Teams
Cybersecurity is divided into three disciplines. Each has its own skills, tools, and mindset. Pick your path.
Red Team
Attackers. Break in, escalate, exfiltrate. Recon, exploitation, privilege escalation, lateral movement. PTES, MITRE ATT&CK, Cyber Kill Chain.
→ DEFENSIVEBlue Team
Defenders. Detect, respond, contain. SIEM, threat hunting, incident response, detection engineering. NIST IR, Diamond Model, MITRE ATT&CK for defenders.
→ INTEGRATIONPurple Team
Where red meets blue. Attack-detect-validate cycles. Framework mapping, shared telemetry, continuous improvement. The full picture.
→Which Should You Pick?
You do not have to pick one forever. Most cybersecurity careers involve all three:
- Red team teaches you how systems break. You learn to think like an attacker.
- Blue team teaches you how systems survive. You learn to detect and respond.
- Purple team combines both. You attack, then verify your blue team catches it.
The HTB CJCA certification tests both red and blue skills. Start with whichever interests you more, then learn the other.
Frameworks
All three teams use the same underlying frameworks, just from different angles:
| Framework | Red Team | Blue Team |
|---|---|---|
| MITRE ATT&CK | Plan attacks by tactic | Map detections to techniques |
| Cyber Kill Chain | Track attack progress | Identify detection gaps |
| PTES | Guide engagement execution | Understand attacker workflow |
| NIST SP 800-61 | Understand attack phases | Guide incident response |
| Diamond Model | Profile adversaries | Analyze intrusions |