Purple Team Exercises in India & UAE.
Collaborative red + blue team exercises that validate your detection and response capability against real adversary TTPs — running side-by-side with your SOC analysts so every missed alert becomes a tuned rule before the engagement closes.
What is purple teaming?
Purple teaming runs offensive (red) and defensive (blue) teams together so every simulated attack immediately becomes a validated detection and response improvement. Macksofy executes MITRE ATT&CK techniques against your SOC, measures what your SIEM catches, and closes the gaps — turning red-team findings into lasting detection coverage.
A red team tells you what got missed. Purple makes it stop being missed.
- Blue knows
- No — that is the point
- Output
- What got missed
- Rules shipped
- None during the engagement
- Best when
- You need to know if you would survive
- Blue knows
- Yes — they are in the room
- Output
- Detection rules, tuned and validated
- Rules shipped
- During the engagement, in your repo
- Best when
- You have a SOC and want it measurably better
Both are worth buying — in that order. If you have never run a red team, you may not yet know which detections matter. Red team operations is the covert version of this work.
Execute. Miss. Tune. Replay. Confirm.
Every technique runs this loop before the exercise moves on. Your analysts write the rules — we sit with them while they do it, which is also how the training happens.
- Convert red team findings into shipped detection rules — not next-quarter remediation tickets
- Measurable MITRE ATT&CK coverage improvement (baseline → target) with evidence
- Train Tier-1 and Tier-2 SOC analysts on real adversary tradecraft, not vendor demos
- Build the executive evidence pack: '92 ATT&CK techniques tested, 78 detected, 14 hardened'
- ExecuteRed
Red runs one ATT&CK technique against the live estate, announced to the room but not to the tooling.
- ObserveBlue
Blue works their normal queue. Did anything fire — and did it reach a human, or die in a connector?
- Tune togetherTogether
On a miss we stop and write the rule with your analysts — Sigma, SPL, KQL or Wazuh, in your repo.
- ReplayRed
The same technique is executed again, plus a variant, so the rule catches behaviour rather than one literal.
- ConfirmBlue
The alert fires, is triaged, and false-positive rate is checked against your real noise baseline before moving on.
A number your board can be shown twice.
Coverage before, coverage after, and the rules that account for the difference. It is the rare security engagement that produces a metric which genuinely moved rather than a risk that was merely described.
Listed bank, five days on-site across AD, endpoint and the email gateway. Rules were written and validated inside the engagement window, not filed as recommendations for next quarter.
Fired, reached the queue, and an analyst actioned it. Recorded with the rule that caught it.
Nothing fired. A rule was written with your analysts during the exercise and validated on replay.
Needs telemetry you do not currently collect. Ranked in the hardening roadmap with what it would take.
The finding nobody scopes for · on a separate fintech engagement the EDR detected the technique correctly and the alert never reached the SOC queue — a broken connector. A red team report would have recorded a miss. The purple loop found the pipeline.
Three things that need to be true. We will say so if they are not.
Purple teaming is the validate-and-tune step that comes after you have a SOC. If you are earlier than that, we will point you at SOC setup or a managed service instead of selling you this.
Splunk, Sentinel, Wazuh, Elastic or QRadar with endpoint and identity logs actually flowing. Purple teaming tunes what exists — it cannot tune an absent log source.
Someone has to be in the room to write and own the rules. We run this against client SOCs, MSSP SOCs and hybrids without preference.
The value comes from stopping on a miss and building the detection together. If change control cannot move inside the window, a red team fits better.
Five phases, one charter.
Signed jointly by red, blue and IT leads before anything runs — so nobody is surprised, and nobody is defensive.
- ▸Threat-model intake: industry-relevant APTs and ransomware families
- ▸MITRE ATT&CK baseline assessment of current detection coverage
- ▸Joint engagement charter signed by red + blue + IT leads
- ▸Initial access scenarios (phishing, exposed services, supply-chain)
- ▸Execution + persistence + privilege escalation
- ▸Lateral movement + credential access
- ▸Defense evasion + collection + exfiltration
- ▸Each phase: red executes → blue detects/misses → joint tuning → replay
- ▸Sigma / Splunk / Sentinel / Wazuh rule authoring with your analysts
- ▸False-positive tuning against your baseline noise profile
- ▸Validation: re-execute technique until the alert fires reliably
- ▸Coverage map: techniques tested vs. detected vs. blocked vs. tuned
- ▸Gap inventory ranked by likelihood + business impact
- ▸Quick-win + medium-term hardening roadmap
- ▸Executive summary with coverage delta (before / after)
- ▸Per-technique writeup: PoC, detection rule shipped, remaining gap
- ▸30-day retest of the hardened rule set
One moved a metric. One found a silent failure.
Scope · 5-day on-site purple team across AD + endpoint + email gateway
Result · Lifted ATT&CK coverage from 47% to 71% across 18 techniques; shipped 14 new SIEM rules during the engagement
Material — passed RBI System Audit detection-control test on the same quarter
Scope · Phishing → lateral → exfil scenario with managed SOC live in the loop
Result · Discovered that EDR detected the technique but the alert never reached the SOC queue (broken connector) — fixed mid-engagement
Critical — silent detection-pipeline failure that would have hidden a real ransomware precursor
Emulation frameworks and your rule syntax.
Red runs adversary-emulation tooling; blue writes in whatever the SIEM speaks — Sigma, SPL, KQL or the Wazuh rule editor. Rules land in your repository, not in an appendix.
Transparent tiers. No surprises at quote time.
Indicative price ranges based on typical Indian engagements. Final fixed-price quote within 72 hours of the discovery call.
Focused
- Manual + tooled testing
- CERT-In format report
- Free 30-day retest
Stack
- Everything in Focused
- Web + API + mobile coverage
- Executive + technical briefings
Programme
- Everything in Stack
- Quarterly cycles + post-release retests
- Same consultants throughout
Note · Indicative pricing in INR. Final quote depends on scope, asset count and engagement window. Fixed-price proposal within 72 hours.
What you get when the exercise ends
- MITRE ATT&CK coverage heatmap (before / after)
- Per-technique evidence pack (red PoC + blue detection rule shipped)
- Tuned Sigma / Splunk / Sentinel / Wazuh rule set
- Detection engineering runbook + future-cadence recommendation
- Free 30-day retest of the hardened rule set
- Executive coverage delta report
Sectors we operate in
Empanelled by CERT-In. Accredited by EC-Council.
“We've worked with three Big 4 firms before Macksofy. None found what their team did in our payments stack. The most actionable report we've received in a decade.”
“The CHFI training Macksofy delivered for our cyber cell raised investigation quality measurably. Practical, India-context-aware, and respectful of our operational realities.”
“Came in with zero security background. 5 weeks later I was running Burp Suite and Metasploit confidently. Cleared CEH on the first attempt.”
Questions before the charter is signed.
Where Macksofy delivers Purple Team.
On-site engagements across India's BFSI, fintech, government and SaaS metros plus the UAE. Senior consultants fly from Mumbai BKC for kickoff, key reviews and exit briefings; remote weeks run through the rest of the engagement.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- Thousands of professionals trained
- India + UAE engagements
