Skip to content
winfunc
Purple teaming

Turn every attack into a detection.

Replay real attack chains against your logging and alerting, side by side with your defenders. Every gap becomes a detection that is proven to fire before the exercise ends.

What's included
  1. acme
  2. /Engagements
  3. /Purple team · replay
3 gaps closed
Replayed4
Alerted before1
Alerting now4
TechniqueLogAlertBlock
T1190Exploit public-facing application
T1552.005Cloud instance metadata API
T1078.004Valid cloud accounts
T1530Data from cloud storage
sigma · metadata-credentials-off-host.ymlT1552.005
title: Instance role credentials used off-host
logsource: { product: aws, service: cloudtrail }
detection:
  selection: { userIdentity.arn|contains: 'assumed-role/app-role' }
  filter: { sourceIPAddress|cidr: '10.0.0.0/8' }
  condition: selection and not filter
Purple team · detection coverageIllustrative data
The problem

Most detections are never tested against a real attack.

Rules get written from threat reports and vendor defaults, then trusted. A purple team exercise runs the techniques that actually work against your environment and records what your SIEM logged, alerted on, and blocked, one technique at a time.

Included

What winfunc covers.

  • Replays of red team chains and the ATT&CK techniques that fit your stack
  • Per-technique results: logged, alerted, blocked, or missed
  • Detection logic drafted for every gap, in the format your SIEM uses
  • Replays repeated until each new detection fires
  • Working sessions with your SOC and detection engineers
  • Coverage tracked from one exercise to the next
Outcomes

What your team walks away with.

01

Coverage you can measure

A technique-by-technique record of what your monitoring catches today, instead of a coverage estimate.

02

Rules that are proven

Every new detection is validated against the same activity that slipped through, not a synthetic test event.

03

One room, one timeline

Attackers and defenders work from the same record, so fixes to logging, alerting, and code happen together.

04

Compounding readiness

The next red team engagement starts from the updated coverage, so each round tests something new.

Start with one repository

Bring us your hardest codebase.
We'll bring the proof.

Scope a first audit with our security engineers. You get findings with traces, reproduction evidence, and patches ready for review.

Scoped with you. Delivered with evidence.

A voxel chessboard: a bone rook and a red knight, with the traced path between them lit green after the fix was verified