Skip to content
Calcrivo

Purple Team Effectiveness Calculator

Measure purple team value: detections built per technique tested, gaps closed, time to new detection and coverage gained.

Inputs

techniques
techniques
gaps
detections
detections
days
weeks
detections

Purple Team Effectiveness

69.0/ 100

Initial Detection Rate

36.7%

Gap Closure Rate

68.4%

Validation Rate

80.8%

Coverage Gained This Cycle

28.3%

Detections Shipped per Week

4.33per week

Programme Rating

C — Fair

Step by step

  1. Values used

    Techniques exercised in the cycle = 60 techniques; Detected on the first attempt = 22 techniques; Gaps identified = 38 gaps; New or improved detections shipped = 26 detections; Detections re-tested and confirmed = 21 detections; Mean days from gap to shipped detection = 12 days; Cycle length = 6 weeks; Detections that generated unacceptable noise = 4 detections

  2. Purple Team Effectiveness

    effectiveness = 0.30×gapClosure + 0.25×validation + 0.20×speed + 0.15×quality + 0.10×coverageGain, where gapClosure = detections shipped ÷ gaps found and speed = 100 − 3 × days to detection.

  3. Purple Team Effectiveness

    = 69.0 / 100

  4. Initial Detection Rate

    = 36.7

  5. Gap Closure Rate

    = 68.4

  6. Validation Rate

    = 80.8

  7. Coverage Gained This Cycle

    = 28.3

  8. Detections Shipped per Week

    = 4.33 per week

How it works

A purple team is only worth its cost if findings become durable detections, so gap closure and re-validation carry more than half the weight. Speed matters because a gap known for three months is an unmitigated risk, and quality is scored explicitly because shipping noisy rules to close a gap on paper makes the SOC worse. The initial detection rate is reported separately: it measures the estate you started with, not the team's work. Red teams produce reports and blue teams produce alerts; the purple metric is the only one that tracks whether a finding actually changed what the SOC can see.

Formula

Purple Team Effectiveness

effectiveness = 0.30×gapClosure + 0.25×validation + 0.20×speed + 0.15×quality + 0.10×coverageGain, where gapClosure = detections shipped ÷ gaps found and speed = 100 − 3 × days to detection.

gapClosure
Share of identified gaps that produced a shipped detection
validation
Share of new detections proven by re-testing
speed
Penalty of three points per day from gap to shipped detection
quality
Share of new detections that did not introduce unacceptable noise

Frequently Asked Questions

How is Purple Team Effectiveness calculated?

effectiveness = 0.30×gapClosure + 0.25×validation + 0.20×speed + 0.15×quality + 0.10×coverageGain, where gapClosure = detections shipped ÷ gaps found and speed = 100 − 3 × days to detection. A purple team is only worth its cost if findings become durable detections, so gap closure and re-validation carry more than half the weight. Speed matters because a gap known for three months is an unmitigated risk, and quality is scored explicitly because shipping noisy rules to close a gap on paper makes the SOC worse. The initial detection rate is reported separately: it measures the estate you started with, not the team's work.

Why does Purple Team Effectiveness matter?

Red teams produce reports and blue teams produce alerts; the purple metric is the only one that tracks whether a finding actually changed what the SOC can see.

What values do I need to enter?

This calculator takes 8 inputs: Techniques exercised in the cycle, Detected on the first attempt, Gaps identified, New or improved detections shipped, Detections re-tested and confirmed, Mean days from gap to shipped detection, Cycle length, Detections that generated unacceptable noise. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Is a low initial detection rate a bad result?

No — it is the reason the exercise was worth running. A 37% first-run rate on realistic techniques is normal; what matters is whether the other 63% turned into validated detections before the next cycle.

Why penalise noisy detections?

Because a rule that fires two hundred times a day is switched off or ignored within a fortnight, which means the gap is still open while the metrics say it closed. Counting noise against the score keeps the number honest.

You might also need