# Purple team

> Running the attack and the defence as one exercise, so every fix is verified against the technique that found the hole.

The traditional split hands a red team's report to a blue team weeks later, and the feedback loop that should exist never closes: the attacker never learns which of their techniques the defences would now catch, and the defender never learns whether the fix works against the real thing or only against the description of it.

Purple team collapses that. The same engagement finds the weakness, applies the fix and re-runs the original attack, which means the deliverable is a verified control rather than a recommendation. It also produces a shorter report, because a finding that was fixed and re-tested takes one line instead of a page of caveats.

It is a working arrangement rather than a third team. The word describes red and blue operating together, and on a small engagement it can be one person doing both halves — which is the version that removes the handover entirely.

## Related terms

- https://dfieldsolutions.com/en/glossary/penetration-test.md
- https://dfieldsolutions.com/en/glossary/red-team.md
- https://dfieldsolutions.com/en/glossary/blue-team.md
- https://dfieldsolutions.com/en/glossary/security-audit.md

---

Source: https://dfieldsolutions.com/en/glossary/purple-team
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
