Webcasts

To attend this webcast, login to your SANS Account or create your Account.

Practical tips to build a successful purple team

  • Wednesday, August 14th, 2019 at 10:30 AM EDT (14:30:00 UTC)
  • Erik Van Buggenhout
This webcast has been archived. You can view the webcast presentation and download the slides by logging into your SANS Portal Account or creating an Account. Click the Register Now button after you have logged in to view the Webcast.

You can now attend the webcast using your mobile device!

Overview

The Purple Team Summit will bring together leading security practitioners to explore practical uses of threat emulation tactics, detection capabilities, and security controls. Experts will draw upon their own experiences and share current purple team concepts that you can implement within your own security program.

Purple Team is a hot topic! Many organizations (small to large) are attempting to implement purple team techniques to improve their overall cyber security posture. But what is purple teaming? How can we concretely start doing it? Amongst others, we will try to respond to the following questions:

  • How does purple team compare to red team?
  • How can we improve the "red-blue" feedback loop?
  • What tools are available that can support our purple team efforts?
  • How can we leverage MITRE ATT&CK?
  • What profiles do I need to perform purple teaming?
  • What are some key metrics and KPI's for your purple team efforts? (or: how to gain management support?)

Speaker Bio

Erik Van Buggenhout

Erik Van Buggenhout is the lead author of SEC599 - Defeating Advanced Adversaries. In addition to SEC599, Erik teaches SEC560 - Network Penetration Testing & Ethical Hacking and SEC542 - Web Application Penetration Testing & Ethical Hacking. He has been involved with SANS since 2009, first as a Mentor, working his way to Community Instructor in 2012 and finally becoming a Certified Instructor in 2016.

Erik loves explaining deeply technical concepts by using war stories, adding a few funny anecdotes here and there. As a testimony of his technical expertise, he has obtained the GSE, GCIA, GNFA, GPEN, GWAPT, GCIH, and GSEC certifications.

In addition to his work with SANS, Erik is the co-founder of Belgian cyber security firm NVISO, which focuses on high-end cyber security services, specializing in government, defense and the financial sector. Together with his team of 20+ technical experts, Erik delivers a wide array of technical security services, including penetration testing, security monitoring & incident response.

Need Help? Visit our FAQ page or email webcast-support@sans.org.

Not able to attend a SANS webcast? All Webcasts are archived so you may view and listen at a time convenient to your schedule. View our webcast archive and access webcast recordings/PDF slides.