Ciberseguridad ofensiva · Cybersecurity
Red Team and Purple Team
Full adversarial assessment and collaborative work with your defensive team, mapped to MITRE ATT&CK, to strengthen the defences where they actually give way.
- Framework
- MITRE ATT&CK
- Duration
- 4 to 8 weeks
- Red Team
- Stealth exercise, no notice to the internal team
- Purple Team
- Collaborative exercise, attacker and defender together
The problem
The Red Team attacks without warning and measures real detection. The Purple Team does the same, but with the defensive team watching the screen: each technique is executed, you observe whether it raises an alert and the rule is tuned on the spot. One measures, the other teaches.
What it includes
Reconocimiento
Se recopila información sobre el entorno objetivo para identificar activos, relaciones y vulnerabilidades aprovechables.
Planificación
Se desarrollan estrategias y tácticas específicas para alcanzar los objetivos definidos en el entorno objetivo.
Análisis de vulnerabilidades
Se identifican debilidades en sistemas y aplicaciones que puedan explotarse para lograr esos objetivos.
Explotación
Se aplican activamente técnicas y tácticas para aprovechar las vulnerabilidades identificadas durante la planificación.
Post-explotación
Se busca mantener el acceso y ampliar el control sobre el entorno comprometido tras la intrusión inicial.
Exfiltración
Se transfieren datos desde el entorno comprometido a ubicaciones controladas, para demostrar el impacto real de la brecha.
Sesión Purple
Ejecución conjunta con tu equipo de defensa: cada técnica se lanza, se revisa si generó alerta y se corrige la detección en el momento.
How we work
- 01DefiniciónObjetivos, límites, activos críticos y reglas de enfrentamiento.
- 02Ejecución RedOperación sigilosa mapeada a MITRE ATT&CK.
- 03Sesión PurpleRepetición de las técnicas junto al equipo defensor, ajustando detecciones.
- 04ClosingInforme, métricas de detección y plan de mejora.
Deliverables
| Document | Length |
|---|---|
| Informe de operación Cadena de ataque completa, mapeada a ATT&CK. | included |
| Matriz de detección Qué técnicas se detectaron y cuáles no. | included |
| Reglas propuestas Detecciones nuevas para tus herramientas. | included |
Scope of responsibility: in black box exercises it may not be possible to test every MITRE ATT&CK technique. If a device cannot be compromised, the client decides whether to provide additional access so the technique can still be evaluated. And if the objective is exfiltration, some techniques may not be necessary.