Purple Team Ops
Bridge skill: this is a both-blue-and-pentest category. The actual work is collaboration — red simulates a TTP, blue tries to detect it, both learn at the same time. No surprise engagements ("see if we catch them without warning"); that is red team. Purple is planned, measured, and aimed at gap closure.
When to use
A SOC can write endless rules without ever knowing if they cover the right TTPs. A red team can run endless engagements without the defensive side learni
[Description truncada. Veja o README completo no GitHub.]