Program overview
In these exercises an attacking team carries out an agreed set of techniques while a defending team monitors, investigates, and responds. The red side can be your own offensive security staff or DeployOpen engineers. The blue side is usually your SOC, incident responders, or detection engineers.
All activity runs in an isolated lab or private range set up to match the parts of your environment in scope. Exercises can run with each side working separately, or as a purple team session where both sides share notes as each technique runs.
Skills covered
Adversary emulation
Planning and running a sequence of techniques from a chosen threat group or scenario, and keeping an activity log the blue team's results can be checked against.
Detection and alert tuning
Finding which techniques produce signals in your tools, which do not, and what rule or logging changes would close the gap.
Investigation and response
Tracing attacker activity across hosts and accounts, containing it, and confirming it has stopped.
Purple team collaboration
Working through techniques one at a time with both sides present, so the blue team sees the exact activity behind each signal.
Reporting
Explaining findings to the other team and to management in terms each audience can act on.
How the program runs
We agree objectives with both teams: which threats to emulate, which defenses to test, and what each side should learn. We review your detection stack, logging, and response procedures to choose relevant techniques.
We set up the lab to match the in-scope parts of your environment and write the exercise plan. It lists techniques mapped to MITRE ATT&CK, rules of engagement, stop conditions, and contacts. Both sides approve the plan before the exercise.
The red team runs the agreed techniques and logs each action with a timestamp. The blue team detects, investigates, and responds with your tools. A DeployOpen engineer acts as controller, tracks both sides, and can pause activity at any time.
Both teams compare the red team log with blue team observations, technique by technique. We record what was detected, when, and on what evidence, and agree which detection and response changes to make.
Formats
| Format | Who it suits | What it covers |
|---|---|---|
| Purple team session | Teams building or tuning detections | Techniques run one at a time with both sides present, discussing each signal as it appears |
| Red versus blue exercise | Established SOC and response teams | A full scenario where the blue team does not know the plan in advance, followed by a joint debrief |
| Tabletop walkthrough | Security leads and managers | An attack path and the expected detections and responses, discussed without hands-on systems |
| Recurring exercises | Teams tracking detection coverage over time | New or repeated techniques at an agreed interval, compared with earlier results |
Sample scenarios
Initial access to domain compromise
A phishing foothold, credential theft, lateral movement, and privilege escalation in a Windows Active Directory lab.
Ransomware operator emulation
Discovery, defense evasion, backup deletion, and staged encryption based on publicly reported ransomware group behavior.
Cloud control plane attack
Use of a leaked access key, privilege escalation through role assumption, and access to data in cloud storage.
Living off the land
Built-in system tools and scripting used for discovery and persistence, testing detections that do not depend on malware signatures.
Data exfiltration
Staging data and moving it out over common protocols, testing network monitoring and data loss controls.
Attacks on AI-enabled workflows
Prompt injection against an internal AI assistant with tool access, testing whether its actions are logged and detected.
What you receive
The debrief and written outputs connect each red team action to what the blue team saw.
Technique-level results
- Each technique mapped to MITRE ATT&CK
- Whether it was prevented, detected, logged only, or missed
- Time from action to detection where it was recorded
Detection improvements
- New or revised detection rules to write
- Log sources to add or adjust
- Related defensive techniques from MITRE D3FEND
Response findings
- Investigation or containment steps that slowed the team
- Runbook changes and missing playbooks
- Access or tooling responders lacked
Materials to rerun
- Exercise plan and red team activity log
- Lab configuration notes
- A retest list for techniques that were missed
Common questions
Who should attend?
Offensive security staff, SOC analysts, threat hunters, detection engineers, and incident responders. Security managers can join the debrief.
Do we need our own red team?
No. DeployOpen engineers can act as the red team, or work alongside your offensive security staff.
Do the exercises use our tools?
Yes. The lab is set up around your detection and response tools and the parts of your environment in scope. All activity stays inside the isolated lab or private range.
Is it remote or on-site?
Remote or on-site delivery can be agreed.
How do you measure progress?
Results are recorded per technique. Repeating the same techniques in a later exercise shows which gaps have been closed.
Is the work confidential?
Yes. We sign an NDA on request, and exercise outputs are handled as sensitive material under an agreed handling plan.
How to prepare
Tell us what you want to test: a specific threat group, a set of techniques, or recent detection changes. Share a summary of your detection stack, logging, and response procedures.
Name a sponsor who approves the exercise plan and a contact on each side. Decide whether the blue team should know the plan in advance, and arrange for participating analysts to be released from normal duties during the exercise.
MITRE ATT&CK and D3FEND
Exercise plans and results use MITRE ATT&CK technique IDs, so findings can be compared with your detection coverage and repeated in later exercises. Each exercise includes only the techniques that serve its objective.
Recommended defensive changes reference MITRE D3FEND, which describes defensive techniques and links them to the offensive techniques they counter.

