- May 21, 2025
The True Value of Purple Teaming in a Linux Environment
- cr0nx
“In a fight, always observe your opponent – their eyes, their movements, their intentions.” - Bruce Lee stressed real-time observation of the enemy. Understanding an opponent involves not just pre-fight preparation but continuously adapting to their behavior and energy during the confrontation.
In today’s rapidly evolving threat landscape, securing Linux-based systems—widely used in servers, IoT, cloud/AI infrastructure, and DevOps pipelines—requires more attention than ever. You already probably know I am a huge advocate of learning the Linux/network defensive/forensics part through hands-on, offensive scope. The same goes in reverse → you can gain a lot of knowledge and useful experience through analyzing detection rules, signatures, Sigma rules, and also APT campaigns writeups or Threat Intelligence reports, etc., and then trying to generate attack events that would hopefully trigger existing detection logic (next step is naturally trying to bypass it).
In other words, I learn how the red team carries out their attacks to train my blue team mindset in an offensive way, which is useful to protect Linux production servers and better understand Linux internals. It's all about observing how attackers’ actions in the systems appear in different types of logs and telemetry, and how well existing tools perform in many of the detection or response use cases.
Saying that, welcome to Purple Teaming, a collaborative approach that bridges the gap between offensive (Red Team) and defensive (Blue Team) security practices. This article explores the true value of Purple Teaming in Linux environments, offering actionable insights for cybersecurity professionals seeking to enhance their organization’s resilience against real-world Linux threats.
Purple Teaming is a collaborative cybersecurity exercise where the Red Team (offensive security) and Blue Team (defensive security) work together to simulate, detect, and respond to threats in a controlled environment. Unlike standalone Red Team operations, which aim to emulate adversaries covertly, or Blue Team monitoring, which focuses on defense, Purple Teaming emphasizes transparency and knowledge sharing.
In a Linux context, Purple Teaming could involve:
-
Simulating adversary tactics, such as exploiting true web app vulnerabilities, abusing security misconfigurations, installing C2 implants, deploying persistence (udev rules, cron, at), stealing passwords (pam_authok anyone?), process/network/file hiding, and executing data exfiltration (ntp? ssh? dns?). It can be done just by using single offensive tests (ex. fileless/memfd_create executions, loading eBPF code or LKM modules by custom loader), even in an assumed breach style, or by developing full attack chains, where you emulate a complete attack starting from discovery and initial access phase and finishing on lateral movement, C2 and exfil.
-
Testing detection capabilities, like monitoring for anomalous syslog entries, unauthorized SSH access, analyzing Runtime Security alerts, triggered EDR detections, raw telemetry if needed, and corresponding network connections
Iteratively improving defenses based on real-time feedback.
The goal is to enhance threat resilience—the ability to prevent, detect, and respond to attacks while fostering a culture of continuous improvement.
The list of Key Objectives could include:
-
Emulate Realistic Threats: Replicate adversary tactics, techniques, and procedures (TTPs) relevant to Linux environments, informed by threat intelligence, ex. emulations of In-memory BOF executions, installing kernel space / eBPF rootkits capable of doing syscall hooking, etc.
-
Enhanced Detection and Response: By combining offensive and defensive perspectives, Purple Teaming sharpens the Blue Team’s ability to detect and respond to Linux-specific attacks. Collaborative exercises reveal blind spots in tools like SIEMs or IDS/IPS deployed on Linux hosts.
-
Strengthen Collaboration: Align Red and Blue Teams (DevOps/SecOps/Linux Administrators as well!) to share insights, reducing friction and improving response times.
-
Identify Gaps: Uncover weaknesses in Linux configurations, monitoring tools, or incident response workflows.
Drive Actionable Improvements: Translate findings into practical enhancements, such as updated EDR/Runtime Security rules or hardened kernel and services.
In the Linux detection ecosystem, we have a ton of tools ready to deploy and test. Syslog alone is not enough! ;) I recommend playing with at least below tools. Remember, this is the 1st critical part of Purple Teaming exercises preparation → having OS/network low-level telemetry in a central place + search heads and indexing, and providing the ability to query the systems on demand:
-
Runtime Security:
Falco (Host/K8S)
Jibril (Host)
Kunai (Host)
Tetragon (Host/K8S)
Tracee (Host/K8S)
Neuvector (K8S)
Kubearmor (K8S)
Syslog/auditd → SELinux logs are useful even if you have permissive mode
-
EDR:
Crowdstrike Falcon / SentinelOne / MS Defender / Palo Alto Cortex / Tanium → There are many Linux-oriented EDR implementations, take a look at the amazing project → https://www.edr-telemetry.com/linux
Elastic Security
Sandfly Security (not classic EDR, but a very powerful Agentless solution)
LKRG (not EDR, but performs runtime integrity checking of the Linux kernel and detection of security vulnerability exploits against the kernel)
-
SIEM:
Wazuh
Graylog
Elastic
Splunk
Qradar
any other
-
Network:
Suricata
Zeek → conn.log, dns.log, ssh.log, ssl.log, ntp.log, kerberos.log, ntlm.log, http.log, to name a few
Arkime FPC
Squid Forward Proxy
WAF Reverse Proxy →modsecurity
-
DFIR:
OSquery
Velociraptor
UAC
Volatility Framework for Memory Forensics → linux_lsmod, linux_hidden_modules, linux.check_syscall.Check_syscall, linux.psaux.PsAux, linux.proc.Maps, check_ftrace, linux_bpf to name a few
Then, during an exercise, you can easily pivot between different types of events and drill down into them, trying to connect the dots:
-
Falco → Notice Disallowed outbound connection destination (command=c2-implant -F 2 connection=192.168.39.82:53978->public_IP:123
-
Kunai → data.command_line = /usr/sbin/c2-implant -F 2 → connect, send_data, execve, file_create, bpf_prog_load
-
Zeek → community_id / dst-src ports / 1st time seen, HASSH/JA3/JA4, bytes sent, malicious IP?, etc.
-
Velociraptor → Generic.Detection.Yara.Glob
Sandfly → Full IR Scan
-
-
-
The most important thing is to find at least one critical detection point/event and then carefully look for the context and corresponding behavior. I like to rely on Falco to provide contextual events based on rules (yes, easily bypassable) and Kunai, which allows us to understand individual events within the provided raw telemetry (usually visible as a chain of events):
execve
execve_script
exit
exit_group
clone
prctl
kill
ptrace
Init_module
bpf_prog_load
bpf_socket_filter
mprotect_exec
mmap_exec
connect
dns_query
send_data
read
read_config
write
write_config
file_rename
file_unlink
write_close
file_create
file_scan
In short, visibility on many different layers is the key.
“Adapt to the enemy like water to a vessel.”
– Bruce Lee used the metaphor of water to describe flexibility in combat. Understanding the enemy means adapting to their style, strengths, and weaknesses to use them against them.
From the perspective of an attacker, you have to armor yourself. Again, there is plenty to choose from:
Exploits (local, remote)
-
C2 Frameworks like Mythic, Sliver, Merlin, just to name a few → check the C2matrix project:
C2 plugins, modules, addons, ex, socks, tunnel/port forwarding, execute-shellcode, process/library injectors, port scanners, fileless execution, etc.
-
Atomic Red Team: There are many Linux security tests:
-
Caldera:
Webshells
Knowledge about existing GTFObins / lobins
Port / web / OS scanners
User/ kernel/ eBPF Rootkits
Linux CLI / one-liners/ shell tricks for reverse shells, file reading (read FILE < secrets.txt), upload/download
Sounds like a bit of chaos, correct?
As a Linux security professional, I prefer to have all my offensive knowledge in a central place. My customers feel the same. That’s why I created EDRmetry Playbook - an effective Linux EDR/SIEM Evaluation Testing Playbook which allows for Detection Coverage/Incident Response testing by executing dedicated Linux offensive chunks/scripts/codes mapped to MITRE ATT&CK™ Framework. All offensive techniques are ready to use by searching, copying, pasting into the terminal, and running. You can choose a single technique, or you can chain many together. You can focus on one tactic or just run all of them separately. Each of us has different needs and a different perspective. Each of us wants to achieve something different:
Purple Teaming Exercises
EDR / Detection evaluation testing
Red team campaigns
Threat Hunting hypothesis
Forensics
Knowledge transfer / hands-on training
General self-paced learning
Thus, I wanted to provide a dynamic structure for the project, where everyone can use it according to their needs.
Returning to the main topic, your offensive part of purple teaming exercises could include some of the defined tests:
-
Initial Access:
EDR-T6114 - ActiveMQ CVE-2023-46604 Exploitation
EDR-T6105 - Apache HTTP CVE-2021-41773 Exploitation
EDR-T6185 - Apache Tomcat Manager Brute Force
EDR-T6116 - Apache Tomcat Manager Exploitation
EDR-T6077 - Code Execution via SSH XZBackdoor
EDR-T6210 - HTTPD CVE-2014-6271 Shellshock RCE
EDR-T6228 - JetBrains TeamCity CVE-2023-42793
EDR-T6062 - Kafka CVE-2023-25194 Exploitation
EDR-T6178 - MySQL Brute Force
EDR-T6262 - Ofbiz CVE-2024-45507 SSRF+RCE
EDR-T6243 - OpenSMTPD CVE-2020-7247 RCE
EDR-T6118 - Oracle WebLogic SSRF Exploitation
EDR-T6119 - Remote UAF Exploitation - root
EDR-T6261 - Remote UAF Exploitation - user
EDR-T6110 - Solr Log4J JNDI Exploitation
EDR-T6113 - Spring CVE-2022-22963 Exploitation
EDR-T6019 - SSH Brute Force / Spraying
-
Discovery:
EDR-T6065 - /proc enumeration
EDR-T6036 - C2 randomized hostname lookups
EDR-T6050 - Check ASLR configuration
EDR-T6055 - Check bpf settings from /proc
EDR-T6265 - Dismap Asset Discovery
EDR-T6097 - Download and launch LinEnum
EDR-T6084 - Enumerate kernel modules
EDR-T6225 - Execute "What Server" Enumeration
EDR-T6040 - Execute LinPEAS from /dev/tcp
EDR-T6069 - Execute nping
EDR-T6259 - Find all suid/sgid files
EDR-T6260 - Find all writable dirs
EDR-T6263 - Find SSH keys
EDR-T6223 - Get Kernel Text Region Address
EDR-T6047 - Kcore Memory File Read
EDR-T6218 - Linux VM Check via Hardware
EDR-T6217 - Linux VM Check via Kernel Modules
EDR-T6124 - Local Network Discovery Scan
EDR-T6251 - Process Snooping with pspy
EDR-T6204 - Read local file using curl
EDR-T6068 - Sudo Enumeration
-
Execution:
EDR-T6138 - Bash HTTP GET data with /dev/tcp
EDR-T6122 - Dump process memory via GDB
EDR-T6009 - eBPF system("whoami") Execution with bpftrace
EDR-T6025 - Encrypted ELF implant
EDR-T6094 - Establish Unix Socket connection
EDR-T6041 - Execute binary listening from a hidden directory as root
EDR-T6085 - Execute Linux Hack Tools
EDR-T6099 - Execute LKM call_usermodehelper() on ICMP
EDR-T6205 - Export proxy_http
EDR-T6039 - File Transfer to a hidden directory
EDR-T0003 - Install suspicious RPM package
EDR-T6086 - LKM Load/unload kernel module
EDR-T6051 - Modify core_pattern file
EDR-T6177 - MySQL UDF Command Execution
EDR-T6173 - OpenSSL - hackshell download without curl
EDR-T6174 - Perl - File download without curl
EDR-T6172 - Python - File download without curl
EDR-T6247 - Python GET File over Network
EDR-T6203 - Renice or Ulimit Execution
EDR-T6123.004 - Revshell mkfifo+nc
EDR-T6171 - Simplest Proc Name Masquerading
-
Defense Evasion:
EDR-T6108 - ASM Injection over /proc/PID/mem
EDR-T6239 - Bash Anti-Forensic Log Wiper
EDR-T6064 - Bash Script Obfuscation
EDR-T6089 - Bashrc File Hiding with ls Alias
EDR-T6156 - Block rsyslogd logging
EDR-T6167 - BOF Loading with BOF-Stager
EDR-T6222 - Change Shell Optional Behavior
EDR-T6005 - Clear kernel ring buffer
EDR-T6221 - Clear Paging Cache
EDR-T6088 - Copy/rename commands to exotic directory
EDR-T6043 - Disable .bash_history
EDR-T6193 - Disable ASLR
EDR-T6034 - Disable EDR/XDR sensor
EDR-T6219 - Disable SELinux
EDR-T6214 - Disable syslog
EDR-T6080 - Disable/modify iptables rules
EDR-T6268 - eBPF Attach prog to eth1 with XDP
EDR-T6008 - eBPF Hide PID with bad-bpf
EDR-T6267 - eBPF Hide PID/file with evilBPF
EDR-T6159 - eBPF Rename Loaded LKM module
EDR-T6253 - eBPF socket/proc/audit/bpftool Hider
EDR-T6245 - Enable Unprivileged BPF
EDR-T6121 - Execute fileless ELF with fee
EDR-T6067 - Execute Invisible SSH notty session
EDR-T6078 -Execute masscan/xmring via PRoot as BYOF
EDR-T6133 - File immutable with chattr
EDR-T6132 - File immutable with mount
EDR-T6188 - Fileless Execution with memexec
EDR-T6037 - Fileless memfd_create execution
EDR-T6045 - Hidden Executable File Creation in /dev/shm
EDR-T6098 - Hiding Process Name with /etc/ld.so.preload
EDR-T6227 - Inotify Trigger Action on File Access
EDR-T6248 - IPTables Drop outbound traffic
EDR-T6142 - LD_PRELOAD Process ENV Tampering
EDR-T6149 - LD_PRELOAD Shared Library shell_reverse_tcp
EDR-T6107 - LKM Remote Loading
EDR-T6166 - Load ELF object in memory via ELFLoader
EDR-T6081 - Modify /etc/hosts
EDR-T6053 - mount --bind process hiding
EDR-T6249 - mount -o remount
EDR-T6237 - Parent-child Obfuscated Process Hierarchy
EDR-T6241 - Patch Dynamic Linker
EDR-T6127 - Process Injection over dd+/proc/PID/mem
EDR-T6141 - Process Name Masquerading with argv[0] overwrite
EDR-T6038 - Process Name Masquerading with exec
EDR-T6140 - Process Name Masquerading with prctl()
EDR-T6032 - Proxy Execution with DDexec
EDR-T6111 - Ptrace Process Masq with Zapper
EDR-T6256 - Ptrace-less Process Injection with dlinject
EDR-T6238 - ptrace() based Anti-Analysis
EDR-T6028 - Ptrace() Shared Object Process Injection
EDR-T6244 - Python Userland Exec
EDR-T6220 - Reboot via Kernel System Request
EDR-T6092 - Space before command
EDR-T6182 - Suspicious File/Directory Location
EDR-T6096 - Terminate/stop syslog/EDR Agent
EDR-T6207 - Timestomping - Modifying the system date
EDR-T6054- Timestomping - touch
EDR-T6072 - Wipe Filesystem with shred
EDR-T6106 - Zombieant Preloading a decoy binary
-
Persistence:
EDR-T6048 - /etc/sudoers Modification
EDR-T6209 - Add Backdoor User - /etc/passwd modification
EDR-T6031 - Add backdoor user with uid=0
EDR-T6095 - Add new group
EDR-T6091 - Add User to Privileged Group
EDR-T6145 - At job persistence
EDR-T6250 - Backdooring Initramfs
EDR-T6170 - Cap_setuid over LD linker
EDR-T6093 - Crontab root Backdoor
EDR-T6213 - Deploy malicious RPM package
EDR-T6144 - DNF Package Manager
EDR-T6152 - eBPF Boopkit Rootkit
EDR-T6007 - eBPF Magic SRC Port Tracepoint Exe with bpftrace
EDR-T6158 - eBPF mount bpffs
EDR-T6157 - eBPF sudo Rootkit
EDR-T6151 - eBPF TripleCross Rootkit
EDR-T6117 - Execute UPX Reverse SSH server
EDR-T6161 - Ftrace Hooking Rootkit
EDR-T6146 - Git hook persistence
EDR-T6235 - Hiding SSH key with /etc/ld.so.preload
EDR-T6208 - HTTPD mod_authg Backdoor
EDR-T6017 - HTTPD mod_backdoor module
EDR-T6046 - Libc readdir() function hooking with /etc/ld.so.preload
EDR-T6101 - LKM ENOTTY Netfilter Hooking
EDR-T6155 - LKM KoviD Rootkit
EDR-T6153 - LKM Reptile Rootkit
EDR-T6163 - LKM Reveng Rootkit
EDR-T6023 - LKM rootkit - Diamorphine
EDR-T6154 - LKM Suterusu Rootkit
EDR-T6029 - Modify crontab with @reboot
EDR-T6164 - PAM Static Password Backdoor
EDR-T6011.004 - PHP base64 system Backdoor
EDR-T6011.009 - PHP filter chain generator
EDR-T6011.001 - PHP GET method
EDR-T6011.007 - PHP Weevly
EDR-T6139 - Python .pth Extensions
EDR-T6128 - Revshell ~/.profile background
EDR-T6066 - SSH Authorized keys
EDR-T6104 - SSHD Dummy Cipher Suite
EDR-T6130 - SUID backdoor
EDR-T6015 - Systemd Backdoor service
EDR-T6024 - Systemd Backdoor Timer Service
EDR-T6165 - Systemd-run Backdoor Timer Service
EDR-T6102 - Systemtap LPE creds() upgrade
EDR-T6179 - Udev+atd C2 persistence
EDR-T6011.014 - Webshell base64 PHP Eval
EDR-T6011.013 - Webshell PHP Array_join Obfuscation
EDR-T6011.003 - Webshell PHP Char Obfuscated
EDR-T6011.010 - Webshell PHP Eval
EDR-T6011.005 - Webshell PHP p0wny-shell
EDR-T6011.006 - Webshell PHP Proc Open
EDR-T6011.008 - Webshell PHP Simple popen()
EDR-T6011.012 - Webshell Tinyshell
EDR-T6162 - xt_conntrack.ko Rootkit
-
Privilege Escalation:
EDR-T6231 - DirtyPipe CVE-2022-0847 LPE
EDR-T6216 - Docker BOTB Break out the Box
EDR-T6215 - Docker Host Escape with Proc injection
EDR-T6147 - Docker Host Escape with socket
EDR-T6073 - Execute Trap signals
EDR-T6049 - Exploit local suid binary
EDR-T6232 - Linux Kernel CVE-2022-2588 LPE
EDR-T6183 - MySQL wsrep_provider CVE-2021-27928
EDR-T6229 - Namespace manipulation with unshare
EDR-T6187 - NFS SUID Escalation
EDR-T6184 - PATH Hijacking
EDR-T6230 - pkexec CVE-2021-4034 Exploitation
EDR-T6100 - Register LKM Char Device + LPE
EDR-T6109 - Socket Command Injection
EDR-T6233 - XZ / liblzma backdoor CVE-2024-3094
-
Exfiltration:
EDR-T6115 - DNS Exfiltration
EDR-T6169 - eBPF Magic String Tracepoint Execution with bpftrace
EDR-T6136 - Exfil data using rsync
EDR-T6137 - Exfil data using transfer.sh
EDR-T6211 - ICMP Python Scapy Exfiltration
EDR-T6168 - ICMP_exfil + nping Exfiltration
EDR-T6112 - NTP Data Exfiltration
EDR-T6103 - PAM creds over HTTP Post
EDR-T6234 - pam_exec SSHD Exfiltration
EDR-T6120 - Python FTP Upload
EDR-T6180 - SMB Data Exfiltration with impacket
EDR-T6257 - Telegram Data Exfiltration
EDR-T6052 - Upload data over HTTP/HTTPS
EDR-T6021 - Upload data over SCP/SFTP
EDR-T6135 - Upload data over WebDAV
EDR-T6181 - Upload/download data over SSHFS
-
Command and Control:
EDR-T6254 - DNS AXFR Payload Delivery
EDR-T6264 - eBPF Keylogger + DNS RCE
EDR-T6212 - Emp3r0r C2 Shadowsocks C2
EDR-T6090 - Execute Offensive Linux Tunneling tools
EDR-T6076 - Execute process via ProxyChains
EDR-T6224 - Fileless Reverse shell with sshx
EDR-T6123.014 - Gsocket Secure Connection
EDR-T6123.013 JSP+sh
EDR-T6075 - Make Non-standard port HTTP/HTTPS connection
EDR-T6126.004 - Merlin HTTPX C2
EDR-T6126.001 - Meterpreter reverse_tcp/https
EDR-T6126.005 - Mythic+Poseidon Websockets C2
EDR-T6126.003 - Mythic+Thanalos HTTP C2
EDR-T6200 - Ngrok Tunneling
EDR-T6123.008 - openssl+bash+/dev/fd/3
EDR-T6123.010 - PHP+bash
EDR-T6126.006 - Platypus C2
EDR-T6123.001 - Process Masquerading as kworker+exec+/dev/tcp
EDR-T6123.003 - Revshell curl+telnet
EDR-T6123.002 - Revshell curlshell
EDR-T6123.004 - Revshell mkfifo+nc
EDR-T6123.016 - Revshell on LKM call_usermodehelper()
EDR-T6123.012 - Revshell over GDB
EDR-T6123.009 - Revshell perl+ENV keys
EDR-T6123.006 - Revshell Perl+socket
EDR-T6123.015 - Revshell Python TLS
EDR-T6123.005 - Revshell python+socket+pty
EDR-T6123.007 - Revshell socat+bash
EDR-T6191 - Shell over HTTP streams
EDR-T6190 - Shell Over Reverse SSH
EDR-T6126.002 - Sliver C2 MTLS
EDR-T6134 - Upgrade a reverse shell to a PTY shell
EDR-T6011.011 - Webshell PHP FFI
EDR-T6148 - XOR shell_reverse_tcp Loader
-
Lateral Movement:
EDR-T6125 - Create a SOCKS proxy with ssh
EDR-T6258 - DarkFlare TCP over CDN Tunneling
EDR-T6186 - DNS Zone Transfer
EDR-T6071 - Drop Malicious Files Remotely
EDR-T6057 - Execute Port Scanning
EDR-T6226 - Execute SSHD as a victim user
EDR-T6255 - FRP Fast Reverse Proxy
EDR-T6131 - Hijack SSH Client Session
EDR-T6192 - Ligolo-ng Reverse TCP/TLS Tunneling
EDR-T6016 - Network ping sweep
EDR-T6035 - Proxychains TOR connection
EDR-T6189 - Reverse SOCKS5 proxy
EDR-T6160 - Socks Proxy from Tomcat JSP
EDR-T6033 - SSH Linux Tunneling
EDR-T6246 - SSHD Manipulation in sshd_config.d
EDR-T6266 - Tailscale Tunneling
EDR-T6074 - Visit malicious Threat Intel URL
-
Credential Access:
EDR-T6201 - Dump credentials via unshadow
EDR-T6242 - eBPF bcc Sniffs pam_get_authtok() with python3
EDR-T6199 - eBPF pamspy
EDR-T6006 - eBPF Sniff pam_get_authtok() with bpftrace
EDR-T6269 - eBPF Sniff SSL/TLS Traffic
EDR-T6060 - Read /etc/shadow
EDR-T6012 - Sniff sshd with strace
-
Impact:
EDR-T6240 - Bash Fork Bomb
EDR-T6005 - Clear kernel ring buffer
EDR-T6252 - Crypto Mining CPU stress
EDR-T6018 - Ransomware bash+openssl
EDR-T6058 - Ransomware Black Basta
EDR-T6063 - Ransomware C - lokpack
The cool thing is that you can create a full attack chain easily:
Do you feel the power of this modular approach? These offensive security tests represent techniques used to evaluate the detection and prevention capabilities of security products, particularly EDR solutions. Their true value lies in:
Identifying security gaps in defensive controls
Validating that security tools can detect known attack techniques
Helping security teams practice incident response against realistic scenarios
Building real-world attack chains to test defense-in-depth implementations
“Know yourself, know your enemy, and in a hundred battles, you will never be in danger.”
– Inspired by Sun Tzu and often referenced by Lee, this highlights that understanding both your own strengths and weaknesses and those of your enemy is crucial for success. Knowledge of the opponent allows you to anticipate their moves and prepare an effective strategy.
Purple Teaming is more than a buzzword - it’s a strategic approach to securing environments against sophisticated threats. By uniting the offensive expertise of Red Teams with the defensive capabilities of Blue Teams, organizations can proactively identify weaknesses, refine detection, and respond faster to incidents. In Linux ecosystems, where adversaries exploit open-source tools and misconfigurations, Purple Teaming is a game-changer. How do I know? Well, this article is based on many years of experience and collaborations with the biggest infrastructures and Blue/Red/SOC teams all over the world. They are all saying the same thing:
“Experimenting with offensive techniques and using tools for detection and forensics greatly enhances skills and allows for better understanding of the Linux threat landscape, making faster decisions during IR.”
Ready to implement Purple Teaming in your organization? Start by defining clear objectives, leveraging threat intelligence, and fostering collaboration between your security teams. The result will be a stronger, more resilient Linux infrastructure capable of withstanding real-world attacks.
If your company is looking for Linux Purple Teaming services, feel free to reach out. I am open to knowledge sharing, private training, and services. Check out also my hands-on self learning course in PurpleLabs:
-
Linux Attack, Detection and Live Forensics - Materials Only - Lifetime Access:
-
Defensive Security website:
That’s it for now! Time to prepare for my X33fcon training - you can still join:
-
Effective Linux EDR/XDR Evaluation Testing for Red and Blue Team:
LINKS:
-
Random Linux security gists:
-
awesome-linux-attack-forensics-purplelabs:
-
Advanced Linux Detection and Forensics Cheatsheet:
-
OffensiveCon25 - Dino Dai Zovi - Keynote - How Offensive Security Made Me Better at Defense: