Adversary emulation and simulation
This section is designed to give an overview of the possible solutions and products that can help us perform security testing to evaluate our maturity. As the maturity model presented in Chapter 2, Purple Teaming – a Generic Approach and a New Model, suggests, we will start with manual security testing before translating our effort into more advanced scenarios, and finally, implement autonomous and continuous security testing mechanisms.
We will see that some of the solutions are more focused on the technical aspects of purple teaming, while others were created with pure collaboration and documentation in mind. That is why we will look at Atomic Red Team, Caldera, VECTR, and Picus Security. We tried to select various projects that are open source, free, commercial solutions, focused on atomic testing and collaboration, to have a glimpse of the different purple flavors.
Nevertheless, it is worth mentioning other great projects and commercial...