The Challenge
The client is a large ASX-listed enterprise with a well-funded security programme, a 24/7 security operations centre and a modern detection stack. On paper the controls were strong. What the board and the CISO could not answer with confidence was a harder question: if a capable, patient attacker was already operating inside the environment, would the SOC see it, and how quickly could analysts move from alert to containment?
Previous penetration tests had confirmed that individual vulnerabilities could be exploited, but they said little about detection and response. Leadership wanted honest, measurable insight into mean time to detect and mean time to respond across a realistic attack chain, not a checklist. They also wanted the exercise to build the SOC's capability, not simply grade it after the fact.
Our Approach
StrikeCyber ran an objective-based adversary simulation delivered as a collaborative purple team engagement, working alongside the client's SOC rather than purely covertly. Expert operators emulated a threat actor relevant to the sector, mapping every action to MITRE ATT&CK so that each technique could be tied directly to the detections it should have triggered.
- An initial covert phase established a foothold and progressed through the attack chain while the SOC responded blind, giving a true baseline for detection and response timing.
- The engagement then shifted to an open purple team mode, where operators replayed techniques step by step with SOC analysts and detection engineers observing telemetry in real time.
- Each technique was scored on whether it was logged, alerted or missed, and detection content was tuned live, then the technique was re-run to confirm the improvement.
This detect, tune and re-test loop turned the exercise into hands-on capability building. Findings flowed into a shared portal so technical staff and executives saw the same real-time picture.
What We Found
- Slow progression through the early attack chain went unnoticed. Initial access, persistence and internal reconnaissance produced telemetry, but no alerts fired, so mean time to detect for the quiet opening moves was effectively unbounded.
- Defence evasion worked more often than expected. Living-off-the-land techniques using signed system binaries, and lightly obfuscated command execution, slipped past endpoint rules that were tuned for noisier, commodity tooling.
- Credential access and lateral movement were where detection finally engaged, but response was slow. Kerberoasting and reuse of harvested credentials eventually raised alerts, yet unclear escalation paths meant analysts lost time deciding who owned the response.
- Log coverage had blind spots. Several cloud and identity events that should have been central to detection were not being ingested, so key attacker actions left no trace the SOC could act on.
The Outcome
Because the engagement was collaborative, most gaps were addressed during the exercise itself. New and tuned detections were written for the evasion and lateral movement techniques that had been missed, then re-tested until they fired reliably. The log coverage gaps in cloud and identity telemetry were closed so the earlier blind spots became visible. The escalation and ownership confusion was resolved with a clearer response playbook, which noticeably shortened the time from alert to containment in the later replays.
Rather than a single pass or fail grade, the client received a technique-by-technique view of what was detected, what was missed and what had since been fixed, with re-test evidence for each. The SOC came away having practised against realistic tradecraft, and the CISO gained a defensible, measurable account of detection and response maturity to take to the board.
Why It Matters
Prevention-focused testing tells an enterprise which doors are unlocked. It says little about whether anyone is watching the corridors. For a mature organisation, the real risk is the attacker who is already inside and moving quietly. A collaborative purple team adversary simulation measures detection and response against genuine tradecraft and improves it in the same engagement, so investment lands on the gaps that let a breach run undetected. If you want to know how your own SOC would perform against a capable adversary, get in touch.