Skip to content
StrikeCyberStrikeCyber
Enterprise

Adversary Simulation and Purple Team for an Enterprise

A large enterprise had invested heavily in detection tooling and wanted to know which techniques it would actually catch.

Industry
Enterprise
Services
Adversary Simulation
Engagement
Collaborative purple team exercise

The Challenge

The client is a large enterprise with a mature security function, a well-staffed operations center and substantial investment in detection and response tooling. That investment was the problem. Leadership could describe what the organization had bought but not what it could catch, and the security team suspected that coverage was uneven in ways nobody had measured.

A covert red team would have answered a narrow version of the question by finding one path and proving it worked. What the enterprise needed was breadth: an honest map of which adversary techniques generated an alert, which generated telemetry that nobody was watching, and which produced nothing at all.

Our Approach

StrikeCyber ran a collaborative purple team exercise, executing a defined set of techniques mapped to MITRE ATT&CK while the client's detection engineers watched their own consoles in real time.

  • A technique set selected from adversary profiles relevant to the client's sector, spanning initial access, execution, persistence, credential access, lateral movement and exfiltration.
  • Each technique executed openly, with the operator and the detection engineer observing together what appeared in the tooling and what did not.
  • Immediate tuning between executions, so a technique that produced nothing could be instrumented and retested within the same session.

The value of adversary simulation run this way is the feedback loop. Rather than a report arriving weeks later, the detection team improved its coverage during the engagement and confirmed the improvement immediately.

What We Found

  • Strong coverage of commodity activity. Known malicious binaries, common attack tooling and obvious command-and-control patterns were reliably detected.
  • Weak coverage of living-off-the-land techniques. Activity carried out with built-in system utilities generated telemetry but no alerting, and was consistently missed.
  • Credential access largely invisible. Several techniques for harvesting credentials from memory and from disk produced no detection at all.
  • Alerting configured but not routed. A number of rules fired correctly into a console nobody monitored outside business hours.

The Outcome

The detection engineering team wrote and tuned new rules for the living-off-the-land and credential access techniques during the exercise itself, then confirmed them against a repeat execution. Coverage across the tested technique set improved substantially, and more importantly the team learned which of its assumptions about coverage had been wrong.

The routing problem was addressed by restructuring alert severity and on-call escalation, so that the rules already working reached someone who could act. The enterprise now repeats a condensed version of the exercise quarterly, using it to validate that coverage has not regressed as tooling and environments change.

Why It Matters

Detection coverage is easy to assume and hard to know. Tools are bought, rules are enabled, dashboards look healthy, and nobody establishes which of the techniques a real adversary would use would actually raise an alarm. A purple team answers that question technique by technique, and it improves the answer while it is being asked. To measure what your tooling would actually catch, get in touch.

FAQ

About this case study

Is this a real StrikeCyber engagement?

Yes. This enterprise case study is drawn from a genuine engagement, anonymised where needed to protect the client, showing the challenge, our approach and the outcome.

Can StrikeCyber deliver similar results for our organization?

Yes. The expert-led, prioritized approach behind this outcome applies across enterprise and other sectors and organization sizes. Scope a free consultation to discuss your environment.

How is client confidentiality protected?

Findings and client data are isolated to your organization and handled in access-limited environments we control in the United States. Nothing is published without the client's consent.

Ready to take the offensive?

StrikeCyber specializes in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

(877) 657-8496Free Consultation