Purple overview
In the previous series of chapters, we have seen various components of an infrastructure needed for the red and blue teams. But what about purple components? Do they involve additional specific servers and applications? The short answer is yes and no, but that is what we are going to see in this chapter.
First, let's quickly go through what we think mandatory components of a red and blue infrastructure are to perform purple teaming exercises:
All the components discussed in the previous chapters can be found here in the preceding figure. Of course, this is a nice-to-have architecture and not everybody can tend to, or even target, such architecture. At a minimum, we should have a log collection infrastructure and mechanisms so that we can centralize the logs necessary for our use cases (alerts, dashboard, and reporting, for example) with a security information and event...