DFIELDSOLUTIONS

Security

GlossaryPurple team

Running the attack and the defence as one exercise, so every fix is verified against the technique that found the hole.

The traditional split hands a red team's report to a blue team weeks later, and the feedback loop that should exist never closes: the attacker never learns which of their techniques the defences would now catch, and the defender never learns whether the fix works against the real thing or only against the description of it.

Purple team collapses that. The same engagement finds the weakness, applies the fix and re-runs the original attack, which means the deliverable is a verified control rather than a recommendation. It also produces a shorter report, because a finding that was fixed and re-tested takes one line instead of a page of caveats.

It is a working arrangement rather than a third team. The word describes red and blue operating together, and on a small engagement it can be one person doing both halves — which is the version that removes the handover entirely.

Related terms

The bench this belongs to

Cybersecurity

Purple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.

All termsStart a conversationMarkdown version

DField Bt. · Dunakeszi · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain