Skip to content
Paul Marinos
Menu

The Purple Team Loop

The full circuit from adversary technique to tested detection — emulation, detection validation, backlog, and prioritization — and why breaking the loop is what makes red teaming theater.

A red team engagement that ends with a report of what got compromised has delivered half its value and thrown the other half away. The half that lasts is the loop: the technique the adversary used becomes a tested detection, which changes what the next adversary can get away with. Without the loop, offense and defense are two teams measuring each other; with it, they are one system that improves.

It starts with adversary emulation — “can we execute this actor’s techniques and see who notices,” not “can we get in.” The engagement is threat-informed: pick an actor whose targeting pattern makes you plausibly next, emulate its TTPs, and treat detection evasion as a measurement instrument rather than a trophy. What got caught, what didn’t, and why, is the data — which means the engagement has to be instrumented and deconflicted, not just successful.

The engagement timeline is now a list of techniques with a caught/not-caught verdict against each. That is exactly the input detection quality needs. Each “not caught” is a coverage gap; each “caught” is a control to regression-test so it does not silently rot. Atomic Red Team and adversary emulation turn the one-time engagement finding into a repeatable test — the difference between “we weren’t detecting this in March” and “we detect this, and we prove it every build.”

A validated gap is a detection lifecycle intake. The hypothesis is handed the technique, checks whether the data source even exists to see it, and if so produces a rule that is tuned, deployed and monitored for drift. This is where the loop most often breaks: a red team finds twenty gaps, three become rules, and the other seventeen are a PDF nobody actioned. The loop only closes if the finding enters a backlog with an owner.

Twenty gaps do not get fixed at once, so the backlog is a prioritization problem — the same one every queue on this site inherits. Order by which techniques the emulated actor actually leads with, which map to exposed assets, which have the business behind them. A gap in a technique your threat model says you will face beats a gap in one you will not, and the base-rate discipline keeps the queue honest.

The output of prioritize feeds the next emulate: the technique you decided to build a detection for is the one the next engagement should try to slip past, to confirm the rule works against a live operator rather than only against a replay. Emulate → validate → backlog → prioritize → emulate. Each lap raises the floor.

The reason this is a thread and not a single pillar’s article is that no pillar owns it. Red teaming owns emulate, detection engineering owns validate and backlog, intel owns prioritize — and an organization that staffs those separately, with no handoff between them, has bought all four capabilities and none of the loop. It is the same disconnect that lets one finding be rediscovered five times, and its natural sequel is alert to answer, which picks up when a detection built here actually fires.

Graph View

Last updated:

Spotted an error on this page? Report it.