Skip to content

Core Concepts

Key Terms in Purple Team Operations

Atomic Tests

Atomic tests are the fundamental building blocks of adversary behavior, representing specific, observable actions that adversaries perform during an attack. These tests are designed to isolate and simulate individual tactics, techniques, and procedures (TTPs) from MITRE ATT&CK frameworks. By breaking down complex attacks into discrete, reproducible actions, atomic tests enable defenders to systematically evaluate and validate defensive controls.

Technique Mapping

Technique mapping involves associating atomic tests with specific MITRE ATT&CK techniques to contextualize their purpose and alignment with known adversary behaviors. This process helps defenders understand how a test fits into broader attack patterns and prioritize coverage for high-impact tactics. For example, a service-creation test maps to MITRE ATT&CK technique T1052 ("Exploit Public-Facing Application") only if the atomic test specifically mimics behavior associated with exploiting public-facing applications (e.g., leveraging a web server vulnerability). By linking tests to techniques, teams can validate whether their defenses address relevant attack vectors.

Detection Validation

Detection validation is the process of verifying whether defensive measures effectively identify and mitigate malicious activity. This involves testing defenses against atomic tests to confirm their ability to detect, alert on, or block specific adversary behaviors. For instance, a firewall rule designed to block exploit traffic would be validated by running an atomic test that replicates the exploit behavior and observing whether the rule successfully intercepts the attempt. This ensures that defensive strategies are both actionable and aligned with real-world attack scenarios.