The colour scheme of security describes roles: the red team simulates realistic attacks on the organisation, technology and people; the blue team defends — detecting, analysing and responding day to day. Purple teaming is not a third squad but a working mode: attackers and defenders collaborate openly, technique by technique.
The purpose is always the same: replace assumptions with evidence. Not whether an attack would be possible, but whether it is detected and stopped — that is the question.
How do the exercise formats differ?
A penetration test looks for as many vulnerabilities as possible within a defined scope. A red team engagement pursues one objective — such as access to a specific system — by any path, often over weeks and without warning the defenders: a test of the entire detection and response chain.
Purple teaming turns that into a learning cycle: together, a technique (from MITRE ATT&CK, say) is executed, alerts are checked, detection is sharpened — and repeated. Per exercise day this yields more measurable improvement than any blind test.
Which exercise fits when
- Penetration test: systematically find vulnerabilities of an application or environment.
- Red team: realistically test the maturity of detection and response — including people and process.
- Purple team: close detection gaps deliberately, technique by technique.
- Tabletop exercise: rehearse management decision paths for the emergency.