. Miss. Tune. Replay. Confirm.

Every technique runs this loop before the exercise moves on. Your analysts write the rules — we sit with them while they do it, which is also how the training happens.

  • Convert red team findings into shipped detection rules — not next-quarter remediation tickets
  • Measurable MITRE ATT&CK coverage improvement (baseline → target) with evidence
  • Train Tier-1 and Tier-2 SOC analysts on real adversary tradecraft, not vendor demos
  • Build the executive evidence pack: '92 ATT&CK techniques tested, 78 detected, 14 hardened'
The loop · repeated per technique
red blue together
  1. ExecuteRed

    Red runs one ATT&CK technique against the live estate, announced to the room but not to the tooling.

  2. ObserveBlue

    Blue works their normal queue. Did anything fire — and did it reach a human, or die in a connector?

  3. Tune togetherTogether

    On a miss we stop and write the rule with your analysts — Sigma, SPL, KQL or Wazuh, in your repo.

  4. ReplayRed

    The same technique is executed again, plus a variant, so the rule catches behaviour rather than one literal.

  5. ConfirmBlue

    The alert fires, is triaged, and false-positive rate is checked against your real noise baseline before moving on.

The exercise does not advance to the next technique until the alert fires reliably. That is the whole difference from a red team report.
The deliverable

A number your board can be shown twice.

Coverage before, coverage after, and the rules that account for the difference. It is the rare security engagement that produces a metric which genuinely moved rather than a risk that was merely described.

ATT&CK coverage delta · one anonymised engagement
Before the exercise47%
At close71%
+24
points of coverage
18
techniques tested
14
SIEM rules shipped

Listed bank, five days on-site across AD, endpoint and the email gateway. Rules were written and validated inside the engagement window, not filed as recommendations for next quarter.

What the map records per technique
Detected

Fired, reached the queue, and an analyst actioned it. Recorded with the rule that caught it.

Missed, then tuned

Nothing fired. A rule was written with your analysts during the exercise and validated on replay.

Gap remaining

Needs telemetry you do not currently collect. Ranked in the hardening roadmap with what it would take.

The finding nobody scopes for · on a separate fintech engagement the EDR detected the technique correctly and the alert never reached the SOC queue — a broken connector. A red team report would have recorded a miss. The purple loop found the pipeline.

Before you book

Three things that need to be true. We will say so if they are not.

Purple teaming is the validate-and-tune step that comes after you have a SOC. If you are earlier than that, we will point you at SOC setup or a managed service instead of selling you this.

You have a SIEM with real telemetry

Splunk, Sentinel, Wazuh, Elastic or QRadar with endpoint and identity logs actually flowing. Purple teaming tunes what exists — it cannot tune an absent log source.

You have analysts, in-house or MSSP

Someone has to be in the room to write and own the rules. We run this against client SOCs, MSSP SOCs and hybrids without preference.

You can pause and fix mid-exercise

The value comes from stopping on a miss and building the detection together. If change control cannot move inside the window, a red team fits better.

Methodology

Five phases, one charter.

Signed jointly by red, blue and IT leads before anything runs — so nobody is surprised, and nobody is defensive.

Phase 1
Pre-engagement
  • Threat-model intake: industry-relevant APTs and ransomware families
  • MITRE ATT&CK baseline assessment of current detection coverage
  • Joint engagement charter signed by red + blue + IT leads
Phase 2
Phase-by-phase execution
  • Initial access scenarios (phishing, exposed services, supply-chain)
  • Execution + persistence + privilege escalation
  • Lateral movement + credential access
  • Defense evasion + collection + exfiltration
  • Each phase: red executes → blue detects/misses → joint tuning → replay
Phase 3
Detection engineering co-build
  • Sigma / Splunk / Sentinel / Wazuh rule authoring with your analysts
  • False-positive tuning against your baseline noise profile
  • Validation: re-execute technique until the alert fires reliably
Phase 4
ATT&CK coverage hardening
  • Coverage map: techniques tested vs. detected vs. blocked vs. tuned
  • Gap inventory ranked by likelihood + business impact
  • Quick-win + medium-term hardening roadmap
Phase 5
Reporting & retest
  • Executive summary with coverage delta (before / after)
  • Per-technique writeup: PoC, detection rule shipped, remaining gap
  • 30-day retest of the hardened rule set
Engagement snapshots

One moved a metric. One found a silent failure.

Listed Bank (Mumbai BKC)

Scope · 5-day on-site purple team across AD + endpoint + email gateway

Result · Lifted ATT&CK coverage from 47% to 71% across 18 techniques; shipped 14 new SIEM rules during the engagement

Material — passed RBI System Audit detection-control test on the same quarter

Risk severity · High
LMHC
Fintech Lending Platform (Bengaluru)

Scope · Phishing → lateral → exfil scenario with managed SOC live in the loop

Result · Discovered that EDR detected the technique but the alert never reached the SOC queue (broken connector) — fixed mid-engagement

Critical — silent detection-pipeline failure that would have hidden a real ransomware precursor

Risk severity · Critical
LMHC
Both sides of the table

Emulation frameworks and your rule syntax.

Red runs adversary-emulation tooling; blue writes in whatever the SIEM speaks — Sigma, SPL, KQL or the Wazuh rule editor. Rules land in your repository, not in an appendix.

Everything shipped during the exercise stays yours.
Tools we operate
MITRE CalderaAtomic Red TeamPrelude OperatorCobalt Strike (RoE-permitting)Covenant + SliverBloodHoundCustom EDR-evasion toolingSigma · Splunk SPL · KQL · Wazuh rule editor
Indicative pricing · INR

Transparent tiers. No surprises at quote time.

Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.

Free 30-day retest · CERT-In format reports
Tier 01

Focused

₹2.5L–₹5L
Single asset or app
  • Manual + tooled testing
  • CERT-In format report
  • Free 30-day retest
Request a fixed-price quote
Tier 02

Stack

₹6L–₹12L
Multi-asset engagement
  • Everything in Focused
  • Web + API + mobile coverage
  • Executive + technical briefings
Request a fixed-price quote
Tier 03

Programme

Starts at ₹15L
Quarterly retainer · large estate
  • Everything in Stack
  • Quarterly cycles + post-release retests
  • Same consultants throughout
Request a fixed-price quote

Note · Indicative pricing in INR. Final quote depends on scope, asset count and engagement window. Fixed-price proposal within 72 hours.

Deliverables

What you get when the exercise ends

  • MITRE ATT&CK coverage heatmap (before / after)
  • Per-technique evidence pack (red PoC + blue detection rule shipped)
  • Tuned Sigma / Splunk / Sentinel / Wazuh rule set
  • Detection engineering runbook + future-cadence recommendation
  • Free 30-day retest of the hardened rule set
  • Executive coverage delta report
Industries

Sectors we operate in

Banking & Financial ServicesFintech & PaymentsInsurance & InsurTechSaaS & Product CompaniesGovernment & PSUHealthcare & HealthTechTelecom
What clients say · Trusted India + UAE

Empanelled by CERT-In. Accredited by EC-Council.

CERT-In Empanelled
Govt of India · MeitY
EC-Council ATC
Authorized Training
ISO 27001 Certified
Info Security Mgmt
CompTIA Authorized Partner
Training Delivery
We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.
LF
Information Security Manager
Listed Fintech · BKC, Mumbai
The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.
MP
Cyber Cell
Maharashtra Police · Mumbai
Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.
HS
DevSecOps Lead
Healthcare SaaS · Hyderabad
FAQ

Questions before the charter is signed.

A red team runs covert and reports at the end. A purple team runs collaboratively — red executes a technique, blue tries to detect, we pause and tune together, then replay. The deliverable is shipped detection rules + a hardened MITRE map, not just a list of what got missed.
You need a SIEM + analysts (in-house or MSSP-provided). If you're early-stage, our SOC Setup or MSS engagement makes more sense first; purple teaming is the validate-and-tune step that comes after you have a SOC running.
5–15 working days. Focused scope (email phishing + AD lateral, for example) is 5 days. Full estate (cloud + endpoint + identity + email) is 10–15. Quote within 48 hours of scoping.
Yes — we run purple teaming against client-operated SOCs, MSSP-operated SOCs and hybrid setups. We're tone-neutral about who operates blue; the goal is to leave your detection coverage measurably better.
Delivery footprint

Where Macksofy delivers Purple Team.

On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.

References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements