Purple team

A purple team run fires six red team actions against the target and then asks the blue team pipeline what it saw. The score is the share of those actions that produced a detection, split between the cryptographic actions and the web actions.

1
Exercises
Six red team actions in each
67%
Avg blue score
Mean detection coverage
67%
Best coverage
Strongest single exercise
6
Actions fired
Across every exercise

Run a new exercise

The exercise runs the same six actions against every target. Detection results are reproducible per host.
Open the scan form

Past exercises

TargetRatingOverallCryptoWebMissedStarted
treasury.firstnationalbank.com FAIR 67% 67% 67% 2 4 d ago
2026-08-26 03:00 UTC

Red team action set

ActionCategoryWhat the red team does
Harvest now decrypt later capture
harvest_now_decrypt_later
Cryptography Captured 412 handshakes negotiated under a classical group. Stored transcripts remain recoverable once quantum capability lands.
Protocol downgrade attempt
tls_downgrade
Cryptography The listener accepted a TLSv1.2 hello and dropped the hybrid group from the negotiated parameters.
Certificate substitution
certificate_forgery
Cryptography A substitute chain built on a classical issuing key was accepted by the default client trust store.
Response header injection
header_injection
Web Injected a response header that survived the edge proxy and reached the browser unmodified.
Information disclosure probe
information_disclosure
Web Version banners and a stack trace were recovered from error responses on the public origin.
Authentication weakness probe
authentication_weakness
Web The login surface accepted unlimited attempts with no second factor and no lockout.

Rating bands

GOOD
80 percent of red team actions detected or better. The pipeline sees most of what an adversary would do.
FAIR
50 to 79 percent detected. Coverage exists but leaves a usable gap.
POOR
Under 50 percent detected. Most red team activity would run unobserved.