Skip to content

Lab 04 — Detection Validation & Purple Team Exercise

Property Value
Lab Name Detection Validation & Purple Team Exercise
Module Module 08 — Cloud Red Team Operations
Lab Number Lab 04
Difficulty Advanced
Estimated Time 5–6 Hours
Platforms AWS, Microsoft Azure, Google Cloud, Kubernetes
Tools Used AWS CloudTrail, AWS Security Hub, Amazon GuardDuty, Azure Monitor, Microsoft Sentinel, Google Cloud Logging, Google Security Command Center, Falco, Prometheus, Grafana, Splunk/Elastic SIEM, MITRE ATT&CK Navigator
Prerequisites Lab 03 — Cloud Lateral Movement Simulation
Objective Validate cloud detections, measure SOC visibility, improve detection logic through Purple Team collaboration, and produce executive detection assessment reports.

CloudNova Technologies has completed the reconnaissance, identity assessment, and lateral movement phases of the Cloud Red Team engagement for MedSecure Global.

Although several attack paths were successfully demonstrated using approved synthetic resources, executive leadership now wants to answer an equally important question:

Would our Security Operations Centre detect these attacks quickly enough to stop a real attacker before significant business impact occurs?

Your mission is to execute controlled attack simulations, validate cloud telemetry, measure security detection and response capabilities, collaborate with Blue Team analysts, improve detection coverage, and verify that security improvements reduce organizational risk.

This engagement follows the GoHackersCloud Enterprise Cloud Red Team Operations Framework and all activities remain within approved Rules of Engagement.


By the end of this lab you will be able to:

  • Validate cloud security telemetry.
  • Measure detection coverage.
  • Verify cloud logging architecture.
  • Evaluate SIEM visibility.
  • Assess SOC investigations.
  • Perform Purple Team collaboration.
  • Tune detection rules.
  • Improve cloud monitoring.
  • Measure response effectiveness.
  • Produce executive-ready detection assessment reports.

Cloud Attack Simulation
Cloud Audit Logs
┌──────┼────────┐
▼ ▼ ▼
CloudTrail Azure Logs GCP Logs
Central SIEM
Detection Rules
SOC Analysts
Incident Response
Executive Dashboard

Before beginning verify:

  • AWS CloudTrail enabled
  • Azure Activity Logs enabled
  • Google Cloud Audit Logs enabled
  • SIEM operational
  • GuardDuty enabled
  • Security Hub enabled
  • Microsoft Sentinel configured
  • Google SCC configured
  • Kubernetes Audit Logging enabled
  • Falco deployed
  • Synthetic attack environment available

Review enterprise logging.

Validate:

  • CloudTrail
  • Azure Activity Logs
  • Google Cloud Audit Logs
  • Kubernetes Audit Logs
  • VPC Flow Logs
  • DNS Logs
  • Authentication Logs
  • CI/CD Logs

Document:

  • Retention
  • Coverage
  • Missing logs
  • Centralization

Enterprise Logging Assessment Completed

Confirm telemetry reaches the SIEM.

Review:

  • Identity events
  • API calls
  • IAM changes
  • Resource modifications
  • Authentication events
  • Kubernetes events
  • Serverless events

Telemetry Validation Successful

Lab Task 03 — Execute Controlled Attack Simulation

Section titled “Lab Task 03 — Execute Controlled Attack Simulation”

Using approved synthetic identities execute:

  • Login
  • Role assumption
  • Service account usage
  • Kubernetes API access
  • Secret retrieval
  • Serverless execution
  • Cross-account access

Collect timestamps for every action.


  • Approved identities
  • Approved resources
  • Synthetic assets only
  • Audit logs generated
  • Evidence collected

Determine whether security controls detect:

  • Privilege escalation
  • Role assumption
  • Excessive API activity
  • Secret access
  • Cross-account movement
  • Kubernetes privilege abuse
  • Serverless abuse

Activity Logged Alert Generated Severity
Role Assumption Yes Yes Medium
Secret Access Yes Yes High
Kubernetes Admin Access Yes Yes Critical
Service Account Abuse Yes Partial High
Cross-Account Access Yes No High

The Blue Team investigates the alerts.

Measure:

  • Alert creation time
  • Analyst acknowledgement
  • Investigation duration
  • Escalation time
  • Containment decision
  • Root cause analysis

SOC Investigation Timeline Completed


Conduct a collaborative review between:

  • Red Team
  • Blue Team
  • SOC
  • Cloud Security
  • Detection Engineers
  • Incident Response

Discuss:

  • Missed detections
  • Alert quality
  • False positives
  • False negatives
  • Detection gaps
  • ATT&CK coverage

Red Team Attack
Detection Review
SOC Investigation
Gap Analysis
Detection Tuning
Repeat Test
Improved Detection

Improve SIEM content.

Examples:

  • New IAM alerts
  • Better Kubernetes detections
  • Identity anomaly detection
  • API abuse detection
  • Cloud persistence alerts
  • Serverless monitoring
  • Secret access alerts

Document every tuning change.


Detection Rules Updated

Repeat the approved attack scenarios after tuning.

Measure improvements.

Record:

  • Alert generation time
  • Detection quality
  • Investigation speed
  • Response effectiveness

Metric Before After
Detection Time 12 min 2 min
Investigation Time 35 min 12 min
False Positives 14 5
ATT&CK Coverage 62% 91%

Map every attack technique.

Review:

  • Initial Access
  • Discovery
  • Credential Access
  • Privilege Escalation
  • Lateral Movement
  • Persistence
  • Collection
  • Command & Control
  • Impact

Document:

  • Detection coverage
  • Logging
  • Alert quality
  • Response quality

MITRE ATT&CK Coverage Matrix


Lab Task 10 — Detection Maturity Assessment

Section titled “Lab Task 10 — Detection Maturity Assessment”

Evaluate:

  • Visibility
  • Detection
  • Investigation
  • Automation
  • Response
  • Containment
  • Threat Hunting

Assign maturity:

  • Initial
  • Developing
  • Defined
  • Managed
  • Optimized

Prepare:

  • Executive Summary
  • Detection Overview
  • Purple Team Results
  • Detection Gaps
  • SOC Performance
  • ATT&CK Coverage
  • Recommendations
  • Roadmap

Produce:

  • Enterprise Logging Assessment
  • Telemetry Validation Report
  • Detection Validation Report
  • SOC Investigation Timeline
  • Purple Team Workshop Report
  • Detection Rule Improvement Register
  • ATT&CK Coverage Matrix
  • Detection Maturity Assessment
  • Executive Summary
  • Technical Report
  • Improvement Roadmap

You have successfully completed this lab when you can:

  • Validate cloud telemetry.
  • Verify SIEM visibility.
  • Measure SOC detection performance.
  • Identify monitoring gaps.
  • Improve detection logic.
  • Conduct Purple Team collaboration.
  • Produce executive detection reports.
  • Recommend measurable security improvements.

After completing this lab you will be able to:

  • Think like both a Cloud Red Team Operator and a Blue Team Defender.
  • Validate enterprise cloud detection capabilities.
  • Assess SIEM effectiveness.
  • Improve detection engineering through Purple Team collaboration.
  • Measure SOC response performance.
  • Map cloud attacks to MITRE ATT&CK.
  • Produce executive-level cloud detection assessments used during enterprise security consulting engagements.

➡️ Lab 05 — Enterprise Cloud Red Team Engagement

In the final lab of this module, you will combine everything learned throughout Module 08 into a complete end-to-end Cloud Red Team engagement. You will plan the operation, establish Rules of Engagement, perform reconnaissance, assess cloud identities, validate privilege escalation and lateral movement, simulate business impact, measure detection and response, conduct Purple Team collaboration, and deliver executive and technical reports just as professional Cloud Red Team consultants do during real enterprise security engagements.