Becoming a Purple Team Ambassador with SCYTHE’s Jorge Orchilles episode artwork

EPISODE · Dec 15, 2022 · 48 MIN

Becoming a Purple Team Ambassador with SCYTHE’s Jorge Orchilles

from Hacker Valley Blue · host Hacker Valley Media

Jorge Orchilles, Chief Technology Officer at SCYTHE and Principal SANS Instructor, brings his expertise in purple teaming to the pod this week to talk about the uniquely human and the understandably technical parts of red and blue collaboration. As the Purple Team Ambassador at SANS, Jorge lives for all things purple team, pioneering the purple team framework used in different SANS courses. This week, Jorge talks about transitioning from tech to security and remembering we all are working for the same goal.    Timecoded Guide: [00:00] Growing up in tech & discovering the cybersecurity world [13:52] Moving from SOC & ethical hacking to pen testing [26:25] Encountering the human side of a purple team engagement  [32:02] Proactive cybersecurity collaboration with PlexTrac & SCYTHE [45:57] Transitioning from red vs purple to purple through knowing all sides   Sponsor Links: Thank you to our friends at Axonius and Plex Trac for sponsoring this episode! The Axonius solution correlates asset data from existing solutions to provide an always up-to-date inventory, uncover gaps, and automate action — giving IT and security teams the confidence to control complexity. Learn more at axonius.com/hackervalley PlexTrac, the Proactive Cybersecurity Management Platform, brings red and blue teams together for better collaboration and communication. Check them out at plextrac.com/hackervalley   What was your experience writing a book as you got into working security? As a system admin just starting to get into SOC, Jorge agreed to write a book on Windows 7. In the course of just a few months, Jorge ended up writing a book, finishing up his Master’s degree, and working the night shift for his new SOC job. This type of grind paid off for Jorge’s career, but he doesn’t miss the amount of stress and strain he felt by trying to get everything done at once--- a common feeling amongst overworked tech employees.  “It was a great experience [writing a book], but at the same time, I was finishing my Master's, and I just got the SOC job, so I had to work three months of night shift, and it was like 7pm to 7am. So, that night shift along with the Masters, along with writing a book was just a lot.”   What was the moment that the purple team idea clicked for you?   In 2016, Jorge encountered a purple team activity for the first time as an employee at Citigroup. Back then, Jorge explains that the term “purple team” didn’t even exist yet, and their exercises were instead referred to as collaborative red team engagements. Still, the concept of purple teaming immediately piqued Jorge’s interest, especially when he began to encounter the personal collaborative efforts of purple teaming within the rigid world of cyber and tech.  “A lot of people think purple teaming is just these collaborative, hands-on exercises, but there's a psychological part of purple teaming no one ever talks about and that is the understanding that we are all human, we all have different goals, we all work for the same company.”   What are things that we could do or exercises to perform to create a bonding experience in a purple team exercise? Purple teaming is much more than seating your red team and blue team in the same room. Jorge explains that goals for purple team engagements have to be thoroughly defined and understood by members of the team before the engagement begins. Through his work with SCYTHE and SANS, Jorge often encounters practitioners and managers with the wrong perspective on purple teaming, thinking it's just a forced effort instead of an active collaboration. “The overall goals need to be covered first. What is the goal? Is it to run an adversary emulation together so that the blue learns from the red and the red learns for the blue? Or, is it to foster a collaborative culture? Because those two goals are different.”   What advice do you have for a security practitioner making that transition from red and blue team to a purple team?  Jorge has two pieces of advice for up -and-coming practitioners looking to make the most of purple team opportunities: remember the human element and learn as much as you can. Remembering the human element reminds you that everyone you work with, blue or red teamer, is a real person striving to make your company a more secure place to work. Learning as much as you can allows for a well-rounded approach in everything you do, from red to blue and everything in between.  “I do think that if you want to be good at either offense or defense, you have to understand the other side. It’s hard to be a defender if you have absolutely no idea what the attackers are doing, and it's hard to be an attacker if you have no idea what the defenders are doing.” --------------- Links: Keep up with our guest Jorge Orchilles on LinkedIn, Twitter, and his personal website Learn more about SCYTHE on LinkedIn and the SCYTHE website Find out more about SANS course on the SANS website Check out Jorge’s Purple Team Exercise Framework Thank you to our friends at Axonius and PlexTrac for sponsoring this episode! Connect with Davin Jackson on LinkedIn and Twitter Watch the live recording of this show on our YouTube Continue the conversation by joining our Discord Hear more from Hacker Valley Media and Hacker Valley Blue  

Jorge Orchilles, Chief Technology Officer at SCYTHE and Principal SANS Instructor, brings his expertise in purple teaming to the pod this week to talk about the uniquely human and the understandably technical parts of red and blue collaboration. As the Purple Team Ambassador at SANS, Jorge lives for all things purple team, pioneering the purple team framework used in different SANS courses. This week, Jorge talks about transitioning from tech to security and remembering we all are working for the same goal.    Timecoded Guide: [00:00] Growing up in tech & discovering the cybersecurity world [13:52] Moving from SOC & ethical hacking to pen testing [26:25] Encountering the human side of a purple team engagement  [32:02] Proactive cybersecurity collaboration with PlexTrac & SCYTHE [45:57] Transitioning from red vs purple to purple through knowing all sides   Sponsor Links: Thank you to our friends at Axonius and Plex Trac for sponsoring this episode! The Axonius solution correlates asset data from existing solutions to provide an always up-to-date inventory, uncover gaps, and automate action — giving IT and security teams the confidence to control complexity. Learn more at axonius.com/hackervalley PlexTrac, the Proactive Cybersecurity Management Platform, brings red and blue teams together for better collaboration and communication. Check them out at plextrac.com/hackervalley   What was your experience writing a book as you got into working security? As a system admin just starting to get into SOC, Jorge agreed to write a book on Windows 7. In the course of just a few months, Jorge ended up writing a book, finishing up his Master’s degree, and working the night shift for his new SOC job. This type of grind paid off for Jorge’s career, but he doesn’t miss the amount of stress and strain he felt by trying to get everything done at once--- a common feeling amongst overworked tech employees.  “It was a great experience [writing a book], but at the same time, I was finishing my Master's, and I just got the SOC job, so I had to work three months of night shift, and it was like 7pm to 7am. So, that night shift along with the Masters, along with writing a book was just a lot.”   What was the moment that the purple team idea clicked for you?   In 2016, Jorge encountered a purple team activity for the first time as an employee at Citigroup. Back then, Jorge explains that the term “purple team” didn’t even exist yet, and their exercises were instead referred to as collaborative red team engagements. Still, the concept of purple teaming immediately piqued Jorge’s interest, especially when he began to encounter the personal collaborative efforts of purple teaming within the rigid world of cyber and tech.  “A lot of people think purple teaming is just these collaborative, hands-on exercises, but there's a psychological part of purple teaming no one ever talks about and that is the understanding that we are all human, we all have different goals, we all work for the same company.”   What are things that we could do or exercises to perform to create a bonding experience in a purple team exercise? Purple teaming is much more than seating your red team and blue team in the same room. Jorge explains that goals for purple team engagements have to be thoroughly defined and understood by members of the team before the engagement begins. Through his work with SCYTHE and SANS, Jorge often encounters practitioners and managers with the wrong perspective on purple teaming, thinking it's just a forced effort instead of an active collaboration. “The overall goals need to be covered first. What is the goal? Is it to run an adversary emulation together so that the blue learns from the red and the red learns for the blue? Or, is it to foster a collaborative culture? Because those two goals are different.”   What advice do you have for a security practitioner making that transition from red and blue team to a purple team?  Jorge has two pieces of ad

NOW PLAYING

Becoming a Purple Team Ambassador with SCYTHE’s Jorge Orchilles

0:00 48:54

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

2 Old Ladies Walking Rozee 2 Old Ladies Walking features the journeys, insights, and light conversation between Liz and Rosie, two women of a certain age who live in the Hudson Valley of New York. From pelvic floor challenges and life with young adult children to food, bird calls, fear of “mad lamb” disease, and myriad topics in between, we cover it all while walking on the scenic trails of the northeast, or wherever our travels take us. Join us and have a listen! You Bet Your Garden Lehigh Valley Public Media “You Bet Your Garden” touted as an hour of “chemical-free horticultural hijinks,” is a weekly, nationally syndicated broadcast hosted by Mike McGrath. It is produced in the studios of PBS39 in Bethlehem, PA. This weekly call-in program offers ‘fiercely organic’ advice to gardeners far and wide. Blue Light News Archive Blue Light News is an innovative new Internet radio show devoted to covering the news of Unicoi County in a unique and interesting way. Celebration of Life Church Bozeman COLC It is our desire at Celebration of Life Church to reach into Bozeman and the entire Gallatin Valley with the Gospel of Jesus Christ and impact it for the Kingdom of God; to go beyond the four walls of the church and touch people in our community with the love of God; and to share the goodness of God in such a way that it will draw all men into a loving relationship with the One True Living God. We also desire to train up in the Word of God and encourage them to take the Gospel message to our community through various outreaches and evangelism. Enjoy our podcast and feel free to visit us.

Frequently Asked Questions

How long is this episode of Hacker Valley Blue?

This episode is 48 minutes long.

When was this Hacker Valley Blue episode published?

This episode was published on December 15, 2022.

What is this episode about?

Jorge Orchilles, Chief Technology Officer at SCYTHE and Principal SANS Instructor, brings his expertise in purple teaming to the pod this week to talk about the uniquely human and the understandably technical parts of red and blue collaboration. As...

Can I download this Hacker Valley Blue episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!