Purple Teaming for Blue Teams
Master Purple Teaming for Blue Teams
Stop guessing if your detections actually work. Run realistic purple team exercises to validate, improve, and measure your detection coverage across Microsoft Sentinel, Defender XDR, and open-source SIEMs, turning assumptions into proven resilience.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Phase 1: Foundations and Lab Build
What Purple Teaming for Blue Teams teaches: stop assuming your detections fire and prove it. Emulate each attacker technique, watch whether detection catches it, fix the gaps, and measure real coverage across Sentinel, Splunk, and Elastic, walking 61 ATT&CK techniques end to end. The validation loop you'll run, the proven coverage you walk away with, and how the course is structured. Start here.
Show 7 lessonsHide lessons
- 0.1PT0.1 How Real Incidents Actually Unfold, and What Your Rules MissPreview
- 0.2PT0.2 The Purple-Team MindsetPreview
- 0.3PT0.3 The Vocabulary of CoveragePreview
- 0.4PT0.4 The Toolkit and What Comes NextPreview
- 0.5Module SummaryPreview
- 0.6Check My KnowledgePreview
- 0.7Sample Technique Sub. T1059.001 PowerShell (Preview from Module 3)Preview
Build a four-environment, three-SIEM purple-team lab from scratch. Windows endpoint with Sysmon, Active Directory domain controller, Linux with auditd, M365 developer tenant, Sentinel, Defender XDR Advanced Hunting, and your choice of Splunk Free or Elastic. Fire the first technique and confirm telemetry lands in all three SIEMs.
Show 14 lessonsHide lessons
- 1.1PT1.1 Why a Local Lab, and Why Not Your Work Environment
- 1.2PT1.2 Hypervisor and VM Setup
- 1.3PT1.3 Windows Endpoint Build with Sysmon
- 1.4PT1.4 Active Directory Domain Controller Build
- 1.5PT1.5 Joining the Endpoint to the Domain
- 1.6PT1.6 Linux VM Build with auditd
- 1.7PT1.7 M365 Developer Tenant Configuration
- 1.8PT1.8 Azure Subscription, Sentinel, and Log Analytics
- 1.9PT1.9 Defender XDR Advanced Hunting
- 1.10PT1.10 Secondary SIEM. Splunk Free
- 1.11PT1.11 Secondary SIEM. Elastic Stack
- 1.12PT1.12 Smoke Test. Fire Your First Technique
- 1.13Module Summary
- 1.14Check My Knowledge
Phase 2: Walking the ATT&CK Kill Chain
Walk six initial access techniques end-to-end: spearphishing links and attachments, stolen cloud credentials, exploited public-facing applications, compromised remote services, and abused trust relationships. Fire each attack against your lab. Watch the telemetry. Write the rules that catch them.
Show 11 lessonsHide lessons
- 2.1PT2.1 Phishing: Spearphishing Link (T1566.002)
- 2.2PT2.2 Phishing: Spearphishing Attachment (T1566.001)
- 2.3PT2.3 Valid Accounts: Cloud Accounts (T1078.004)
- 2.4PT2.4 Exploit Public-Facing Application (T1190)
- 2.5PT2.5 External Remote Services (T1133)
- 2.6PT2.6 Trusted Relationship (T1199)
- 2.7PT2.7 Drive-by Compromise (T1189)
- 2.8PT2.8 Phishing via Service (T1566.003)
- 2.9PT2.9 Module Deliverable. Initial Access Coverage Report
- 2.10Module Summary
- 2.11Check My Knowledge
Walk ten execution techniques end-to-end across Windows, Linux, Active Directory, and Microsoft 365. PowerShell, cmd, Bash, VBA macros, Python, JavaScript, WMI, scheduled tasks, user execution, and COM object abuse. Fire each technique in your lab, observe the telemetry, write the Sigma rules that catch them, and tune for production.
Show 13 lessonsHide lessons
- 3.1PT3.1 Command and Scripting Interpreter: PowerShell (T1059.001)
- 3.2PT3.2 Command and Scripting Interpreter: Windows Command Shell (T1059.003)
- 3.3PT3.3 Command and Scripting Interpreter: Unix Shell (T1059.004)
- 3.4PT3.4 Command and Scripting Interpreter: Visual Basic (T1059.005)
- 3.5PT3.5 Command and Scripting Interpreter: Python (T1059.006)
- 3.6PT3.6 Command and Scripting Interpreter: JavaScript (T1059.007)
- 3.7PT3.7 Windows Management Instrumentation (T1047)
- 3.8PT3.8 Scheduled Task/Job: Scheduled Task (T1053.005)
- 3.9PT3.9 User Execution: Malicious File (T1204.002)
- 3.10PT3.10 Inter-Process Communication: Component Object Model (T1559.001)
- 3.11PT3.11 Module Deliverable. Execution Coverage Report
- 3.12Module Summary
- 3.13Check My Knowledge
Walk twelve persistence techniques end-to-end across Windows, Linux, Active Directory, and Microsoft 365. Registry run keys, scheduled tasks, WMI subscriptions, SSH keys, service creation, device registration, cloud credentials, DLL hijacking, and more. Fire each technique, observe it survive a reboot, write the rules that catch the implant before it fires again.
Show 15 lessonsHide lessons
- 4.1PT4.1 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (T1547.001)
- 4.2PT4.2 Scheduled Task/Job: Scheduled Task. Persistence Focus (T1053.005)
- 4.3PT4.3 Event Triggered Execution: WMI Event Subscription (T1546.003)
- 4.4PT4.4 Account Manipulation: Device Registration (T1098.005)
- 4.5PT4.5 Account Manipulation: SSH Authorized Keys (T1098.004)
- 4.6PT4.6 Create Account: Local Account (T1136.001)
- 4.7PT4.7 Create or Modify System Process: Windows Service (T1543.003)
- 4.8PT4.8 Event Triggered Execution: Change Default File Association (T1546.001)
- 4.9PT4.9 Account Manipulation: Additional Cloud Credentials (T1098.001)
- 4.10PT4.10 Event Triggered Execution: Unix Shell Configuration Modification (T1546.004)
- 4.11PT4.11 Hijack Execution Flow: DLL Search Order Hijacking (T1574.001)
- 4.12PT4.12 Office Application Startup: Office Template Macros (T1137.001)
- 4.13PT4.13 Module Deliverable. Persistence Coverage Report
- 4.14Module Summary
- 4.15Check My Knowledge
Walk twelve privilege escalation techniques end-to-end across Windows, Linux, Active Directory, and Microsoft 365. UAC bypass, sudo abuse, token impersonation, SUID exploitation, process injection, cloud role assignment, SID-History injection, and more. Fire each technique, observe the elevation, write the rules that catch the privilege boundary crossing.
Show 15 lessonsHide lessons
- 5.1PT5.1 Abuse Elevation Control Mechanism: Bypass User Account Control (T1548.002)
- 5.2PT5.2 Abuse Elevation Control Mechanism: Sudo and Sudo Caching (T1548.003)
- 5.3PT5.3 Access Token Manipulation: Token Impersonation/Theft (T1134.001)
- 5.4PT5.4 Abuse Elevation Control Mechanism: Setuid and Setgid (T1548.001)
- 5.5PT5.5 Valid Accounts: Domain Accounts (T1078.002)
- 5.6PT5.6 Process Injection: DLL Injection (T1055.001)
- 5.7PT5.7 Account Manipulation: Additional Cloud Roles (T1098.003)
- 5.8PT5.8 Access Token Manipulation: Parent PID Spoofing (T1134.004)
- 5.9PT5.9 Process Injection: Thread Execution Hijacking (T1055.003)
- 5.10PT5.10 Hijack Execution Flow: DLL Side-Loading (T1574.002)
- 5.11PT5.11 Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access (T1548.005)
- 5.12PT5.12 Access Token Manipulation: SID-History Injection (T1134.005)
- 5.13PT5.13 Module Deliverable. Privilege Escalation Coverage Report
- 5.14Module Summary
- 5.15Check My Knowledge
Walk ten defense evasion techniques that exist to defeat the detection rules you built in Modules 2–5. Disable security tools, clear event logs, obfuscate commands, abuse trusted binaries, patch telemetry at the source, masquerade processes, hide artifacts, delete evidence, modify firewalls, and pass hashes. For each technique, discover which of your existing rules break, understand why they break, and rebuild detection that survives the evasion.
Show 13 lessonsHide lessons
- 6.1PT6.1 Impair Defenses: Disable or Modify Tools (T1562.001)
- 6.2PT6.2 Indicator Removal: Clear Windows Event Logs (T1070.001)
- 6.3PT6.3 Obfuscated Files or Information: Command Obfuscation (T1027.010)
- 6.4PT6.4 System Binary Proxy Execution: Rundll32 (T1218.011)
- 6.5PT6.5 Impair Defenses: Disable Windows Event Logging (T1562.002)
- 6.6PT6.6 Masquerading: Match Legitimate Name or Location (T1036.005)
- 6.7PT6.7 Hide Artifacts: Hidden Files and Directories (T1564.001)
- 6.8PT6.8 Indicator Removal: File Deletion (T1070.004)
- 6.9PT6.9 Impair Defenses: Disable or Modify System Firewall (T1562.004)
- 6.10PT6.10 Use Alternate Authentication Material: Pass the Hash (T1550.002)
- 6.11PT6.11 Module Deliverable. Defense Evasion Coverage Report
- 6.12Module Summary
- 6.13Check My Knowledge
Walk twelve credential access techniques that harvest passwords, hashes, tokens, and session cookies from Windows, Active Directory, Microsoft 365, and Linux. For each technique, understand what credential material the attacker obtains, why that material gives them access beyond the current endpoint, and how to detect the harvesting before the credentials are used.
Show 15 lessonsHide lessons
- 7.1PT7.1 OS Credential Dumping: LSASS Memory (T1003.001)
- 7.2PT7.2 OS Credential Dumping: NTDS.dit (T1003.003)
- 7.3PT7.3 OS Credential Dumping: DCSync (T1003.006)
- 7.4PT7.4 Steal or Forge Kerberos Tickets: Kerberoasting (T1558.003)
- 7.5PT7.5 Steal Web Session Cookie (T1539)
- 7.6PT7.6 Credentials from Password Stores: Web Browsers (T1555.003)
- 7.7PT7.7 Unsecured Credentials: Credentials in Files (T1552.001)
- 7.8PT7.8 Brute Force: Password Spraying (T1110.003)
- 7.9PT7.9 Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning (T1557.001)
- 7.10PT7.10 OS Credential Dumping: /etc/shadow (T1003.008)
- 7.11PT7.11 Steal Application Access Token (T1528)
- 7.12PT7.12 Modify Authentication Process: Multi-Factor Authentication (T1556.006)
- 7.13PT7.13 Module Deliverable. Credential Access Coverage Report
- 7.14Module Summary
- 7.15Check My Knowledge
Walk five discovery techniques that enumerate accounts, systems, groups, cloud services, and files across Windows, Active Directory, Microsoft 365, and Linux. For each technique, understand what question the attacker is answering, why the answer enables lateral movement, and how to detect the enumeration before the attacker acts on it.
Show 15 lessonsHide lessons
- 8.1PT8.1 Account Discovery: Local and Domain Accounts (T1087.001/.002)
- 8.2PT8.2 Remote System Discovery (T1018)
- 8.3PT8.3 Permission Groups Discovery: Local and Domain Groups (T1069.001/.002)
- 8.4PT8.4 Cloud Service Discovery (T1526)
- 8.5PT8.5 File and Directory Discovery (T1083)
- 8.6PT8.6 Domain Trust Discovery (T1482)
- 8.7PT8.7 System Network Configuration Discovery (T1016)
- 8.8PT8.8 System Network Connections Discovery (T1049)
- 8.9PT8.9 System Owner/User Discovery (T1033)
- 8.10PT8.10 System Information Discovery (T1082)
- 8.11PT8.11 Network Share Discovery (T1135)
- 8.12PT8.12 Cloud Infrastructure Discovery (T1580)
- 8.13PT8.13 Module Deliverable. Discovery Coverage Report
- 8.14Module Summary
- 8.15Check My Knowledge
Walk twelve lateral movement techniques that move attackers across Windows, Active Directory, Microsoft 365, and Linux using legitimate protocols. For each technique, understand why the attacker chose this movement method, what telemetry distinguishes it from legitimate administration, and how to detect the lateral step before the attacker reaches their target.
Show 15 lessonsHide lessons
- 9.1PT9.1 Remote Services: Remote Desktop Protocol (T1021.001)
- 9.2PT9.2 Remote Services: SMB/Windows Admin Shares (T1021.002)
- 9.3PT9.3 Remote Services: Windows Remote Management (T1021.006)
- 9.4PT9.4 Remote Services: Distributed Component Object Model (T1021.003)
- 9.5PT9.5 Remote Services: SSH (T1021.004)
- 9.6PT9.6 Use Alternate Authentication Material: Pass the Hash (T1550.002)
- 9.7PT9.7 Use Alternate Authentication Material: Pass the Ticket (T1550.003)
- 9.8PT9.8 Internal Spearphishing (T1534)
- 9.9PT9.9 Remote Service Session Hijacking: RDP Hijacking (T1563.002)
- 9.10PT9.10 Lateral Tool Transfer (T1570)
- 9.11PT9.11 Software Deployment Tools (T1072)
- 9.12PT9.12 Taint Shared Content (T1080)
- 9.13PT9.13 Module Deliverable. Lateral Movement Coverage Report
- 9.14Module Summary
- 9.15Check My Knowledge
Walk twelve collection techniques that gather email, files, credentials, screen content, and cloud data across Windows, Microsoft 365, and Linux. For each technique, understand what the attacker is targeting, how they stage it for exfiltration, and how to detect the harvesting before the data leaves your network.
Show 15 lessonsHide lessons
- 10.1PT10.1 Archive Collected Data: Archive via Utility (T1560.001)
- 10.2PT10.2 Email Collection: Local Email Collection (T1114.001)
- 10.3PT10.3 Email Collection: Remote Email Collection (T1114.002)
- 10.4PT10.4 Automated Collection (T1119)
- 10.5PT10.5 Data from Information Repositories: SharePoint (T1213.003)
- 10.6PT10.6 Data from Local System (T1005)
- 10.7PT10.7 Data Staged: Local Data Staging (T1074.001)
- 10.8PT10.8 Screen Capture (T1113)
- 10.9PT10.9 Video Capture (T1125)
- 10.10PT10.10 Input Capture: Keylogging (T1056.001)
- 10.11PT10.11 Data from Cloud Storage Object (T1530)
- 10.12PT10.12 Data from Network Shared Drive (T1039)
- 10.13PT10.13 Module Deliverable. Collection Detection Program Template
- 10.14Module Summary
- 10.15Check My Knowledge
Detect and analyze twelve C2 communication techniques across HTTP/S, DNS, tunneling, proxy, encoding, and protocol impersonation channels. Build detection at the network layer using beacon analysis, certificate fingerprinting, protocol compliance, and entropy measurement.
Show 15 lessonsHide lessons
- 11.1PT11.1 Application Layer Protocol: Web Protocols (T1071.001)
- 11.2PT11.2 Application Layer Protocol: DNS (T1071.004)
- 11.3PT11.3 Protocol Tunneling (T1572)
- 11.4PT11.4 Encrypted Channel: Asymmetric Cryptography (T1573.002)
- 11.5PT11.5 Application Layer Protocol: Mail Protocols (T1071.003)
- 11.6PT11.6 Web Service (T1102)
- 11.7PT11.7 Dynamic Resolution: Domain Generation Algorithms (T1568.002)
- 11.8PT11.8 Proxy: Internal Proxy (T1090.001)
- 11.9PT11.9 Proxy: External Proxy (T1090.002)
- 11.10PT11.10 Non-Application Layer Protocol (T1095)
- 11.11PT11.11 Data Encoding: Standard Encoding (T1132.001)
- 11.12PT11.12 Data Obfuscation: Protocol Impersonation (T1001.003)
- 11.13PT11.13 Module Deliverable. C2 Detection Matrix
- 11.14Module Summary
- 11.15Check My Knowledge
Validate detection coverage across twelve exfiltration techniques, from C2-channel piggyback and cloud storage abuse to DNS tunneling, webhook endpoints, USB media, and automated pipelines. Build volume-based, destination-based, and behavioral detection across network, cloud, and endpoint layers.
Show 15 lessonsHide lessons
- 12.1PT12.1 Exfiltration Over C2 Channel (T1041)
- 12.2PT12.2 Exfiltration to Cloud Storage (T1567.002)
- 12.3PT12.3 Exfiltration Over Unencrypted Non-C2 Protocol (T1048.003)
- 12.4PT12.4 Exfiltration Over Encrypted Non-C2 Protocol (T1048.001)
- 12.5PT12.5 Exfiltration to Code Repository (T1567.001)
- 12.6PT12.6 Transfer Data to Cloud Account (T1537)
- 12.7PT12.7 DNS Exfiltration (T1048.002)
- 12.8PT12.8 Data Transfer Size Limits (T1030)
- 12.9PT12.9 Scheduled Transfer (T1029)
- 12.10PT12.10 Exfiltration Over Webhook (T1567.004)
- 12.11PT12.11 Automated Exfiltration (T1020)
- 12.12PT12.12 Exfiltration Over Physical Medium: USB (T1052.001)
- 12.13PT12.13 Module Deliverable. Exfiltration Detection Coverage Map
- 12.14Module Summary
- 12.15Check My Knowledge
Detect and contain twelve impact techniques, from ransomware encryption and wiper attacks to recovery inhibition, account lockout, data manipulation, and resource hijacking. Build detection that catches irreversible damage in progress and races to limit blast radius.
Show 15 lessonsHide lessons
- 13.1PT13.1 Data Encrypted for Impact (T1486)
- 13.2PT13.2 Inhibit System Recovery (T1490)
- 13.3PT13.3 Service Stop (T1489)
- 13.4PT13.4 Account Access Removal (T1531)
- 13.5PT13.5 Data Destruction (T1485)
- 13.6PT13.6 External Defacement (T1491.002)
- 13.7PT13.7 Disk Wipe: Disk Structure Wipe (T1561.002)
- 13.8PT13.8 System Shutdown/Reboot (T1529)
- 13.9PT13.9 Resource Hijacking (T1496)
- 13.10PT13.10 Data Manipulation: Stored Data (T1565.001)
- 13.11PT13.11 Network Denial of Service: Direct Network Flood (T1498.001)
- 13.12PT13.12 Firmware Corruption (T1495)
- 13.13PT13.13 Module Deliverable. Impact Detection and Containment Matrix
- 13.14Module Summary
- 13.15Check My Knowledge
Phase 3: Capstone
Execute the complete CHAIN-HARVEST AiTM attack chain across all four environments and three SIEMs. Assess detection coverage, identify gaps, build the remediation plan, and produce a portfolio-grade purple-team report.
Show 15 lessonsHide lessons
- 14.1PT14.1 CHAIN-HARVEST Scenario Briefing (INC-2026-0227)
- 14.2PT14.2 Phase 1: Initial Access and Execution (T1566.002 → T1059.001)
- 14.3PT14.3 Phase 2: Persistence and Privilege Escalation (T1098.005 → T1548.002)
- 14.4PT14.4 Phase 3: Defense Evasion and Credential Access (T1562.001 → T1003.001)
- 14.5PT14.5 Phase 4: Discovery and Lateral Movement (T1087.002 → T1021.002)
- 14.6PT14.6 Phase 5: Collection and Exfiltration (T1560.001 → T1567.002)
- 14.7PT14.7 Phase 6: Impact. Recovery Inhibition and Ransomware (T1490 → T1486)
- 14.8PT14.8 Detection Coverage Assessment
- 14.9PT14.9 Gap Analysis and Remediation Planning
- 14.10PT14.10 Building the Purple-Team Program
- 14.11PT14.11 Writing the Purple-Team Report
- 14.12PT14.12 Full-Chain Exercise. CHAIN-HARVEST End-to-End
- 14.13PT14.13 Module Deliverable. CHAIN-HARVEST Purple-Team Report
- 14.14Module Summary
- 14.15Check My Knowledge
Phase 0: Course Resources
The lookup layer: every emulation command and validation query the course teaches, grouped by the question you are asking at the moment you open the page.
Show 11 lessonsHide lessons
- 1Telemetry Preflight
- 2Initial Access and Execution
- 3Persistence and Privilege Escalation
- 4Defense Evasion and Credential Access
- 5Discovery and Lateral Movement
- 6Collection, Command and Control, and Exfiltration
- 7Impact
- 8Did the Detection Fire
- 9Why the Rule Stayed Silent
- 10Coverage Arithmetic
- 11Cleanup
Procedures: what you do, in what order, what each step must produce, and where it branches. The exercise lifecycle from authorization through to the reported coverage figure.
Show 7 lessonsHide lessons
The build-and-verify reference for the emulation lab: what the environment has to produce, the settings that are off by default and decide every later result, the activity generation that gives you something to detect, and the verification that fails loudly.
Exercises worked end to end, including the wrong turns: the technique run, the rule that did or did not fire, the diagnosis, the rule change, and the re-test that settled it.
Emulation procedures opened at the moment you are about to run a technique family: prerequisites, pre-flight, time budget, the execution sequence, the validation, and the tiered disposition of the result.
Where to practice purple teaming beyond the course: the detection library, the Splunk Lab, the SOC Simulator and the open-source emulation frameworks, with an honest note on which of them is written for this course and which is not.
The emulation commands, detection rules and telemetry indicators from every module in one place, indexed by ATT&CK tactic. The working kit you carry into your next exercise.
Show 1 lessonHide lessons
Where to check whether anything in this course has changed: the ATT&CK releases the technique set tracks, the emulation framework documentation, the Sigma rule sources, and the detection community work cited throughout the course.
Course Completion
You've reached the end of Purple Teaming for Blue Teams. This closing module looks back at what you built across the course, how it changed the way you read a coverage figure, and where to take the work next.
Show 1 lessonHide lessons
Course overview
The Purple Teaming for Blue Teams course is built specifically for Blue Team Cybersecurity professionals who want to validate detection coverage across Microsoft and open-source SIEMs. You'll gain hands-on expertise to:
By the end, you'll have the practical skills and methodology to run ongoing purple team programs that measurably improve your organization's detection and response effectiveness.
How this course works
The course argument is that a detection nobody has fired is an untested assumption. Every technique across the ATT&CK tactics runs the same five-step cycle in a lab you build.
1. Simulate. Execute the technique yourself so you know exactly what happened and when. Reading about it tells you the outcome, not the footprint.
2. Investigate. Follow it through the telemetry it produced, and find which sources saw it and which were blind. The blind ones are the finding.
3. Detect. Write the rule against the durable artifact the technique leaves, not against the tool that created it this time.
4. Tune. Measure the alert volume, exclude the legitimate activity, and accept that every exclusion is a new blind spot you now own.
5. Validate. Re-run the technique to prove the rule fires. Then ask how you would bypass your own rule, and close that gap before somebody else finds it.
The capstone chains it: a full intrusion emulated end to end, then reported as a coverage figure with a stated denominator and a remediation plan somebody could fund.
What this course assumes
No minimum experience and no prerequisite course, and no offensive background assumed. The lab is built from nothing across four environments and three SIEMs.
What makes it go faster: a machine with enough memory to run several virtual machines, and comfort at a command line. The lab build is taught in full, including the telemetry settings that are off by default and decide every result after them.
What this course does not cover: penetration testing as a profession, exploit development and red team tradecraft. Attack technique here exists to test a detection.
Who this course is for
You're a Blue Team Cybersecurity professional (Detection Engineer, SOC Analyst, Threat Hunter, or Security Engineer) who wants to validate and strengthen your actual detection coverage. This course is built for you if you want to:
In short: if you're a blue teamer who wants to validate that your detections actually catch real attacks, this course is for you.
What you'll learn
By the end of this Purple Teaming for Blue Teams course you will be able to:
Key course takeaways
Things you need to know
What are the prerequisites for this course?
There are no prerequisites. The course teaches purple teaming methodology from first principles. Familiarity with detection engineering, KQL, and MITRE ATT&CK will help you move faster, but neither is required. Every technique and tool is explained at first use.
What are the device requirements?
A device with a modern browser. For hands-on exercises, a lab environment with a Windows VM, a Linux VM, and access to a Microsoft 365 E5 developer tenant with Sentinel. The course walks you through setup and provides Atomic Red Team and Caldera installation guides.
How will the course benefit your career?
Purple teaming is how mature security teams prove their detections work. Organizations need people who can execute ATT&CK techniques safely, validate detection coverage, close gaps, and report the results. This course gives you the methodology, the tool proficiency, and the program framework to lead that capability.
Purple team skills are increasingly a requirement for senior detection engineering, security architecture, and SOC leadership roles.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may deploy Sigma rules, KQL detections, and coverage frameworks in your production environment. You may not redistribute course content or share account credentials.
Attack techniques: All technique execution is in your own isolated lab. Do not execute techniques against systems you do not own or have explicit written authorization to test.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then prove your skills under time pressure. Pass mark: 70. Earn your certificate with CPE credits.
One random scenario per attempt. Certificate issued on pass.