
DEF CON 33 - Redefining Purple Teaming for Max impact - A Pennington, S Marrone, L Proehl
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 40:51
Purple teaming enhances security through collaboration between red and blue teams, breaking down silos and improving detection and response by simulating real-world adversary behavior. 2:44
Key Takeaways:
• Purple teaming fosters transparency and mutual learning, with both teams planning and executing together, leading to better detection and response skills 3:00.
• Adversary emulation should start small, using threat intelligence or industry-specific threats, and grow from there to ensure realism and relevance 10:24.
• Success is measured by tangible outcomes—such as new detections, documentation, and MITRE ATT&CK coverage—rather than raw counts of exercises 18:45.
• Effective storytelling and executive reporting are essential to justify investments, especially when demonstrating gaps in logging or detection 23:10.
Organizations should begin with foundational security practices before advancing to purple teaming, and smaller teams may benefit from vendor-led services to build capability 29:04.
Sources:
- 2:44 Discussion on the value of collaboration in purple teaming.
- 3:00 Emphasis on shared planning and learning between red and blue teams.
- 10:24 Guidance on selecting realistic adversaries using threat intel.
- 18:45 Metrics for success including new detections and MITRE coverage.
- 23:10 Importance of narrative reporting to executive leadershi
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Um, so I I think we're we're here to self-introduce. So I'm just going to kick off. Um, and so yeah, hopefully you're here for the right panel. This we're going to be talking a bit about purple teaming adversary emulation. Since the creator stage, we're associated with one of the villages and this is coming to you. >> Yeah, I think you want me more for the streaming. Gotcha. Excellent. So um here uh associated with the adversary village and so kick it off. Um program says we have uh four panelists. We're not quite sure why we only have three but we're going to go with it. Uh so I want to start off with just a round of introductions on who else up here on stage. So I start with you Sydney. >> Yeah. So my name is Sydney Moroni. I'm a principal threat hunter at Splunk right now. I've been in …