
DEF CON 33 - Letthemin: Facilitating High Value Purple Teams Using Assumed Compromise - Sarah Hume
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 27:35
Purple teaming uses an "assume compromise approach" to create high-value security evaluations by testing detection capabilities rather than vulnerabilities 0:31.
Key Takeaways:
• Purple teaming is a collaborative workshop where red and blue teams execute together in an open-book format, bringing all security departments together 4:08
• Unlike automated breach and attack simulation, purple teaming focuses on attack authenticity and shouldn't be replaced by BAS solutions 8:07
• The assume compromise approach gives testers access at multiple levels to fully simulate adversary activities, like testing DC sync attacks to evaluate underlying activities rather than specific procedures 10:11
• Purple team scoring focuses on successful outcomes without penalizing "failures," creating a blame-free environment that fosters collaboration 15:49
The goal of this approach is to flip the burden of perfection, recognizing that defenders can't prevent everything but can break the attack chain through strategic detection and prevention controls 21:01.
Sources:
- 0:31 Introduction to assume compromise approach for purple teams
- 4:08 Definition of purple teaming as collaborative workshop
- 8:07 Distinction between purple teaming and breach and attack simulation
- 10:11 Example of DC sync attack testing
- 15:49 Purple team scoring methodology
- 21:01(https://www.youtube.com/watch?v=xM8nodIw1_E&t=126
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right, it is officially noon. Longest six minutes of my life. Let's get started. Thank you so much for being here. I'm super excited to be giving this talk. I hope you're ready for 30 minutes of your life that you will never get back. My presentation today is facilitated by the Adversary Village. So, just want to say an extra special thank you to them for the opportunity. Um, I spent a lot of my time at Defcon last year at the Adversary Village and I really learned a lot and I knew I wanted to come back and contribute to that community. So, in kind, I'm going to be talking about purple teams, namely this unique approach that we call the assume compromise approach that we've found to be the most effective strategy in creating a highv value purple team engagement. First, I'm going to int…