Red team, blue team and purple team: what is the difference?
In cybersecurity, colours tell attackers from defenders. The red team simulates attackers, the blue team defends, and the purple team is the two working together. These are roles, not necessarily different people: understanding all three is the fastest way to become good at any one of them.
Red team: attacking in order to improve
The red team imitates the behaviour of a real adversary, with written authorisation, to find out whether an organisation's defences actually hold. It looks for vulnerabilities, uses social engineering, tries to move through the network without being noticed and documents everything it managed to do. Its product is not the intrusion but the report that lets the weak points be fixed.
Blue team: defend, detect, respond
The blue team protects the systems every day. It configures and updates defences (hardening, firewalls, authentication), monitors logs and alerts, investigates suspicious events and coordinates incident response. A strong blue team does not try to stop every attack, which is impossible, but to notice them quickly and limit the effect.
Purple team: collaboration
The purple team is not a separate group but a method: red and blue work together and share what they learn straight away instead of surprising each other at the end of an exercise. The attackers explain how they did it, the defenders say what they saw and what they missed, and together they improve defences and alerts.
| Red team | Blue team | Purple team | |
|---|---|---|---|
| Goal | find weaknesses by simulating an attack | prevent, detect and respond | make the two teams learn from each other |
| Typical activities | reconnaissance, simulated phishing, controlled exploitation | hardening, monitoring, log analysis, incident handling | joint exercises, writing detection rules |
| Output | a report of the gaps found | sturdier systems and better alerts | verified defences and an improvement loop |
A worked example of a purple exercise
- The two teams choose a technique to test together, for example repeated sign-in attempts with wrong passwords against a test service.
- The red team runs it in a controlled environment and announces the start time.
- The blue team checks whether alerts fired and whether the logs show the attempts. Suppose nothing fired.
- Together they write a detection rule (for example: more than five failed logins in a minute from one address) and deploy it.
- The red team repeats the test: now the alert fires. The technique moves to the "covered" list and the next one is picked.
How to defend: what you can do without a dedicated team
- Learn both sides. Defenders need to know attack techniques; attackers need to understand how an intrusion is detected.
- Practise in safe environments: labs, CTFs and cyber ranges let you try things without risk to real systems. Start with the guide to CTFs.
- Document and share: every exercise must end with a concrete change (a rule, a patch, a procedure).
- Never without permission: tests on real systems always need a written agreement defining what is allowed.
Why the game is called PurpleDuel
The name joins exactly those two halves: in the labs you learn how attackers think and, with the final write-up, how to defend; in the card duels every attack has its countermeasure; in the PvP Arena you set up a server to defend and attack others. Playing both roles is, in miniature, the job of a purple team.