Red team and blue team exercises

Facilitated exercises where an attacking team and a defending team work through agreed scenarios in an isolated lab, followed by a joint debrief on detection and response.

On this page

Program overview

In these exercises an attacking team carries out an agreed set of techniques while a defending team monitors, investigates, and responds. The red side can be your own offensive security staff or DeployOpen engineers. The blue side is usually your SOC, incident responders, or detection engineers.

All activity runs in an isolated lab or private range set up to match the parts of your environment in scope. Exercises can run with each side working separately, or as a purple team session where both sides share notes as each technique runs.

Skills covered

Adversary emulation

Planning and running a sequence of techniques from a chosen threat group or scenario, and keeping an activity log the blue team's results can be checked against.

Detection and alert tuning

Finding which techniques produce signals in your tools, which do not, and what rule or logging changes would close the gap.

Investigation and response

Tracing attacker activity across hosts and accounts, containing it, and confirming it has stopped.

Purple team collaboration

Working through techniques one at a time with both sides present, so the blue team sees the exact activity behind each signal.

Reporting

Explaining findings to the other team and to management in terms each audience can act on.

How the program runs

We agree objectives with both teams: which threats to emulate, which defenses to test, and what each side should learn. We review your detection stack, logging, and response procedures to choose relevant techniques.

Formats

FormatWho it suitsWhat it covers
Purple team sessionTeams building or tuning detectionsTechniques run one at a time with both sides present, discussing each signal as it appears
Red versus blue exerciseEstablished SOC and response teamsA full scenario where the blue team does not know the plan in advance, followed by a joint debrief
Tabletop walkthroughSecurity leads and managersAn attack path and the expected detections and responses, discussed without hands-on systems
Recurring exercisesTeams tracking detection coverage over timeNew or repeated techniques at an agreed interval, compared with earlier results

Sample scenarios

Initial access to domain compromise

A phishing foothold, credential theft, lateral movement, and privilege escalation in a Windows Active Directory lab.

Ransomware operator emulation

Discovery, defense evasion, backup deletion, and staged encryption based on publicly reported ransomware group behavior.

Cloud control plane attack

Use of a leaked access key, privilege escalation through role assumption, and access to data in cloud storage.

Living off the land

Built-in system tools and scripting used for discovery and persistence, testing detections that do not depend on malware signatures.

Data exfiltration

Staging data and moving it out over common protocols, testing network monitoring and data loss controls.

Attacks on AI-enabled workflows

Prompt injection against an internal AI assistant with tool access, testing whether its actions are logged and detected.

What you receive

The debrief and written outputs connect each red team action to what the blue team saw.

Technique-level results

  • Each technique mapped to MITRE ATT&CK
  • Whether it was prevented, detected, logged only, or missed
  • Time from action to detection where it was recorded

Detection improvements

  • New or revised detection rules to write
  • Log sources to add or adjust
  • Related defensive techniques from MITRE D3FEND

Response findings

  • Investigation or containment steps that slowed the team
  • Runbook changes and missing playbooks
  • Access or tooling responders lacked

Materials to rerun

  • Exercise plan and red team activity log
  • Lab configuration notes
  • A retest list for techniques that were missed

Common questions

Who should attend?

Offensive security staff, SOC analysts, threat hunters, detection engineers, and incident responders. Security managers can join the debrief.

Do we need our own red team?

No. DeployOpen engineers can act as the red team, or work alongside your offensive security staff.

Do the exercises use our tools?

Yes. The lab is set up around your detection and response tools and the parts of your environment in scope. All activity stays inside the isolated lab or private range.

Is it remote or on-site?

Remote or on-site delivery can be agreed.

How do you measure progress?

Results are recorded per technique. Repeating the same techniques in a later exercise shows which gaps have been closed.

Is the work confidential?

Yes. We sign an NDA on request, and exercise outputs are handled as sensitive material under an agreed handling plan.

How to prepare

Tell us what you want to test: a specific threat group, a set of techniques, or recent detection changes. Share a summary of your detection stack, logging, and response procedures.

Name a sponsor who approves the exercise plan and a contact on each side. Decide whether the blue team should know the plan in advance, and arrange for participating analysts to be released from normal duties during the exercise.

MITRE ATT&CK and D3FEND

Exercise plans and results use MITRE ATT&CK technique IDs, so findings can be compared with your detection coverage and repeated in later exercises. Each exercise includes only the techniques that serve its objective.

Recommended defensive changes reference MITRE D3FEND, which describes defensive techniques and links them to the offensive techniques they counter.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.