# AEGIS — Purple Team Framework - **Document ID:** ARCH-47 - **Phase:** E.3 — Adversarial/Defensive Teams - **Status:** Draft for review (post four-reviewer discipline) - **Version:** 0.1 - **Date:** 2026-07-10 - **Owner:** Chief Security Architect --- ## 1. Purpose Codify joint red/blue exercises where the two teams share visibility during engagement and collaborate on improvement. Purple engagements convert red findings into blue detection improvements without adversarial time-lag. ## 2. Model - Scoped scenario chosen jointly. - Red team executes with blue team observing in real time. - After each step: pause + discuss + blue implements detection improvement + verify. - End: signed report + improved rules + updated threat model. ## 3. Cadence - Quarterly major engagements. - Monthly narrow purple on specific attack chains. - On demand after red-team surprise findings. ## 4. Deliverables - Improved detection content (Sigma or statistical). - Enriched threat-simulation scenarios (ARCH-39). - Updated ARCH-03 threat model. - New Golden regression tests where warranted. - Shared narrative for on-call training. ## 5. Assumption (hypothesis) - **H-1.** *Purple engagements produce ≥ 3 shipped detection improvements per quarter.* - Evidence: initial pilot results. - Validation: quarterly retrospective. - Confidence: Medium. - Expiration: annually reviewed. - Review Date: 12 months. ## 6. Trust Score Contribution Purple outcomes contribute to `Verification` and `Health` dimensions. ## 7. Independent Architecture Review - **F-1.** *Cost.* Balanced by yield (measured detection improvements). - **F-2.** *Loop dependency between red + blue.* Auditor observer prevents collusion. ## 8. Adversarial Architect Review - **A-1.** *Red team softens scenarios to appear collaborative.* External red team engagement in quarter alternation. - **A-2.** *Blue team over-fits to purple scenarios.* External red team + threat-simulation library variety. ## 9. Operational Reliability Review - **O-1.** Retrospective format standardized. - **O-2.** Sustainable cadence + measurable output. ## 10. Self-Critique - **S-1.** *Real value depends on cross-team culture.* Facilitation + external moderation helps. - **S-2.** *Findings may focus on quick wins vs. deep issues.* Council-level review of purple outputs. ## 11. First-Target Analysis and Redesign **Target:** purple becoming performative — teams follow the process but miss depth. Response: Auditor + Architecture Council quarterly review; yield metric (detection improvements shipped); external moderator when yield drops. ## 12. Future Risks / Known Limitations / Out-of-Scope / Retirement - **Future Risks.** Automation of adversary emulation reducing depth. - **Known Limitations.** Purple can't replace independent red engagement. - **Out-of-Scope.** Blind engagements (that's red team). - **Retirement Conditions.** If detection-engineering matures to a state where purple no longer yields — unlikely within 15 years. ## 13. Decisions ### D-47-1. Quarterly major + monthly narrow purple with external moderation - **Reason.** Balanced yield + independence. ## 14. Change Log - **0.1 (2026-07-10)** — Initial draft.