Energy 
Custom-Made EDR Detections Through Purple Teaming
Purple Teaming
A large energy company ordered a purple team assessment. Objectives were initial access, detection tests on known attack strategies, execution of an implant during active EDR, testing the detection possibilities through EDR or monitoring solutions, as well as, execution of TTPs for lateral movement or persistence.
During the assessment, the blue team was able to develop custom-made detections in the EDR console to detect attack behaviour the EDR would not expose on its own.