Lab 04 — Detection Validation & Purple Team Exercise
Mission Information
Section titled “Mission Information”| Property | Value |
|---|---|
| Lab Name | Detection Validation & Purple Team Exercise |
| Module | Module 08 — Cloud Red Team Operations |
| Lab Number | Lab 04 |
| Difficulty | Advanced |
| Estimated Time | 5–6 Hours |
| Platforms | AWS, Microsoft Azure, Google Cloud, Kubernetes |
| Tools Used | AWS CloudTrail, AWS Security Hub, Amazon GuardDuty, Azure Monitor, Microsoft Sentinel, Google Cloud Logging, Google Security Command Center, Falco, Prometheus, Grafana, Splunk/Elastic SIEM, MITRE ATT&CK Navigator |
| Prerequisites | Lab 03 — Cloud Lateral Movement Simulation |
| Objective | Validate cloud detections, measure SOC visibility, improve detection logic through Purple Team collaboration, and produce executive detection assessment reports. |
Mission Scenario
Section titled “Mission Scenario”CloudNova Technologies has completed the reconnaissance, identity assessment, and lateral movement phases of the Cloud Red Team engagement for MedSecure Global.
Although several attack paths were successfully demonstrated using approved synthetic resources, executive leadership now wants to answer an equally important question:
Would our Security Operations Centre detect these attacks quickly enough to stop a real attacker before significant business impact occurs?
Your mission is to execute controlled attack simulations, validate cloud telemetry, measure security detection and response capabilities, collaborate with Blue Team analysts, improve detection coverage, and verify that security improvements reduce organizational risk.
This engagement follows the GoHackersCloud Enterprise Cloud Red Team Operations Framework and all activities remain within approved Rules of Engagement.
Learning Objectives
Section titled “Learning Objectives”By the end of this lab you will be able to:
- Validate cloud security telemetry.
- Measure detection coverage.
- Verify cloud logging architecture.
- Evaluate SIEM visibility.
- Assess SOC investigations.
- Perform Purple Team collaboration.
- Tune detection rules.
- Improve cloud monitoring.
- Measure response effectiveness.
- Produce executive-ready detection assessment reports.
Enterprise Detection Architecture
Section titled “Enterprise Detection Architecture”Cloud Attack Simulation
│
▼
Cloud Audit Logs
│
┌──────┼────────┐
▼ ▼ ▼
CloudTrail Azure Logs GCP Logs
│
▼
Central SIEM
│
▼
Detection Rules
│
▼
SOC Analysts
│
▼
Incident Response
│
▼
Executive DashboardLab Requirements
Section titled “Lab Requirements”Before beginning verify:
- AWS CloudTrail enabled
- Azure Activity Logs enabled
- Google Cloud Audit Logs enabled
- SIEM operational
- GuardDuty enabled
- Security Hub enabled
- Microsoft Sentinel configured
- Google SCC configured
- Kubernetes Audit Logging enabled
- Falco deployed
- Synthetic attack environment available
Lab Task 01 — Verify Logging Coverage
Section titled “Lab Task 01 — Verify Logging Coverage”Review enterprise logging.
Validate:
- CloudTrail
- Azure Activity Logs
- Google Cloud Audit Logs
- Kubernetes Audit Logs
- VPC Flow Logs
- DNS Logs
- Authentication Logs
- CI/CD Logs
Document:
- Retention
- Coverage
- Missing logs
- Centralization
Expected Output
Section titled “Expected Output”Enterprise Logging Assessment CompletedLab Task 02 — Validate Cloud Telemetry
Section titled “Lab Task 02 — Validate Cloud Telemetry”Confirm telemetry reaches the SIEM.
Review:
- Identity events
- API calls
- IAM changes
- Resource modifications
- Authentication events
- Kubernetes events
- Serverless events
Expected Output
Section titled “Expected Output”Telemetry Validation SuccessfulLab Task 03 — Execute Controlled Attack Simulation
Section titled “Lab Task 03 — Execute Controlled Attack Simulation”Using approved synthetic identities execute:
- Login
- Role assumption
- Service account usage
- Kubernetes API access
- Secret retrieval
- Serverless execution
- Cross-account access
Collect timestamps for every action.
Validation Checklist
Section titled “Validation Checklist”- Approved identities
- Approved resources
- Synthetic assets only
- Audit logs generated
- Evidence collected
Lab Task 04 — Validate Detection Rules
Section titled “Lab Task 04 — Validate Detection Rules”Determine whether security controls detect:
- Privilege escalation
- Role assumption
- Excessive API activity
- Secret access
- Cross-account movement
- Kubernetes privilege abuse
- Serverless abuse
Example Detection Matrix
Section titled “Example Detection Matrix”| Activity | Logged | Alert Generated | Severity |
|---|---|---|---|
| Role Assumption | Yes | Yes | Medium |
| Secret Access | Yes | Yes | High |
| Kubernetes Admin Access | Yes | Yes | Critical |
| Service Account Abuse | Yes | Partial | High |
| Cross-Account Access | Yes | No | High |
Lab Task 05 — SOC Investigation
Section titled “Lab Task 05 — SOC Investigation”The Blue Team investigates the alerts.
Measure:
- Alert creation time
- Analyst acknowledgement
- Investigation duration
- Escalation time
- Containment decision
- Root cause analysis
Expected Output
Section titled “Expected Output”SOC Investigation Timeline Completed
Lab Task 06 — Purple Team Workshop
Section titled “Lab Task 06 — Purple Team Workshop”Conduct a collaborative review between:
- Red Team
- Blue Team
- SOC
- Cloud Security
- Detection Engineers
- Incident Response
Discuss:
- Missed detections
- Alert quality
- False positives
- False negatives
- Detection gaps
- ATT&CK coverage
Purple Team Workflow
Section titled “Purple Team Workflow”Red Team Attack
↓
Detection Review
↓
SOC Investigation
↓
Gap Analysis
↓
Detection Tuning
↓
Repeat Test
↓
Improved DetectionLab Task 07 — Tune Detection Rules
Section titled “Lab Task 07 — Tune Detection Rules”Improve SIEM content.
Examples:
- New IAM alerts
- Better Kubernetes detections
- Identity anomaly detection
- API abuse detection
- Cloud persistence alerts
- Serverless monitoring
- Secret access alerts
Document every tuning change.
Expected Output
Section titled “Expected Output”Detection Rules UpdatedLab Task 08 — Repeat Attack Simulation
Section titled “Lab Task 08 — Repeat Attack Simulation”Repeat the approved attack scenarios after tuning.
Measure improvements.
Record:
- Alert generation time
- Detection quality
- Investigation speed
- Response effectiveness
Example Comparison
Section titled “Example Comparison”| Metric | Before | After |
|---|---|---|
| Detection Time | 12 min | 2 min |
| Investigation Time | 35 min | 12 min |
| False Positives | 14 | 5 |
| ATT&CK Coverage | 62% | 91% |
Lab Task 09 — ATT&CK Mapping
Section titled “Lab Task 09 — ATT&CK Mapping”Map every attack technique.
Review:
- Initial Access
- Discovery
- Credential Access
- Privilege Escalation
- Lateral Movement
- Persistence
- Collection
- Command & Control
- Impact
Document:
- Detection coverage
- Logging
- Alert quality
- Response quality
Expected Output
Section titled “Expected Output”MITRE ATT&CK Coverage Matrix
Lab Task 10 — Detection Maturity Assessment
Section titled “Lab Task 10 — Detection Maturity Assessment”Evaluate:
- Visibility
- Detection
- Investigation
- Automation
- Response
- Containment
- Threat Hunting
Assign maturity:
- Initial
- Developing
- Defined
- Managed
- Optimized
Lab Task 11 — Executive Reporting
Section titled “Lab Task 11 — Executive Reporting”Prepare:
- Executive Summary
- Detection Overview
- Purple Team Results
- Detection Gaps
- SOC Performance
- ATT&CK Coverage
- Recommendations
- Roadmap
Deliverables
Section titled “Deliverables”Produce:
- Enterprise Logging Assessment
- Telemetry Validation Report
- Detection Validation Report
- SOC Investigation Timeline
- Purple Team Workshop Report
- Detection Rule Improvement Register
- ATT&CK Coverage Matrix
- Detection Maturity Assessment
- Executive Summary
- Technical Report
- Improvement Roadmap
Success Criteria
Section titled “Success Criteria”You have successfully completed this lab when you can:
- Validate cloud telemetry.
- Verify SIEM visibility.
- Measure SOC detection performance.
- Identify monitoring gaps.
- Improve detection logic.
- Conduct Purple Team collaboration.
- Produce executive detection reports.
- Recommend measurable security improvements.
Key Learning Outcomes
Section titled “Key Learning Outcomes”After completing this lab you will be able to:
- Think like both a Cloud Red Team Operator and a Blue Team Defender.
- Validate enterprise cloud detection capabilities.
- Assess SIEM effectiveness.
- Improve detection engineering through Purple Team collaboration.
- Measure SOC response performance.
- Map cloud attacks to MITRE ATT&CK.
- Produce executive-level cloud detection assessments used during enterprise security consulting engagements.
What’s Next?
Section titled “What’s Next?”➡️ Lab 05 — Enterprise Cloud Red Team Engagement
In the final lab of this module, you will combine everything learned throughout Module 08 into a complete end-to-end Cloud Red Team engagement. You will plan the operation, establish Rules of Engagement, perform reconnaissance, assess cloud identities, validate privilege escalation and lateral movement, simulate business impact, measure detection and response, conduct Purple Team collaboration, and deliver executive and technical reports just as professional Cloud Red Team consultants do during real enterprise security engagements.