• May 21, 2025

The True Value of Purple Teaming in a Linux Environment

  • cr0nx

“In a fight, always observe your opponent – their eyes, their movements, their intentions.” - Bruce Lee stressed real-time observation of the enemy. Understanding an opponent involves not just pre-fight preparation but continuously adapting to their behavior and energy during the confrontation.


In today’s rapidly evolving threat landscape, securing Linux-based systems—widely used in servers, IoT, cloud/AI infrastructure, and DevOps pipelines—requires more attention than ever. You already probably know I am a huge advocate of learning the Linux/network defensive/forensics part through hands-on, offensive scope. The same goes in reverse → you can gain a lot of knowledge and useful experience through analyzing detection rules, signatures, Sigma rules, and also APT campaigns writeups or Threat Intelligence reports, etc., and then trying to generate attack events that would hopefully trigger existing detection logic (next step is naturally trying to bypass it).


In other words, I learn how the red team carries out their attacks to train my blue team mindset in an offensive way, which is useful to protect Linux production servers and better understand Linux internals. It's all about observing how attackers’ actions in the systems appear in different types of logs and telemetry, and how well existing tools perform in many of the detection or response use cases.


Saying that, welcome to Purple Teaming, a collaborative approach that bridges the gap between offensive (Red Team) and defensive (Blue Team) security practices. This article explores the true value of Purple Teaming in Linux environments, offering actionable insights for cybersecurity professionals seeking to enhance their organization’s resilience against real-world Linux threats.


Purple Teaming is a collaborative cybersecurity exercise where the Red Team (offensive security) and Blue Team (defensive security) work together to simulate, detect, and respond to threats in a controlled environment. Unlike standalone Red Team operations, which aim to emulate adversaries covertly, or Blue Team monitoring, which focuses on defense, Purple Teaming emphasizes transparency and knowledge sharing.



In a Linux context, Purple Teaming could involve:

  • Simulating adversary tactics, such as exploiting true web app vulnerabilities, abusing security misconfigurations, installing C2 implants, deploying persistence (udev rules, cron, at), stealing passwords (pam_authok anyone?), process/network/file hiding, and executing data exfiltration (ntp? ssh? dns?). It can be done just by using single offensive tests (ex. fileless/memfd_create executions, loading eBPF code or LKM modules by custom loader), even in an assumed breach style, or by developing full attack chains, where you emulate a complete attack starting from discovery and initial access phase and finishing on lateral movement, C2 and exfil.

  • Testing detection capabilities, like monitoring for anomalous syslog entries, unauthorized SSH access, analyzing Runtime Security alerts, triggered EDR detections, raw telemetry if needed, and corresponding network connections 

  • Iteratively improving defenses based on real-time feedback.


The goal is to enhance threat resilience—the ability to prevent, detect, and respond to attacks while fostering a culture of continuous improvement.



The list of Key Objectives could include:

  • Emulate Realistic Threats: Replicate adversary tactics, techniques, and procedures (TTPs) relevant to Linux environments, informed by threat intelligence, ex. emulations of In-memory BOF executions, installing kernel space / eBPF rootkits capable of doing syscall hooking, etc.

  • Enhanced Detection and Response: By combining offensive and defensive perspectives, Purple Teaming sharpens the Blue Team’s ability to detect and respond to Linux-specific attacks. Collaborative exercises reveal blind spots in tools like SIEMs or IDS/IPS deployed on Linux hosts.

  • Strengthen Collaboration: Align Red and Blue Teams (DevOps/SecOps/Linux Administrators as well!) to share insights, reducing friction and improving response times.

  • Identify Gaps: Uncover weaknesses in Linux configurations, monitoring tools, or incident response workflows.

  • Drive Actionable Improvements: Translate findings into practical enhancements, such as updated EDR/Runtime Security rules or hardened kernel and services.


In the Linux detection ecosystem, we have a ton of tools ready to deploy and test. Syslog alone is not enough! ;)  I recommend playing with at least below tools. Remember, this is the 1st critical part of Purple Teaming exercises preparation → having OS/network low-level telemetry in a central place + search heads and indexing, and providing the ability to query the systems on demand:

  • Runtime Security:

    • Falco (Host/K8S)

    • Jibril (Host)

    • Kunai (Host)

    • Tetragon (Host/K8S)

    • Tracee (Host/K8S)

    • Neuvector (K8S)

    • Kubearmor (K8S)

  • Syslog/auditd → SELinux logs are useful even if you have permissive mode

  • EDR:

    • Crowdstrike Falcon / SentinelOne / MS Defender / Palo Alto Cortex / Tanium → There are many Linux-oriented EDR implementations, take a look at the amazing project → https://www.edr-telemetry.com/linux

    • Elastic Security

    • Sandfly Security (not classic EDR, but a very powerful Agentless solution)

    • LKRG (not EDR, but performs runtime integrity checking of the Linux kernel and detection of security vulnerability exploits against the kernel)

  • SIEM:

    • Wazuh

    • Graylog

    • Elastic

    • Splunk

    • Qradar

    • any other

  • Network:

    • Suricata 

    • Zeek → conn.log, dns.log, ssh.log, ssl.log, ntp.log, kerberos.log, ntlm.log, http.log, to name a few

    • Arkime FPC

    • Squid Forward Proxy

    • WAF Reverse Proxy →modsecurity

  • DFIR:

    • OSquery

    • Velociraptor

    • UAC

    • Volatility Framework for Memory Forensics → linux_lsmod, linux_hidden_modules, linux.check_syscall.Check_syscall, linux.psaux.PsAux, linux.proc.Maps, check_ftrace, linux_bpf to name a few



Then, during an exercise, you can easily pivot between different types of events and drill down into them, trying to connect the dots:

  • Falco → Notice Disallowed outbound connection destination (command=c2-implant -F 2 connection=192.168.39.82:53978->public_IP:123

    • Kunai → data.command_line = /usr/sbin/c2-implant -F 2 → connect, send_data, execve, file_create, bpf_prog_load

      • Zeek → community_id / dst-src ports / 1st time seen, HASSH/JA3/JA4, bytes sent, malicious IP?, etc.

        • Velociraptor → Generic.Detection.Yara.Glob 

          • Sandfly → Full IR Scan

The most important thing is to find at least one critical detection point/event and then carefully look for the context and corresponding behavior. I like to rely on Falco to provide contextual events based on rules (yes, easily bypassable) and Kunai, which allows us to understand individual events within the provided raw telemetry (usually visible as a chain of events):

  • execve

  • execve_script

  • exit

  • exit_group

  • clone

  • prctl

  • kill

  • ptrace

  • Init_module

  • bpf_prog_load

  • bpf_socket_filter

  • mprotect_exec

  • mmap_exec

  • connect

  • dns_query

  • send_data

  • read

  • read_config

  • write

  • write_config

  • file_rename

  • file_unlink

  • write_close

  • file_create

  • file_scan

In short, visibility on many different layers is the key.



“Adapt to the enemy like water to a vessel.”

– Bruce Lee used the metaphor of water to describe flexibility in combat. Understanding the enemy means adapting to their style, strengths, and weaknesses to use them against them.


From the perspective of an attacker, you have to armor yourself. Again, there is plenty to choose from:

  • Exploits (local, remote)

  • C2 Frameworks like Mythic, Sliver, Merlin, just to name a few → check the C2matrix project: 

  • C2 plugins, modules, addons, ex, socks, tunnel/port forwarding, execute-shellcode, process/library injectors, port scanners, fileless execution, etc.

  • Atomic Red Team: There are many Linux security tests:

  • Caldera:

  • Webshells

  • Knowledge about existing GTFObins / lobins

  • Port / web / OS scanners

  • User/ kernel/ eBPF Rootkits

  • Linux CLI / one-liners/ shell tricks for reverse shells, file reading (read FILE < secrets.txt), upload/download



Sounds like a bit of chaos, correct? 

As a Linux security professional, I prefer to have all my offensive knowledge in a central place. My customers feel the same. That’s why I created EDRmetry Playbook -  an effective Linux EDR/SIEM Evaluation Testing Playbook which allows for Detection Coverage/Incident Response testing by executing dedicated Linux offensive chunks/scripts/codes mapped to MITRE ATT&CK™ Framework. All offensive techniques are ready to use by searching, copying, pasting into the terminal, and running. You can choose a single technique, or you can chain many together. You can focus on one tactic or just run all of them separately. Each of us has different needs and a different perspective. Each of us wants to achieve something different:

  • Purple Teaming Exercises

  • EDR / Detection evaluation testing

  • Red team campaigns

  • Threat Hunting hypothesis

  • Forensics

  • Knowledge transfer / hands-on training

  • General self-paced learning

Thus, I wanted to provide a dynamic structure for the project, where everyone can use it according to their needs. 


Returning to the main topic, your offensive part of purple teaming exercises could include some of the defined tests:

  • Initial Access:

    • EDR-T6114 - ActiveMQ CVE-2023-46604 Exploitation

    • EDR-T6105 - Apache HTTP CVE-2021-41773 Exploitation

    • EDR-T6185 - Apache Tomcat Manager Brute Force

    • EDR-T6116 - Apache Tomcat Manager Exploitation

    • EDR-T6077 - Code Execution via SSH XZBackdoor

    • EDR-T6210 - HTTPD CVE-2014-6271 Shellshock RCE

    • EDR-T6228 - JetBrains TeamCity CVE-2023-42793

    • EDR-T6062 - Kafka CVE-2023-25194 Exploitation

    • EDR-T6178 - MySQL Brute Force

    • EDR-T6262 - Ofbiz CVE-2024-45507 SSRF+RCE

    • EDR-T6243 - OpenSMTPD CVE-2020-7247 RCE

    • EDR-T6118 - Oracle WebLogic SSRF Exploitation

    • EDR-T6119 - Remote UAF Exploitation - root

    • EDR-T6261 - Remote UAF Exploitation - user

    • EDR-T6110 - Solr Log4J JNDI Exploitation

    • EDR-T6113 - Spring CVE-2022-22963 Exploitation

    • EDR-T6019 - SSH Brute Force / Spraying

  • Discovery:

    • EDR-T6065 - /proc enumeration

    • EDR-T6036 - C2 randomized hostname lookups

    • EDR-T6050 - Check ASLR configuration

    • EDR-T6055 - Check bpf settings from /proc

    • EDR-T6265 - Dismap Asset Discovery

    • EDR-T6097 - Download and launch LinEnum

    • EDR-T6084 - Enumerate kernel modules

    • EDR-T6225 - Execute "What Server" Enumeration

    • EDR-T6040 - Execute LinPEAS from /dev/tcp

    • EDR-T6069 - Execute nping

    • EDR-T6259 - Find all suid/sgid files

    • EDR-T6260 - Find all writable dirs

    • EDR-T6263 - Find SSH keys

    • EDR-T6223 - Get Kernel Text Region Address

    • EDR-T6047 - Kcore Memory File Read

    • EDR-T6218 - Linux VM Check via Hardware

    • EDR-T6217 - Linux VM Check via Kernel Modules

    • EDR-T6124 - Local Network Discovery Scan

    • EDR-T6251 - Process Snooping with pspy

    • EDR-T6204 - Read local file using curl

    • EDR-T6068 - Sudo Enumeration

  • Execution:

    • EDR-T6138 - Bash HTTP GET data with /dev/tcp

    • EDR-T6122 - Dump process memory via GDB

    • EDR-T6009 - eBPF system("whoami") Execution with bpftrace

    • EDR-T6025 - Encrypted ELF implant

    • EDR-T6094 - Establish Unix Socket connection

    • EDR-T6041 - Execute binary listening from a hidden directory as root

    • EDR-T6085 - Execute Linux Hack Tools

    • EDR-T6099 - Execute LKM call_usermodehelper() on ICMP

    • EDR-T6205 - Export proxy_http

    • EDR-T6039 - File Transfer to a hidden directory

    • EDR-T0003 - Install suspicious RPM package

    • EDR-T6086 - LKM Load/unload kernel module

    • EDR-T6051 - Modify core_pattern file

    • EDR-T6177 - MySQL UDF Command Execution

    • EDR-T6173 - OpenSSL - hackshell download without curl

    • EDR-T6174 - Perl - File download without curl

    • EDR-T6172 - Python - File download without curl

    • EDR-T6247 - Python GET File over Network

    • EDR-T6203 - Renice or Ulimit Execution

    • EDR-T6123.004 - Revshell mkfifo+nc

    • EDR-T6171 - Simplest Proc Name Masquerading

  • Defense Evasion:

    • EDR-T6108 - ASM Injection over /proc/PID/mem

    • EDR-T6239 - Bash Anti-Forensic Log Wiper

    • EDR-T6064 - Bash Script Obfuscation

    • EDR-T6089 - Bashrc File Hiding with ls Alias

    • EDR-T6156 - Block rsyslogd logging

    • EDR-T6167 - BOF Loading with BOF-Stager

    • EDR-T6222 - Change Shell Optional Behavior

    • EDR-T6005 - Clear kernel ring buffer

    • EDR-T6221 - Clear Paging Cache

    • EDR-T6088 - Copy/rename commands to exotic directory

    • EDR-T6043 - Disable .bash_history

    • EDR-T6193 - Disable ASLR

    • EDR-T6034 - Disable EDR/XDR sensor

    • EDR-T6219 - Disable SELinux

    • EDR-T6214 - Disable syslog

    • EDR-T6080 - Disable/modify iptables rules

    • EDR-T6268 - eBPF Attach prog to eth1 with XDP

    • EDR-T6008 - eBPF Hide PID with bad-bpf

    • EDR-T6267 - eBPF Hide PID/file with evilBPF

    • EDR-T6159 - eBPF Rename Loaded LKM module

    • EDR-T6253 - eBPF socket/proc/audit/bpftool Hider

    • EDR-T6245 - Enable Unprivileged BPF

    • EDR-T6121 - Execute fileless ELF with fee

    • EDR-T6067 - Execute Invisible SSH notty session

    • EDR-T6078 -Execute masscan/xmring via PRoot as BYOF

    • EDR-T6133 - File immutable with chattr

    • EDR-T6132 - File immutable with mount

    • EDR-T6188 - Fileless Execution with memexec

    • EDR-T6037 - Fileless memfd_create execution

    • EDR-T6045 - Hidden Executable File Creation in /dev/shm

    • EDR-T6098 - Hiding Process Name with /etc/ld.so.preload

    • EDR-T6227 - Inotify Trigger Action on File Access

    • EDR-T6248 - IPTables Drop outbound traffic

    • EDR-T6142 - LD_PRELOAD Process ENV Tampering

    • EDR-T6149 - LD_PRELOAD Shared Library shell_reverse_tcp

    • EDR-T6107 - LKM Remote Loading

    • EDR-T6166 - Load ELF object in memory via ELFLoader

    • EDR-T6081 - Modify /etc/hosts

    • EDR-T6053 - mount --bind process hiding

    • EDR-T6249 - mount -o remount

    • EDR-T6237 - Parent-child Obfuscated Process Hierarchy

    • EDR-T6241 - Patch Dynamic Linker

    • EDR-T6127 - Process Injection over dd+/proc/PID/mem

    • EDR-T6141 - Process Name Masquerading with argv[0] overwrite

    • EDR-T6038 - Process Name Masquerading with exec

    • EDR-T6140 - Process Name Masquerading with prctl()

    • EDR-T6032 - Proxy Execution with DDexec

    • EDR-T6111 - Ptrace Process Masq with Zapper

    • EDR-T6256 - Ptrace-less Process Injection with dlinject

    • EDR-T6238 - ptrace() based Anti-Analysis

    • EDR-T6028 - Ptrace() Shared Object Process Injection

    • EDR-T6244 - Python Userland Exec

    • EDR-T6220 - Reboot via Kernel System Request

    • EDR-T6092 - Space before command

    • EDR-T6182 - Suspicious File/Directory Location

    • EDR-T6096 - Terminate/stop syslog/EDR Agent

    • EDR-T6207 - Timestomping - Modifying the system date

    • EDR-T6054- Timestomping - touch

    • EDR-T6072 - Wipe Filesystem with shred

    • EDR-T6106 - Zombieant Preloading a decoy binary

  • Persistence:

    • EDR-T6048 - /etc/sudoers Modification

    • EDR-T6209 - Add Backdoor User - /etc/passwd modification

    • EDR-T6031 - Add backdoor user with uid=0

    • EDR-T6095 - Add new group

    • EDR-T6091 - Add User to Privileged Group

    • EDR-T6145 - At job persistence

    • EDR-T6250 - Backdooring Initramfs

    • EDR-T6170 - Cap_setuid over LD linker

    • EDR-T6093 - Crontab root Backdoor

    • EDR-T6213 - Deploy malicious RPM package

    • EDR-T6144 - DNF Package Manager

    • EDR-T6152 - eBPF Boopkit Rootkit

    • EDR-T6007 - eBPF Magic SRC Port Tracepoint Exe with bpftrace

    • EDR-T6158 - eBPF mount bpffs

    • EDR-T6157 - eBPF sudo Rootkit

    • EDR-T6151 - eBPF TripleCross Rootkit

    • EDR-T6117 - Execute UPX Reverse SSH server

    • EDR-T6161 - Ftrace Hooking Rootkit

    • EDR-T6146 - Git hook persistence

    • EDR-T6235 - Hiding SSH key with /etc/ld.so.preload

    • EDR-T6208 - HTTPD mod_authg Backdoor

    • EDR-T6017 - HTTPD mod_backdoor module

    • EDR-T6046 - Libc readdir() function hooking with /etc/ld.so.preload

    • EDR-T6101 - LKM ENOTTY Netfilter Hooking

    • EDR-T6155 - LKM KoviD Rootkit

    • EDR-T6153 - LKM Reptile Rootkit

    • EDR-T6163 - LKM Reveng Rootkit

    • EDR-T6023 - LKM rootkit - Diamorphine

    • EDR-T6154 - LKM Suterusu Rootkit

    • EDR-T6029 - Modify crontab with @reboot

    • EDR-T6164 - PAM Static Password Backdoor

    • EDR-T6011.004 - PHP base64 system Backdoor

    • EDR-T6011.009 - PHP filter chain generator

    • EDR-T6011.001 - PHP GET method

    • EDR-T6011.007 - PHP Weevly

    • EDR-T6139 - Python .pth Extensions

    • EDR-T6128 - Revshell ~/.profile background

    • EDR-T6066 - SSH Authorized keys

    • EDR-T6104 - SSHD Dummy Cipher Suite

    • EDR-T6130 - SUID backdoor

    • EDR-T6015 - Systemd Backdoor service

    • EDR-T6024 - Systemd Backdoor Timer Service

    • EDR-T6165 - Systemd-run Backdoor Timer Service

    • EDR-T6102 - Systemtap LPE creds() upgrade

    • EDR-T6179 - Udev+atd C2 persistence

    • EDR-T6011.014 - Webshell base64 PHP Eval

    • EDR-T6011.013 - Webshell PHP Array_join Obfuscation

    • EDR-T6011.003 - Webshell PHP Char Obfuscated

    • EDR-T6011.010 - Webshell PHP Eval

    • EDR-T6011.005 - Webshell PHP p0wny-shell

    • EDR-T6011.006 - Webshell PHP Proc Open

    • EDR-T6011.008 - Webshell PHP Simple popen()

    • EDR-T6011.012 - Webshell Tinyshell

    • EDR-T6162 - xt_conntrack.ko Rootkit

  • Privilege Escalation:

    • EDR-T6231 - DirtyPipe CVE-2022-0847 LPE

    • EDR-T6216 - Docker BOTB Break out the Box

    • EDR-T6215 - Docker Host Escape with Proc injection

    • EDR-T6147 - Docker Host Escape with socket

    • EDR-T6073 - Execute Trap signals

    • EDR-T6049 - Exploit local suid binary

    • EDR-T6232 - Linux Kernel CVE-2022-2588 LPE

    • EDR-T6183 - MySQL wsrep_provider CVE-2021-27928

    • EDR-T6229 - Namespace manipulation with unshare

    • EDR-T6187 - NFS SUID Escalation

    • EDR-T6184 - PATH Hijacking

    • EDR-T6230 - pkexec CVE-2021-4034 Exploitation

    • EDR-T6100 - Register LKM Char Device + LPE

    • EDR-T6109 - Socket Command Injection

    • EDR-T6233 - XZ / liblzma backdoor CVE-2024-3094

  • Exfiltration:

    • EDR-T6115 - DNS Exfiltration

    • EDR-T6169 - eBPF Magic String Tracepoint Execution with bpftrace

    • EDR-T6136 - Exfil data using rsync

    • EDR-T6137 - Exfil data using transfer.sh

    • EDR-T6211 - ICMP Python Scapy Exfiltration

    • EDR-T6168 - ICMP_exfil + nping Exfiltration

    • EDR-T6112 - NTP Data Exfiltration

    • EDR-T6103 - PAM creds over HTTP Post

    • EDR-T6234 - pam_exec SSHD Exfiltration

    • EDR-T6120 - Python FTP Upload

    • EDR-T6180 - SMB Data Exfiltration with impacket

    • EDR-T6257 - Telegram Data Exfiltration

    • EDR-T6052 - Upload data over HTTP/HTTPS

    • EDR-T6021 - Upload data over SCP/SFTP

    • EDR-T6135 - Upload data over WebDAV

    • EDR-T6181 - Upload/download data over SSHFS

  • Command and Control:

    • EDR-T6254 - DNS AXFR Payload Delivery

    • EDR-T6264 - eBPF Keylogger + DNS RCE

    • EDR-T6212 - Emp3r0r C2 Shadowsocks C2

    • EDR-T6090 - Execute Offensive Linux Tunneling tools

    • EDR-T6076 - Execute process via ProxyChains

    • EDR-T6224 - Fileless Reverse shell with sshx

    • EDR-T6123.014 - Gsocket Secure Connection

    • EDR-T6123.013 JSP+sh

    • EDR-T6075 - Make Non-standard port HTTP/HTTPS connection

    • EDR-T6126.004 - Merlin HTTPX C2

    • EDR-T6126.001 - Meterpreter reverse_tcp/https

    • EDR-T6126.005 - Mythic+Poseidon Websockets C2

    • EDR-T6126.003 - Mythic+Thanalos HTTP C2

    • EDR-T6200 - Ngrok Tunneling

    • EDR-T6123.008 - openssl+bash+/dev/fd/3

    • EDR-T6123.010 - PHP+bash

    • EDR-T6126.006 - Platypus C2

    • EDR-T6123.001 - Process Masquerading as kworker+exec+/dev/tcp

    • EDR-T6123.003 - Revshell curl+telnet

    • EDR-T6123.002 - Revshell curlshell

    • EDR-T6123.004 - Revshell mkfifo+nc

    • EDR-T6123.016 - Revshell on LKM call_usermodehelper()

    • EDR-T6123.012 - Revshell over GDB

    • EDR-T6123.009 - Revshell perl+ENV keys

    • EDR-T6123.006 - Revshell Perl+socket

    • EDR-T6123.015 - Revshell Python TLS

    • EDR-T6123.005 - Revshell python+socket+pty

    • EDR-T6123.007 - Revshell socat+bash

    • EDR-T6191 - Shell over HTTP streams

    • EDR-T6190 - Shell Over Reverse SSH

    • EDR-T6126.002 - Sliver C2 MTLS

    • EDR-T6134 - Upgrade a reverse shell to a PTY shell

    • EDR-T6011.011 - Webshell PHP FFI

    • EDR-T6148 - XOR shell_reverse_tcp Loader

  • Lateral Movement:

    • EDR-T6125 - Create a SOCKS proxy with ssh

    • EDR-T6258 - DarkFlare TCP over CDN Tunneling

    • EDR-T6186 - DNS Zone Transfer

    • EDR-T6071 - Drop Malicious Files Remotely

    • EDR-T6057 - Execute Port Scanning

    • EDR-T6226 - Execute SSHD as a victim user

    • EDR-T6255 - FRP Fast Reverse Proxy

    • EDR-T6131 - Hijack SSH Client Session

    • EDR-T6192 - Ligolo-ng Reverse TCP/TLS Tunneling

    • EDR-T6016 - Network ping sweep

    • EDR-T6035 - Proxychains TOR connection

    • EDR-T6189 - Reverse SOCKS5 proxy

    • EDR-T6160 - Socks Proxy from Tomcat JSP

    • EDR-T6033 - SSH Linux Tunneling

    • EDR-T6246 - SSHD Manipulation in sshd_config.d

    • EDR-T6266 - Tailscale Tunneling

    • EDR-T6074 - Visit malicious Threat Intel URL

  • Credential Access:

    • EDR-T6201 - Dump credentials via unshadow

    • EDR-T6242 - eBPF bcc Sniffs pam_get_authtok() with python3

    • EDR-T6199 - eBPF pamspy

    • EDR-T6006 - eBPF Sniff pam_get_authtok() with bpftrace

    • EDR-T6269 - eBPF Sniff SSL/TLS Traffic

    • EDR-T6060 - Read /etc/shadow

    • EDR-T6012 - Sniff sshd with strace

  • Impact:

    • EDR-T6240 - Bash Fork Bomb

    • EDR-T6005 - Clear kernel ring buffer

    • EDR-T6252 - Crypto Mining CPU stress

    • EDR-T6018 - Ransomware bash+openssl

    • EDR-T6058 - Ransomware Black Basta

    • EDR-T6063 - Ransomware C - lokpack


The cool thing is that you can create a full attack chain easily:

Do you feel the power of this modular approach? These offensive security tests represent techniques used to evaluate the detection and prevention capabilities of security products, particularly EDR solutions. Their true value lies in:

  • Identifying security gaps in defensive controls

  • Validating that security tools can detect known attack techniques

  • Helping security teams practice incident response against realistic scenarios

  • Building real-world attack chains to test defense-in-depth implementations


“Know yourself, know your enemy, and in a hundred battles, you will never be in danger.”

– Inspired by Sun Tzu and often referenced by Lee, this highlights that understanding both your own strengths and weaknesses and those of your enemy is crucial for success. Knowledge of the opponent allows you to anticipate their moves and prepare an effective strategy.


Purple Teaming is more than a buzzword - it’s a strategic approach to securing environments against sophisticated threats. By uniting the offensive expertise of Red Teams with the defensive capabilities of Blue Teams, organizations can proactively identify weaknesses, refine detection, and respond faster to incidents. In Linux ecosystems, where adversaries exploit open-source tools and misconfigurations, Purple Teaming is a game-changer. How do I know? Well, this article is based on many years of experience and collaborations with the biggest infrastructures and Blue/Red/SOC teams all over the world. They are all saying the same thing: 

  • “Experimenting with offensive techniques and using tools for detection and forensics greatly enhances skills and allows for better understanding of the Linux threat landscape, making faster decisions during IR.”



Ready to implement Purple Teaming in your organization? Start by defining clear objectives, leveraging threat intelligence, and fostering collaboration between your security teams. The result will be a stronger, more resilient Linux infrastructure capable of withstanding real-world attacks.


If your company is looking for Linux Purple Teaming services, feel free to reach out. I am open to knowledge sharing, private training, and services. Check out also my hands-on self learning course in PurpleLabs:


That’s it for now! Time to prepare for my X33fcon training - you can still join:


LINKS: