Purple team
A purple team run fires six red team actions against the target and then asks the blue team pipeline what it saw. The score is the share of those actions that produced a detection, split between the cryptographic actions and the web actions.
1
Exercises
Six red team actions in each
67%
Avg blue score
Mean detection coverage
67%
Best coverage
Strongest single exercise
6
Actions fired
Across every exercise
Run a new exercise
Past exercises
| Target | Rating | Overall | Crypto | Web | Missed | Started |
|---|---|---|---|---|---|---|
| treasury.firstnationalbank.com | FAIR | 67% | 67% | 67% | 2 | 4 d ago 2026-08-26 03:00 UTC |
Red team action set
| Action | Category | What the red team does |
|---|---|---|
| Harvest now decrypt later capture harvest_now_decrypt_later |
Cryptography | Captured 412 handshakes negotiated under a classical group. Stored transcripts remain recoverable once quantum capability lands. |
| Protocol downgrade attempt tls_downgrade |
Cryptography | The listener accepted a TLSv1.2 hello and dropped the hybrid group from the negotiated parameters. |
| Certificate substitution certificate_forgery |
Cryptography | A substitute chain built on a classical issuing key was accepted by the default client trust store. |
| Response header injection header_injection |
Web | Injected a response header that survived the edge proxy and reached the browser unmodified. |
| Information disclosure probe information_disclosure |
Web | Version banners and a stack trace were recovered from error responses on the public origin. |
| Authentication weakness probe authentication_weakness |
Web | The login surface accepted unlimited attempts with no second factor and no lockout. |
Rating bands
- GOOD
- 80 percent of red team actions detected or better. The pipeline sees most of what an adversary would do.
- FAIR
- 50 to 79 percent detected. Coverage exists but leaves a usable gap.
- POOR
- Under 50 percent detected. Most red team activity would run unobserved.