The Challenge
The client is a large enterprise with a mature security function, a well-staffed operations center and substantial investment in detection and response tooling. That investment was the problem. Leadership could describe what the organization had bought but not what it could catch, and the security team suspected that coverage was uneven in ways nobody had measured.
A covert red team would have answered a narrow version of the question by finding one path and proving it worked. What the enterprise needed was breadth: an honest map of which adversary techniques generated an alert, which generated telemetry that nobody was watching, and which produced nothing at all.
Our Approach
StrikeCyber ran a collaborative purple team exercise, executing a defined set of techniques mapped to MITRE ATT&CK while the client's detection engineers watched their own consoles in real time.
- A technique set selected from adversary profiles relevant to the client's sector, spanning initial access, execution, persistence, credential access, lateral movement and exfiltration.
- Each technique executed openly, with the operator and the detection engineer observing together what appeared in the tooling and what did not.
- Immediate tuning between executions, so a technique that produced nothing could be instrumented and retested within the same session.
The value of adversary simulation run this way is the feedback loop. Rather than a report arriving weeks later, the detection team improved its coverage during the engagement and confirmed the improvement immediately.
What We Found
- Strong coverage of commodity activity. Known malicious binaries, common attack tooling and obvious command-and-control patterns were reliably detected.
- Weak coverage of living-off-the-land techniques. Activity carried out with built-in system utilities generated telemetry but no alerting, and was consistently missed.
- Credential access largely invisible. Several techniques for harvesting credentials from memory and from disk produced no detection at all.
- Alerting configured but not routed. A number of rules fired correctly into a console nobody monitored outside business hours.
The Outcome
The detection engineering team wrote and tuned new rules for the living-off-the-land and credential access techniques during the exercise itself, then confirmed them against a repeat execution. Coverage across the tested technique set improved substantially, and more importantly the team learned which of its assumptions about coverage had been wrong.
The routing problem was addressed by restructuring alert severity and on-call escalation, so that the rules already working reached someone who could act. The enterprise now repeats a condensed version of the exercise quarterly, using it to validate that coverage has not regressed as tooling and environments change.
Why It Matters
Detection coverage is easy to assume and hard to know. Tools are bought, rules are enabled, dashboards look healthy, and nobody establishes which of the techniques a real adversary would use would actually raise an alarm. A purple team answers that question technique by technique, and it improves the answer while it is being asked. To measure what your tooling would actually catch, get in touch.