DEF CON 33 - Letthemin: Facilitating High Value Purple Teams Using Assumed Compromise - Sarah Hume

DEF CON 33 - Letthemin: Facilitating High Value Purple Teams Using Assumed Compromise - Sarah Hume

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 27:35

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Purple teaming uses an "assume compromise approach" to create high-value security evaluations by testing detection capabilities rather than vulnerabilities 0:31.

Key Takeaways:
• Purple teaming is a collaborative workshop where red and blue teams execute together in an open-book format, bringing all security departments together 4:08
• Unlike automated breach and attack simulation, purple teaming focuses on attack authenticity and shouldn't be replaced by BAS solutions 8:07
• The assume compromise approach gives testers access at multiple levels to fully simulate adversary activities, like testing DC sync attacks to evaluate underlying activities rather than specific procedures 10:11
• Purple team scoring focuses on successful outcomes without penalizing "failures," creating a blame-free environment that fosters collaboration 15:49

The goal of this approach is to flip the burden of perfection, recognizing that defenders can't prevent everything but can break the attack chain through strategic detection and prevention controls 21:01.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, it is officially noon. Longest six minutes of my life. Let's get started. Thank you so much for being here. I'm super excited to be giving this talk. I hope you're ready for 30 minutes of your life that you will never get back. My presentation today is facilitated by the Adversary Village. So, just want to say an extra special thank you to them for the opportunity. Um, I spent a lot of my time at Defcon last year at the Adversary Village and I really learned a lot and I knew I wanted to come back and contribute to that community. So, in kind, I'm going to be talking about purple teams, namely this unique approach that we call the assume compromise approach that we've found to be the most effective strategy in creating a highv value purple team engagement. First, I'm going to int…