Purple Team Effectiveness Calculator
Measure purple team value: detections built per technique tested, gaps closed, time to new detection and coverage gained.
Inputs
Purple Team Effectiveness
69.0/ 100
Initial Detection Rate
36.7%
Gap Closure Rate
68.4%
Validation Rate
80.8%
Coverage Gained This Cycle
28.3%
Detections Shipped per Week
4.33per week
Programme Rating
C — Fair
Step by step
Values used
Techniques exercised in the cycle = 60 techniques; Detected on the first attempt = 22 techniques; Gaps identified = 38 gaps; New or improved detections shipped = 26 detections; Detections re-tested and confirmed = 21 detections; Mean days from gap to shipped detection = 12 days; Cycle length = 6 weeks; Detections that generated unacceptable noise = 4 detections
Purple Team Effectiveness
effectiveness = 0.30×gapClosure + 0.25×validation + 0.20×speed + 0.15×quality + 0.10×coverageGain, where gapClosure = detections shipped ÷ gaps found and speed = 100 − 3 × days to detection.
Purple Team Effectiveness
= 69.0 / 100
Initial Detection Rate
= 36.7
Gap Closure Rate
= 68.4
Validation Rate
= 80.8
Coverage Gained This Cycle
= 28.3
Detections Shipped per Week
= 4.33 per week
How it works
A purple team is only worth its cost if findings become durable detections, so gap closure and re-validation carry more than half the weight. Speed matters because a gap known for three months is an unmitigated risk, and quality is scored explicitly because shipping noisy rules to close a gap on paper makes the SOC worse. The initial detection rate is reported separately: it measures the estate you started with, not the team's work. Red teams produce reports and blue teams produce alerts; the purple metric is the only one that tracks whether a finding actually changed what the SOC can see.
Formula
Purple Team Effectiveness
effectiveness = 0.30×gapClosure + 0.25×validation + 0.20×speed + 0.15×quality + 0.10×coverageGain, where gapClosure = detections shipped ÷ gaps found and speed = 100 − 3 × days to detection.
- gapClosure
- Share of identified gaps that produced a shipped detection
- validation
- Share of new detections proven by re-testing
- speed
- Penalty of three points per day from gap to shipped detection
- quality
- Share of new detections that did not introduce unacceptable noise
Frequently Asked Questions
How is Purple Team Effectiveness calculated?
effectiveness = 0.30×gapClosure + 0.25×validation + 0.20×speed + 0.15×quality + 0.10×coverageGain, where gapClosure = detections shipped ÷ gaps found and speed = 100 − 3 × days to detection. A purple team is only worth its cost if findings become durable detections, so gap closure and re-validation carry more than half the weight. Speed matters because a gap known for three months is an unmitigated risk, and quality is scored explicitly because shipping noisy rules to close a gap on paper makes the SOC worse. The initial detection rate is reported separately: it measures the estate you started with, not the team's work.
Why does Purple Team Effectiveness matter?
Red teams produce reports and blue teams produce alerts; the purple metric is the only one that tracks whether a finding actually changed what the SOC can see.
What values do I need to enter?
This calculator takes 8 inputs: Techniques exercised in the cycle, Detected on the first attempt, Gaps identified, New or improved detections shipped, Detections re-tested and confirmed, Mean days from gap to shipped detection, Cycle length, Detections that generated unacceptable noise. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is a low initial detection rate a bad result?
No — it is the reason the exercise was worth running. A 37% first-run rate on realistic techniques is normal; what matters is whether the other 63% turned into validated detections before the next cycle.
Why penalise noisy detections?
Because a rule that fires two hundred times a day is switched off or ignored within a fortnight, which means the gap is still open while the metrics say it closed. Counting noise against the score keeps the number honest.
You might also need
- Red Team Coverage CalculatorCommonly used together
- Blue Team Readiness CalculatorCommonly used together
- Breach and Attack Simulation Score CalculatorCommonly used together
- Kill Chain Coverage CalculatorAlso in Forensics & Emerging Threats
- Enterprise Cybersecurity Health Score CalculatorAlso in Forensics & Emerging Threats
- LLM Prompt Injection Risk CalculatorAlso in Forensics & Emerging Threats