Group Purchasing
Group Purchasing

Red, Blue and Purple Teams: Combining Your Security Capabilities for the Best Outcome

Red, Blue and Purple Teams: Combining Your Security Capabilities for the Best Outcome (PDF, 2.63MB)Published: 02 Oct, 2019
Created by:
Chris Dale
Chris Dale

Red, Blue and Purple Teams: Combining Your Security Capabilities for the Best Outcome, published by SANS Institute in October 2019, argues that the traditional adversarial relationship between offensive (Red Team) and defensive (Blue Team) security functions is outdated, and proposes a collaborative "Purple Team" model instead. Written by SANS instructor Chris Dale, who teaches SEC504: Hacker Tools, Techniques, Exploits, and Incident Handling, the paper offers concrete tactics for merging Red and Blue Team efforts to improve organizational security posture.

Key concepts and recommendations:

  • A successful security program shouldn't measure Red Team value by how often it breaks in; if the Red Team always succeeds, the team isn't fulfilling its actual purpose of making the organization harder to attack
  • Splitting a penetration test into two deliveries, a lower-cost reconnaissance/discovery phase followed by exploitation and verification, lets Red and Blue Teams agree on scope collaboratively rather than relying solely on pre-engagement scoping meetings
  • Red Team reports should extend beyond vulnerability details to include detection actions and remediation actions, giving the Blue Team a layered path from finding the issue to fixing the underlying process
  • Blue Teams can accelerate value by feeding the Red Team an existing vulnerability scan for review, or by providing credentials to high-risk assets in advance to identify post-authentication vulnerabilities before real credentials are compromised
  • Automation benefits both teams: Red Teams can use breach simulation to focus on higher-value testing, while Blue Teams can automate detection of Red Team tactics, techniques, and procedures (TTPs) and automatically isolate suspected threats via private VLANs
  • Automation carries its own risk: a vulnerability scanner running with elevated credentials could inadvertently expose those credentials if it scans an attacker-controlled host
  • Real-time collaboration platforms (e.g., screen sharing, shared chat threads) can resolve ambiguous findings, like a suspected false positive, in minutes instead of hours

The paper's central argument is that Red and Blue Teams optimized purely for their own success metrics, breaking in versus stopping every breach, actually work against the organization's real goal of continuous security improvement. Removing that adversarial framing in favor of shared reporting, joint scoping, and real-time collaboration produces measurably better outcomes than running the two functions in isolation.

FAQ

Meet the expert

Chris Dale
Chris Dale

Chris Dale

Principal Instructor

SANS Principal Instructor and River Security CHO Chris Dale helps students turn offensive security insight into practical skills for incident handling, purple teaming, and stronger organizational defense.

Read more about Chris Dale