Case Study: Purple Teaming
Security controls create value only when suspicious behaviour is prevented or converted into evidence that defenders can recognise, prioritise, investigate and contain. A successful endpoint alert does not necessarily mean that every child process, account change, network action or data-transfer route has been stopped.
This case study outlines a ProCheckUp Purple Teaming engagement for an international company. The collaborative exercise used MITRE ATT&CK-aligned insider-threat scenarios to test company-issued laptops, valid user and VPN access, controlled rogue systems on internal networks, identity and cloud activity, and the complete path from telemetry to Security Operations Centre response.

Overview
An international company commissioned ProCheckUp to assess how effectively its round-the-clock security operations capability could identify and respond to realistic post-compromise activity. The engagement paired authorised adversary simulation with direct Blue Team observation, daily evidence review and live detection refinement.
Testing was performed from standard-user company laptops using domain and VPN access, and from controlled internal systems positioned to emulate rogue devices introduced by an insider or a threat actor with physical network access. The scenarios covered endpoint, network, identity, cloud, persistence, collection, command-and-control and exfiltration behaviour.
The customer entered the exercise with meaningful strengths: relatively well-hardened endpoint builds, detailed endpoint telemetry, effective host-isolation capability, network authentication and a distributed Security Operations Centre supported by a managed detection and response partner. These controls detected or prevented many common techniques.
The principal gap was the conversion of telemetry into timely, prioritised action. Across the complete exercise, 34% of tested scenarios were reported as Indicator of Compromise detections. The remaining activity should not be interpreted as an absence of logs: the assessment found that relevant data was often likely present but not elevated into an alert because of missing rules, unparsed events, categorisation, handover or resource constraints.
Engagement at a glance
- - Twelve MITRE ATT&CK tactic families exercised
- - Standard-user laptop, VPN and controlled rogue-device perspectives
- - Endpoint, network, identity, cloud, SIEM and managed-response evidence correlated
- - Thirty-four percent of tested scenarios flagged as IoC detections
- - Observed detection-response times ranged from five minutes to six days
- - Password-spray and Microsoft Management Console monitoring improved during testing
Challenge
Purple Teaming had to test technology and process together while preserving the realism of a live, globally distributed security operation. Three challenges shaped the assessment.
Scale and signal volume
Endpoint, network, identity, cloud and managed-service evidence was distributed across multiple systems. High event volumes, unparsed cloud records and incomplete SIEM rules made weak indicators difficult to prioritise, even where underlying telemetry existed.
Collaboration without losing realism
Daily Purple Team discussions allowed defenders to tune controls quickly, but the SOC was also handling normal operational work. Awareness of the exercise, different service-level expectations and handovers between teams could affect normal incident handling and response time.
Prevention was not always containment
Endpoint controls frequently stopped an initiating executable or common attack technique. The assessment still needed to determine whether child processes, migrated implants, local-account changes, scheduled persistence or data-transfer activity continued after the first prevention event.
Assessment Scope
The public case study generalises all original systems, users and network identifiers. Testing concentrated on the following trust paths:
- - Managed endpoints: standard-user company laptops, local execution, endpoint prevention, persistence, privilege and collection behaviour
- - Valid user and VPN access: insider-threat activity using legitimate domain identities and the internal reach granted to ordinary users
- - Controlled rogue systems: authorised Linux systems placed in internal network segments to test visibility outside managed endpoints
- - Network and identity: scanning, name poisoning, authentication relay, network shares, weak devices, segmentation and lateral-movement opportunities
- - Cloud and telemetry: cloud-portal visibility, directory enumeration, endpoint events, network analytics, SIEM ingestion and event categorisation
- - SOC and managed response: whether activity was blocked, logged, alerted, investigated, escalated and contained, including elapsed response time
The engagement assumed that an insider, compromised user or rogue internal device already had an initial foothold. It therefore focused on the visibility and control of activity after access rather than treating phishing or perimeter compromise as the sole starting point.
Solution
ProCheckUp treated every technique as both an attacker action and a test of the defensive evidence chain. The Red Team and Blue Team worked collaboratively, while the assessment retained independent records of what was attempted, what each control did and when defenders became aware.
The assessment followed four stages:
- 1. Design: map realistic insider and rogue-device scenarios to MITRE ATT&CK, agree safety limits and define the evidence required.
- 2. Exercise: execute controlled activity through managed-laptop, VPN, internal-device, network, identity and cloud paths.
- 3. Observe: classify whether each action was prevented, logged, alerted, investigated, escalated or contained, including response time.
- 4. Tune: review evidence with the Blue Team, improve rules and categorisation, and repeat selected activity to confirm better visibility.
Five defensive states were kept separate: prevented is not the same as logged; logged is not the same as alerted; alerted is not the same as investigated; and investigation is not the same as containment. This distinction prevented a single endpoint event from being mistaken for closure of the whole attack chain.
MITRE ATT&CK Tactic Benchmark
The assessment exercised twelve MITRE ATT&CK tactic families. Ratings reflected the viability and potential impact of the tested behaviour together with the customer’s prevention, detection and response—not the severity of an individual software vulnerability.
High assessed risk
- - Exfiltration: controlled data-transfer routes were not detected consistently across command-and-control, web, authenticated external file sharing and Bluetooth channels
Medium assessed risk
- - Reconnaissance
- - Execution
- - Persistence
- - Privilege Escalation
- - Discovery
- - Collection
- - Command and Control
Low assessed risk
- - Initial Access
- - Defence Evasion
- - Credential Access
- - Lateral Movement
The customer showed stronger detection for Initial Access and Command and Control, with good protection against many common Execution and Defence Evasion techniques. Coverage became less consistent after foothold, particularly across Reconnaissance, Privilege Escalation, Discovery, Persistence, Collection and Exfiltration.
Principal Detection Findings
The tactic-level evidence converged on six cross-cutting themes.
Telemetry did not consistently become an alert
Relevant events were spread across multiple platforms. Missing rules, unparsed cloud records, weak severity categorisation and competing analyst workload allowed activity to remain logged but unactioned.
Recommendation: measure the full telemetry-to-containment pipeline, parse all priority sources, rationalise duplicate portals, tune severity and define clear alert ownership and escalation service levels.
Rogue-device reconnaissance was largely invisible
Conspicuous internal scanning and enumeration from unmanaged test systems generally did not trigger alerts unless selected honeypots were probed. Managed laptops produced stronger telemetry than rogue systems connected elsewhere on the network.
Recommendation: detect scanning from every internal source, expand network analytics and deception coverage, monitor unmanaged-device behaviour and bring non-standard systems into central visibility.
Flat networks widened post-compromise reach
Valid users and VPN-connected systems could communicate with broad internal infrastructure, including less-monitored non-Windows and embedded devices. Guest-access shares and weak device services created further foothold and collection opportunities.
Recommendation: segment by business trust boundary, restrict ordinary-user and VPN reach, isolate weak or embedded systems and verify that firewalls enforce least-necessary communication.
Endpoint prevention sometimes stopped the loader, not the chain
Endpoint protection blocked many common payloads. Advanced process behaviour, repeated execution and trusted utilities could still leave a working child process. In one authorised path, the initiating abuse was detected while subsequent local-account creation and administrator-group membership change were not.
Recommendation: correlate parent and child process trees, alert on local-account and group changes, monitor scheduled tasks and confirm that containment terminates every spawned process and session.
IPv6 activity created a credential-access blind spot
Common name-poisoning activity was detected rapidly, but a more advanced IPv6 adversary-in-the-middle path went undetected and captured an elevated operations-account hash. The hash was not cracked, and the customer’s password policy reduced the likelihood of successful offline recovery.
Recommendation: disable IPv6 where it is not required; otherwise monitor DHCPv6, rogue router advertisements and IPv6 name-resolution activity. Require SMB signing and close relay paths consistently.
Collection and exfiltration had the weakest end-to-end coverage
Controlled proof-of-concepts demonstrated unnoticed archive creation and transfer through command-and-control, web upload, authenticated external file sharing and Bluetooth. USB transfer was blocked, showing that control effectiveness differed materially by channel.
Recommendation: correlate archive creation with outbound traffic, restrict direct-IP and outbound SMB access, govern Bluetooth and web-upload destinations, and tune data-loss controls around abnormal user, process and destination behaviour.
Detection Response and Live Improvements
Thirty-four percent of tested scenarios were flagged as IoC detections. This metric reflects scenarios reported to ProCheckUp as detections and does not mean that the remaining activity generated no raw logs.
Observed response times ranged from five minutes to six days. When the largest outliers were excluded, detected activity could still take up to approximately seven hours to reach analysis. Discovery and Persistence included some of the longer response times.
The collaborative model produced two immediate improvements during the engagement:
- - Password-spray detection: rules were enhanced to identify and alert on distributed authentication guessing more effectively
- - Microsoft Management Console activity: monitoring and alerting were strengthened for suspicious use of a legitimate administration tool
These changes demonstrate the practical value of Purple Teaming: improvement began while testing was in progress rather than waiting for a final report.
Authorised Attack Model
The following sequence combines confirmed outcomes from multiple scenarios. It is an authorised model of attacker progression, not evidence of a real-world breach:
- 1. Valid user or rogue internal device — provided: the engagement began with standard credentials, VPN access or a controlled internal system.
- 2. Map the environment — confirmed: endpoint, network, cloud and directory reconnaissance exposed reachable systems and services.
- 3. Obtain execution — confirmed: allowed downloads, macros, trusted utilities and custom code provided several execution paths.
- 4. Evade or retain access — partly confirmed: advanced process behaviour and persistence techniques sometimes outlived the initiating prevention event.
- 5. Elevate or pivot — partly confirmed: local-account changes, weak devices and broad internal reach created post-compromise options.
- 6. Collect information — confirmed: directory data, screenshots, shared information and local files could be gathered or archived.
- 7. Transfer controlled proof-of-concept data — confirmed: selected command-and-control, web, SMB and Bluetooth transfers succeeded without consistent alerting.
This sequence does not state that a genuine attacker was present, that production information was stolen, that durable persistence was established or that business operations were disrupted.
Control Effectiveness and Assessment Boundaries
Positive controls observed
- - Managed endpoints blocked many basic payloads and malicious behaviours
- - Detailed endpoint telemetry supported incident reconstruction
- - Host isolation was highly effective when deliberately activated
- - Common brute-force, credential-dumping and basic name-poisoning techniques were often detected
- - Standard users had limited access to common remote-administration services
- - Network authentication reduced casual unauthorised-device access
- - Internal analysts and the managed-response partner provided capable advice and adapted rules during testing
Assessment limitations and context
- - Some laptops and internal test systems became available later than planned
- - Local administrative access was delayed
- - Connectivity to controlled internal systems was intermittent
- - Additional internal test locations became available late in the exercise
- - The SOC continued handling normal operational responsibilities
- - Awareness of the Purple Team engagement could alter normal incident-response behaviour
- - The results are a point-in-time benchmark rather than a guarantee of complete attack coverage
- - The source report does not establish that every recommendation was subsequently implemented and independently retested
Outcome
The engagement converted a broad security-control estate into a measurable detection-improvement programme. It gave security leadership a defensible baseline, showed analysts where attacker evidence was lost and demonstrated that rules could improve while testing was still underway.
The results confirmed that defensive capability was meaningfully mature, particularly on managed endpoints and against common attack patterns. The principal opportunities arose once an attacker moved beyond initial access into Reconnaissance, Discovery, Persistence, Collection and Exfiltration, or operated through unmanaged internal devices and less-monitored protocols.
Rather than producing a conventional vulnerability list, the exercise linked each attacker action to its defensive result: prevented, logged, alerted, investigated, contained or missed. This separated technology gaps from rule gaps, event-parsing problems, severity calibration, handover delays and resource constraints.
The live improvements to password-spray and MMC detections demonstrated that the customer’s Blue Team could adapt quickly. The resulting programme prioritised segmentation, wider telemetry coverage, SIEM tuning, stronger egress controls and repeat verification.
Publication boundary: this case study does not state that the complete remediation programme was subsequently implemented or independently retested.
Remediation Priorities
Immediate visibility and containment
- - Segment internal systems using firewalls, VLANs and access controls
- - Bring non-standard and embedded devices into central monitoring
- - Parse and alert on high-value cloud and endpoint data currently left unclassified
- - Detect port scanning and reconnaissance from every internal source
- - Disable IPv6 where unused and monitor rogue DHCPv6 activity where retained
- - Establish an approved remote-access software policy
- - Restrict outbound SMB, patch vulnerable devices and replace weak or default passwords
- - Harden unwanted Bluetooth connectivity on company laptops
Detection and engineering improvements
- - Continually refine SIEM rules, severity, categorisation and alert ownership
- - Align internal SOC and managed-service response procedures and service levels
- - Alert when endpoint or network-monitoring agents go offline
- - Require SMB signing and monitor FTP, Telnet and other insecure protocols
- - Enable full-disk encryption on company laptops
- - Detect macro-enabled documents spawning unusual processes
- - Improve process-injection, local-account and scheduled-task monitoring
- - Enforce MFA, application allowlisting and stronger web-proxy and direct-IP controls
Sustained detection assurance
- - Remove guest-access shares and restrict risky file downloads
- - Conduct regular Purple Team exercises and focused replay tests
- - Complete managed-rule transitions and expand managed detection categories
- - Broaden honeynet, IDS/IPS and network-analytics coverage
- - Monitor unusual data flows and large outbound transfers
- - Reduce standing administrative privilege and monitor local administrator groups
- - Restrict unapproved Windows Subsystem for Linux and equivalent alternative execution environments
The Core Security Lesson
Telemetry is not detection until it becomes actionable.
Purple Teaming connects attacker behaviour to defensive evidence, analyst judgement and response. The objective is not merely to prove that an event exists in a console. It is to confirm that the organisation recognises the complete attack chain, assigns the right priority and contains it before the attacker reaches the intended objective.
The correct question is not simply:
“Did one product raise an alert?”
It is:
“Did the combined security operation identify, investigate and stop the full chain?”
How ProCheckUp Helps
ProCheckUp’s Purple Teaming service turns relevant threat scenarios into measurable improvements across people, process and technology. Support can include:
- - Threat-led and MITRE ATT&CK-aligned scenario design
- - Insider-threat, compromised-user and rogue-device simulation
- - Testing from managed endpoints, VPN contexts and internal network positions
- - Endpoint, identity, network, cloud and data-transfer attack paths
- - EDR, NDR, SIEM, SOC and managed-response evidence correlation
- - Prevention, logging, alerting, investigation and containment measurement
- - Detection-response timing and escalation analysis
- - Live detection engineering and alert-rule refinement
- - Controlled replay testing to verify improvements
- - Immediate, engineering and sustained-assurance remediation roadmaps
Related services include Red Teaming, Penetration Testing and Cloud Penetration Testing.
Conclusion
This engagement demonstrated why a mature security operation must test the complete path from attacker action to containment. The decisive gaps were not limited to missing tools: they included telemetry that was not parsed, events that were not prioritised, unmanaged internal activity, broad network reach and controls that stopped an initial process without closing the wider chain.
By combining realistic simulation, direct Blue Team collaboration, live rule improvement, network segmentation, wider telemetry coverage and repeat verification, organisations can turn existing security investment into faster and more reliable detection and response.
To discuss a Purple Teaming engagement, targeted detection-validation exercise or wider adversary simulation, contact ProCheckUp.
For More Information Please Contact Us
ACCREDITATIONS
