Purple teaming (emulate → detect → improve)
SkillAI & modelsRun a purple-team exercise, emulate specific attacker techniques and validate detection/response end to end. Load for "purple team", detection validation, ATT&CK coverage testing, "can we detect X", or turning red-team findings into blue-team improvements. Signals: detection gaps, ATT&CK mapping, control testing.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Purple teaming (emulate → detect → improve) skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/defense/defense-purple-team/SKILL.md and read by ahel’s review.
When it applies
You want to measure and improve detection, not just find bugs. Purple teaming runs known attacker techniques in a controlled way and checks whether each is prevented, detected, and responded to — closing the loop between offense and defense.
Why it works
Detections are only real if they fire on the actual technique. Emulating each technique and watching the telemetry proves coverage, exposes blind spots, and produces tuned detections — turning "we think we'd catch it" into evidence.
Method
- Pick techniques from real risk: map to MITRE ATT&CK, prioritized by your threat model
(→
defense-threat-modeling) and recent red-team/pentest findings. - Emulate safely: run controlled tests — Atomic Red Team (per-technique atomics) or CALDERA (chained) in a lab/segmented env. One technique at a time, documented.
- Observe the pipeline: for each, check — was it prevented (EDR/control)? logged (right source/fields)? detected (alert fired)? responded (triaged in time)? Record the gap at each stage.
- Fix the gaps: add/tune detections (→
defense-detection-sigma), fix logging coverage, harden the control (→defense-hardening-baseline), and improve the runbook. - Re-test to confirm the detection fires and is low-FP; track ATT&CK coverage over time.
Anti-patterns
- Running noisy tools blindly instead of specific, mapped techniques — you learn nothing measurable.
- Declaring "detected" without checking the alert actually fired and was actionable.
- One-and-done — coverage decays; re-run after infra/detection changes.
Verify
For each emulated technique: a documented prevent/detect/respond result, a new or tuned detection for every gap, and a re-test showing it now fires cleanly.
References
MITRE ATT&CK; Atomic Red Team; MITRE CALDERA; "purple team exercise framework" (SCYTHE).
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
defense-purple-team- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · microsoft
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infrasecrets-exposure-review
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secretsowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)