Solutions · Purple team

Attack and defend in the same loop.

Vypr runs the attacker's round and the defender's check as one cycle: map, route, prove, detect, fix, re-test — after every change, every release and every new exposure.

A workshop isn't a program.

  1. Red demos, blue watches
    The annual exercise ends in a deck. The writeup dies in a drive, and the tricks with it.
  2. Nothing is measured
    Nobody can say which detections fired, which paths closed, what actually got better.
  3. Coverage lives in a spreadsheet
    The claim is updated quarterly. The system it describes changed yesterday.

The deck is not the deliverable.

Missions

The exercise runs every day.

Red, blue and purple presets — or your own instructions — run against the system you have today, not the one you had at the workshop.

  • Pick a preset: red team, blue team or purple team runs
  • Custom instructions for your own scenarios
  • Continuous runs on a schedule or on a trigger
Missions1running·7done
Rotate exposed access keyin progress
Engineer → domain admin via ADCScompleted
Azure Runbooks VM RCEplanned
API .NET RCEcompleted
PresetsCustom instructionsManual
Red
External surface
Rotate exposed access key
Take over leaked secrets
Blue
Protection validation
Purple
Network exposure overview
Confirm or cancel · the agent waits on your call
Findings

Detection ground truth.

Every executed path is a sample of real attacker traffic: see what your controls caught, what they missed, and carry the gap into the next round.

  • Machine-proven, reachable findings as ground truth
  • Severity and stability states on every issue
  • Opportunities surfaced alongside findings
Findings2proven·1unreachable
  • Public storage bucket, readablereachable
  • Admin endpoint reachable from the internetreachable
  • Outdated dependency with a known issueunreachable
Opportunities
  • SSRF to cloud metadataopportunity
IssuesFindings
Public storage bucket, readable
warningmachine provenreachablenot stable
The bucket serves objects to anonymous requests from the internet. The agent retrieved a file as proof; the chain to the identity role is attached.
evidence attachedComplete remediation →
Sessions

One record both teams read.

Red sees the work; blue sees the proof. The same session, the same summary — no deck to translate.

  • The full run, from task to evidence
  • The AI summary both teams act on
  • Tags keep past exercises searchable
Sessions
Rotate exposed access keyrunning
External surface · acme.comdone
Cloud exposure reviewdone
redawskey-rotationagent
SummaryAI activity
Rotate exposed access key
Session summary (AI)A leaked read-only key was proven usable and rotated; evidence exported for the report.
  • 21:37:39Trusted cluster memory loaded
  • 21:37:39Skill cloud:redteaming loaded
  • 21:37:39Scanned route53 — 2 new hosts
  • 21:37:39Discovered SSO + gathered IAM
  • 21:37:39Exported evidence bundle
Activity (15)Worked 2m 36s·verified

Security coverage that behaves like headcount, not another console to check.

The purple loop

The cycle, with the defender in it.

  1. 01
    MAP
    Everything you expose.
  2. 02
    ROUTE
    A path to what matters.
  3. 03
    PROVE
    Which paths are real.
  4. 04
    DETECT
    What your controls caught.
  5. 05
    FIX
    Where it actually opens.
  6. 06back to 01
    RE-TEST
    Until it provably fails.
The purple loop — attack and defense in one round.
Every change · Every release · Every new exposure
Questions

Asked by every team like yours.

  • An exercise is episodic; this is a program. The cycle runs after every change and every release, and each round leaves a measured artifact instead of a deck.

Run the loop on your own domain.
Type your domain.