Kiber təhlükəsizlik · 10 min read
What is the difference between Red Team, Blue Team and Purple Team?
The difference between Red Team and Blue Team in one sentence: one team attacks with permission, the other detects that attack and builds the defense. The offensive team (Red Team) acts like a real attacker on the basis of written authorization and exploits vulnerabilities. The defensive team (Blue Team) monitors logs, writes detection rules and responds to incidents. Purple Team is not a separate team — it is a format of joint work between offense and defense: the offensive team executes a technique, and the defensive team learns to detect it.
- The offensive team finds and proves a vulnerability, the defensive team sees and stops the attack — the goal is the same, the viewpoint is different.
- Purple Team is not a staffing unit but a measurable exercise format: it answers the question «were we able to detect this technique?».
- MITRE ATT&CK is the common language for both sides — an attack technique and a detection rule are named with the same code.
- For a beginner, the barrier to entry into the defensive team is lower; the offensive team requires an intermediate-level technical foundation.
- In Azerbaijan, unauthorized access carries criminal liability — all training is conducted in a closed lab environment.
What is Red Team and what does its daily work consist of?
The offensive team (Red Team) is a group that tests an organization's defenses with the logic of a real attacker. The work is carried out only on the basis of written consent and a contract, within a previously agreed scope. The goal is not to destroy the system but to demonstrate with evidence how far an attack can progress.
Daily work often differs from the picture in the movies. Most of the time goes to reconnaissance, confirming vulnerabilities and documentation.
- Reconnaissance (recon): domain, subdomains, open ports, employee email structure, technology stack.
- Testing web and API vulnerabilities: access control, injection-type vulnerabilities, authentication logic.
- Exploiting server-side and system vulnerabilities, building a chain leading to remote code execution.
- Active Directory attacks: Kerberoasting, AS-REP roasting, credential theft, Pass-the-Hash.
- Lateral movement inside the network and the post-exploitation phase: stealthy movement through the network, privilege escalation, managing C2 (command and control) infrastructure.
- Reporting: the impact of the finding, risk level, reproduction steps and remediation recommendation.
The final product of the work is not an exploitation guide but a penetration testing report. The report gives the technical team a remediation plan and gives management a picture of the risk. Without a good report, a discovered vulnerability creates no value for the organization.
What is Blue Team and how is defense built?
The defensive team (Blue Team) works to see an attack in time and stop it. This work is mainly concentrated in the security operations center (SOC). The foundation of defense lies not in a tool but in a high-quality collection of logs.
- Collecting and normalizing logs: Windows event logs, Linux system logs, network and application logs.
- Setting up a SIEM (security information and event management): connecting sources, retention period, search and correlation logic.
- Writing detection rules and mapping them to MITRE ATT&CK techniques.
- Reducing false positives — when there is a lot of noise, a real event gets lost.
- Incident response: preparation, detection, containment, eradication, recovery and lessons learned.
- Threat hunting: searching for traces in the logs based on a hypothesis, without waiting for a ready-made signal.
NIST SP 800-61 describes incident response as a phased process. In practice this means the success of the defensive team is not measured by the number of signals alone. The key indicator is how quickly an incident is noticed and how quickly it is closed.
What is Purple Team — a third team or a working format?
Purple Team is sometimes presented as a third staffing unit, although it is in fact an operating format. The offensive and defensive teams sit at the same table, observe the same technique from two sides and measure the result. This way the question is posed not as «who won» but as «which technique was detected».
- A target technique is selected — for example, Kerberoasting or Pass-the-Hash, cataloged in MITRE ATT&CK.
- The offensive team executes the technique in a closed lab and records the execution time precisely.
- The defensive team checks which log entries were generated in that time window.
- If there is no signal, a detection rule is written or an existing rule is refined.
- The technique is executed again: does the rule work, does it produce false positives?
- The result is documented — which techniques are detected, which are not, and what the gap-closing plan is.
Why does a common language matter?
When the offensive team says «we stole an account» and the defensive team says «we saw a strange login», the conversation goes nowhere. MITRE ATT&CK gives every technique a name and a code — so an attack step and a detection rule come together in the same catalog, and the gap becomes measurable.
What are the main differences between Red Team, Blue Team and Purple Team?
| Criterion | Red Team | Blue Team | Purple Team |
|---|---|---|---|
| Main goal | To prove a vulnerability through an authorized attack simulation | To detect an attack, stop it and recover | To measure and improve detection capability |
| Typical task | Reconnaissance, exploitation, lateral movement inside the network, post-exploitation | Log analysis, detection rules, incident response, threat hunting | Executing a technique + checking detection at the same time |
| Example tools | Burp Suite, Nmap, sqlmap, BloodHound, Mimikatz, Havoc, Sliver | SIEM, log sources, detection rules, incident logging system | Caldera, Atomic Red Team + SIEM rules |
| Success criterion | An impactful finding and a clear penetration testing report | A reduction in the time spent on detection and response | An increase in the share of detected ATT&CK techniques |
| Who receives the report | The client organization, security leadership | The SOC lead, IT and security leadership | Both sides — a shared results document |
| Entry level | Intermediate: networking, Linux, Windows/AD foundation required | A transition from beginner to intermediate level is possible | For those with experience on both sides |
| Work rhythm | Project format, time-limited operations | Continuous, often shift-based work | Planned exercise cycles |
The main point visible from the table is this: the three roles are not rivals but three stages of the same process. The offensive team finds the gap, the defensive team makes it visible, and the Purple Team format links these two results together.
What tools do they work with?
A list of tools does not define a role, but it shows the nature of daily work well. The breakdown below follows the module logic of offensive team training.
- Web application phase: Burp Suite, Nmap, ffuf, sqlmap — finding and confirming vulnerabilities.
- Server and system phase: ysoserial, commix — exploiting server-side vulnerabilities.
- API and mobile phase: MobSF, Frida, jadx, Postman — application analysis and authentication testing.
- Active Directory phase: BloodHound, Mimikatz, CrackMapExec, Rubeus — domain attacks.
- Lateral movement inside the network and post-exploitation phase: Havoc, Sliver, Evil-WinRM, Empire — C2 infrastructure and stealthy movement.
- Operations and reporting: Caldera, Atomic Red Team, CherryTree — scenario execution and documentation.
| Tool group | Red Team goal | Purple Team / Blue Team goal |
|---|---|---|
| BloodHound | Find the shortest privilege escalation path inside the domain | Clean up risky relationships, put critical accounts under monitoring |
| Mimikatz / Rubeus | Credential theft and ticket attacks | See which event codes are generated and write a detection rule |
| Atomic Red Team | Quick execution of individual ATT&CK techniques | Check whether the signal works for each technique |
| Caldera | An automated attack chain with a full scenario | Measure detection coverage and produce a gap map |
Which role suits you: how can you check yourself?
It is better to make the choice based on working style rather than salary expectations. Answer the following questions honestly.
- Are you more drawn to looking for a way to break a system, or to restoring and hardening it?
- Can you stay calm under shift work and a constant flow of signals? This is normal on the defensive side.
- Do you have the patience to write long, structured reports? Half of the offensive team's work is documents.
- Are you familiar with networking basics, the Linux command line and Windows/Active Directory logic?
- Does repetitive analysis wear you out, or do you find it interesting to track down a trace in the details?
- Do you like communicating with a team on an ongoing basis? The Purple Team format is built precisely on this.
If most of your answers lean toward «find and prove», the offensive team direction suits you. If the answers «see, restore, systematize» prevail, the defensive team is a more natural start. As experience grows, moving between the two sides is common.
Which sequence makes more sense when starting from scratch?
- Build the foundation: network protocols, Linux administration, Windows and Active Directory basics.
- Choose a direction: on the defensive side, logs, SIEM and detection logic; on the offensive side, web, system and Active Directory attacks.
- Practice in a closed lab — theory alone teaches you neither to write a report nor a detection rule.
- Develop the habit of writing reports: the finding, impact, evidence, recommendation structure works on both sides.
- Join Purple Team exercises: check what trace the technique you executed leaves in the log.
- Draw up your own skills map based on MITRE ATT&CK and put the gaps into a plan.
| Program | Duration | Level | Format |
|---|---|---|---|
| Linux Administrator | 4 months | Beginner | Offline / online |
| Blue Team | 6 months | Beginner → intermediate | Offline / online |
| Red Team | 6 months | Intermediate, 18+ | Offline / online |
| DevSecOps | 6 months | Intermediate | Offline / online |
Groups have 8–12 people, and a new group starts every month. The small-group format allows individual tracking on lab assignments. Each program concludes with a Log Academy certificate and preparation for international certifications.
Is Red Team work legal in Azerbaijan?
Yes, but on one condition only: there must be written authorization and a contract. Penetration testing is carried out on the basis of a document with a scope, time window and rules agreed with the client. Without this document, the same actions count as unauthorized access to a computer system.
- The Criminal Code of the Republic of Azerbaijan defines unauthorized access to computer systems and unlawful interference with data as a crime.
- The explanation «I did it for testing purposes» is not considered legal protection without written consent.
- Going beyond the scope — a domain, system or third-party service that was not authorized — creates a separate risk.
- Information about a discovered vulnerability is given only to the client and is not shared publicly.
- In training, all tasks are carried out in a closed lab environment, on an isolated network.
Our editorial principle comes from here as well: the content provides no working exploitation instructions. The explanation is built around concepts, defense and careers. The goal is not to answer «how is hacking done» but the question of how to become a professional in this field.
How do the offensive and defensive sides meet in our lab?
How we do it in our lab
Here is how we do it in our lab: in module M04 of the Red Team program, a real Active Directory lab environment is built and the Kerberoasting, AS-REP roasting and Pass-the-Hash scenarios are executed. BloodHound is used to map domain relationships, and Rubeus and CrackMapExec are used to show how account credentials are obtained. Then we open up together what trace the same event leaves in the log: which entry is generated, why it resembles ordinary user activity and under what condition it can be turned into a detection rule. In M05, the steps of lateral movement inside the network and the post-exploitation phase are followed with the same logic. The course ends in M06 with a full-scenario operation and a professional penetration testing report — all execution takes place in a closed lab environment.
- A working document for the module exercise is prepared: the target domain, permitted actions, time window and stop conditions.
- Participants are divided into two subgroups; each subgroup fills in its own log and note template in advance.
- After the exercise, the notes of both sides are compared face to face: which step was visible, and which left no trace at all.
- The difference between a persistent trace (disk, registry) and a transient one (memory, session) is noted separately.
- The detection rule that was written is re-tested in the next lesson, and the number of false positives is measured.
- The final document is added to the portfolio: finding, impact, evidence, recommendation — in a format you can show at a job interview.
- Is Purple Team a separate position or a working format?
- It is mainly a working format. In some large organizations a coordinator role may exist as a separate staff position, but the essence is the same: the offensive and defensive teams jointly conducting a measurable exercise on the same technique.
- Are Red Team and penetration testing (pentest) the same thing?
- No. Penetration testing is usually aimed at finding as many vulnerabilities as possible in a particular system or application. A Red Team operation, by contrast, sets out to reach a specific target covertly and to test the defense's response.
- Which is easier for a beginner, Red Team or Blue Team?
- The barrier to entry into the defensive team is usually lower, because the program is designed for the beginner-to-intermediate level. The offensive team program requires an intermediate-level technical foundation: an understanding of networking, Linux and Windows/Active Directory.
- Do you need to know programming to start in Red Team?
- Being a professional programmer is not required, but being able to read scripts makes the work considerably easier. Basic knowledge at the Bash and Python level is enough for automation, processing output and adapting ready-made tools.
- Can a Blue Team specialist later move to Red Team?
- Yes, and it is a common path. A specialist with log and detection experience already knows what trace an attack technique leaves, which gives an advantage in operational security (OPSEC) and scenario planning.
- Is Red Team work legal in Azerbaijan?
- A test carried out on the basis of written authorization and a contract is legal. Unauthorized access, however, carries liability under the Criminal Code. In the training environment, all tasks are carried out in an isolated closed lab.
- How many months does the Red Team course last and what level is required?
- The Red Team program lasts 6 months, is designed for the intermediate level and accepts participants over 18. Groups have 8–12 people, and a new group starts every month.
- What tools are used for Purple Team practice?
- Most often Atomic Red Team and Caldera: the first allows quickly executing individual MITRE ATT&CK techniques, the second allows building a chain with a full scenario. The result is compared against the detection rules in the SIEM.