Security testing is often framed as teams: red attacks, blue defends, and purple brings them together to improve faster.
Red, Blue & Purple Teaming
Offence and defence, working together.
Tap or hover a part to learn more.
Attack.
The red team simulates real adversaries — penetration testing and adversary emulation — to find weaknesses before genuine attackers do.
Check your understanding
1. What does a red team do?
2. What is purple teaming?
Keep learning
The teams
- Red team — simulates real adversaries (penetration testing, adversary emulation) to find gaps before attackers do.
- Blue team — the defenders: the SOC, incident response and threat hunting.
- Purple teaming — not a separate team but a collaborative approach: red shares techniques, blue verifies detection and response, and both improve together in real time.
The goal isn't to 'win' but to measurably improve detection and response, often mapped to MITRE ATT&CK. Purple teaming turns a one-off test into continuous improvement — mature, effective and increasingly expected.
