WEEK 09

Red / Blue / Purple

Operational scenario

Red team has a two-hour window against the range. Blue must detect, respond and map every action to ATT&CK.

Week completion
0%
~10 hours this week
Assessment: Knowledge check 8; detection rubric
Deliverable: ATT&CK-mapped detection report
Learning objectives
  • Detect & respond
  • Map activity to MITRE ATT&CK
  • Collaborate as a purple team
Classroom topics
  • Red objectives & limits
  • Blue detection & response
  • Purple collaboration
  • Threat hunting
  • Detection engineering
  • Deconfliction
Standards · vocabulary
MITRE ATT&CK (Enterprise & ICS)NIST SP 800-61r3
SOCSOARMTTDMTTRIOC
Open glossary
Competency demonstrated: Detects, responds and maps to ATT&CK.

Four-mode learning matrix

~1.5 h
Physical hands-on lab

Stand up log forwarding from a device to a collector.

~2 h
Docker container lab

Labs 10–11 — Investigate auth / access logs; forward logs to a SIEM.

~0.5 h
AR/VR immersive scenario

Enter a virtual SOC; run a red-vs-blue simulation. Role: SOC analyst.

No headset? Desktop SIEM screenshots + rules. Printed and mobile versions are also available.

Individual technical assignment

Build one detection rule and test it.

Team exercise

Purple-team round: red acts, blue detects, map to ATT&CK.

Required hardware
  • SIEM training VM (e.g., Security Onion)
  • Log sources
Required software
  • Security Onion / SIEM
  • Sigma rules
Workplace application

SOC analysts spend their shift doing exactly this: triage, map, respond, document.

Docker progression step
L10 Investigating authentication and access logs

From idp and jump logs, reconstruct who accessed what and when.

L11 Forwarding logs to a SIEM

Forward proxy, idp and sensor logs to siem; confirm ingestion and build one dashboard.

L12 Detecting simulated adversary behavior

Run the provided attack script; write one detection rule and map it to ATT&CK.

Open the Docker range
Lab evidence to collect
Safety controls — confirm before starting
Controls practiced this week
Identity & access controlLogging & monitoring / detectionMalware & endpoint defense
See the full crosswalk