Back to glossary

Blue team

2 min read

In security operations, the blue team is the defending side: the people and tooling focused on detecting, responding to and recovering from attacks. The term only means something in relation to an attacking side, which is why it belongs to exercise vocabulary rather than to organisational charts.

July 24, 2026
Compartir:

How it works

The functions grouped under the label are monitoring and triage in the SOC, building and maintaining the logic that generates alerts, which is detection engineering, proactive investigation through threat hunting, incident handling, and the hardening and architecture work that removes the routes in the first place.

The colour vocabulary comes from exercises. Red simulates the adversary, blue defends, and purple is not a third team but a way of running the other two together, with the attack announced and the detection examined technique by technique. The comparison table for the three sits on the purple team entry so it lives in one place.

What goes wrong

The relationship is treated as a contest. A red team engagement that is scored on whether the attackers succeeded produces a defensive team incentivised to be defensive in the wrong sense, and an attacking team incentivised to win rather than to teach. Both outcomes waste the exercise. The useful question was never whether we got in; it was what was seen, when, and what happened next.

The second failure is asymmetry of information after the fact. A red team that hands over a narrative report leaves the defenders unable to act on it. What is actually usable is timestamps, host names, account names, command lines and infrastructure, so the defenders can search their own telemetry and establish whether the data existed at all. Absent telemetry is a more valuable finding than a missing rule, and it only appears from that comparison.

Third, defensive capability is judged by tooling. A well-equipped centre with no authority to contain out of hours is not a defence, it is a monitoring service, and that gap shows up in every exercise where the detection fired correctly and nothing followed.

Where this shows up in an audit

Our exercises are designed to end in a joint session rather than a document handover. We walk through the timeline with the defenders, technique by technique, and record for each one whether telemetry existed, whether a rule fired, whether it was triaged and whether anything was done. That produces a specific work list rather than a grade. Where the client has no defensive function to speak of, we say so plainly, because running a covert exercise against an estate with no detection capability measures something nobody needed measured. This is part of how red and blue work together in a purple team exercise.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.