What we got wrong about purple teaming in our first year
Year one of our purple program produced slide decks, not detections. Here's the structural diagnosis and the pipeline model that fixed it.
May 25, 2026
Senior Detection Engineer & Incident Responder
Marta K. is a senior detection engineer and incident responder with over eight years of hands-on experience operating and scaling security operations in high-growth SaaS and fintech environments. She started her career as a SOC analyst, working night shifts triaging alerts and investigating suspicious activity across endpoint, identity, and cloud environments. Over time, she moved into detection engineering, where she focused on building and tuning detection pipelines, reducing false positives, and mapping coverage to frameworks like MITRE ATT&CK. Marta has led incident response efforts for ransomware, credential compromise, and insider threat scenarios, and has helped teams transition from reactive alert handling to structured investigation workflows and proactive detection strategies. Her work has included implementing detection-as-code practices, improving alert fidelity, and designing playbooks that actually get used during real incidents. She writes about the reality of running security operations — from alert fatigue and broken escalation paths to what actually works when building detections and responding to incidents under pressure.
Year one of our purple program produced slide decks, not detections. Here's the structural diagnosis and the pipeline model that fixed it.
May 25, 2026
AI triage hasn't moved alert fatigue. The structural causes start upstream. Here's what to fix before another AI SOC pilot.
May 12, 2026
Detection engineering stalls when it's treated as a person, not a function. Here's what the function actually owns, and how to build it from Level 0.
May 11, 2026
Most IRPs are written for auditors, not analysts. Here's what a usable incident response plan actually contains, plus a stripped-down template.
May 10, 2026
Practitioner takes on SOC modernization, detection engineering, threat hunting, and more. No fluff. No product pitches.