Walmart’s “Trusted Agent” Strategy Is Rewriting the Rules of Purple Teaming + Video

Listen to this Post

Featured ImageIntroduction: When Attackers and Defenders Stop Fighting Each Other

Cybersecurity teams are often divided by design. Red teams are expected to think like attackers, break through defenses, expose weaknesses, and challenge assumptions. Blue teams, meanwhile, must detect those attacks, investigate suspicious activity, contain threats, and keep the business running.

That separation can be useful, but it can also create an unhealthy rivalry.

When an exercise becomes a competition between “the team that attacked” and “the team that defended,” everyone can lose sight of the real objective: making the organization more resilient.

Walmart is taking a different path.

Under the leadership of Jason O’Dell, the retailer’s Global Vice President of Security Operations, Walmart has developed a collaborative approach to purple teaming built around trust, psychological safety, shared learning, and what O’Dell calls a “trusted agent” model.

Instead of waiting until an adversarial exercise is finished to discover what went wrong, members of the defensive team can observe offensive activity in real time. They can examine telemetry, evaluate detections, identify visibility gaps, and help ensure that the exercise does not accidentally damage production operations.

The result is more than a better penetration test.

It is an attempt to turn offensive and defensive security into a continuous learning system.

The Problem With Traditional Red and Blue Teams

Competition Can Become the Wrong Objective

Traditional security exercises often resemble a contest.

The red team attempts to penetrate systems without being detected. The blue team tries to identify, stop, and investigate the intrusion.

There is obvious value in that model.

But there is also a danger.

If the red team becomes obsessed with proving that it can bypass defenses, while the blue team becomes obsessed with preventing the red team from succeeding, the exercise can evolve into a win-or-lose event.

That mindset can discourage openness.

A Successful Attack Is Not the Real Failure

A red team successfully compromising an environment does not automatically mean the exercise failed.

In fact, discovering that a detection mechanism does not work can be one of the most valuable outcomes possible.

The real question is what happens afterward.

Did the organization understand why the attack worked?

Did defenders learn what signals they missed?

Did engineers improve logging?

Did detection rules become more effective?

Did incident responders learn how the attack actually unfolded?

Did the red team become better at understanding defensive visibility?

Those are the measurements that ultimately matter.

Walmart’s Philosophy: Learn Instead of Win

Changing the Meaning of Purple Teaming

O’Dell’s approach begins with changing the psychology surrounding security exercises.

Rather than asking who won, Walmart asks whether the organization became stronger as a result of the exercise.

That distinction sounds simple, but it changes almost everything.

When employees believe they are being judged on whether they can defeat another internal team, they may become defensive.

When they understand that the exercise exists to improve the organization, collaboration becomes much easier.

Psychological Safety Matters in Cybersecurity

Psychological safety is not normally the first concept people associate with offensive security.

Yet it can be extremely important.

Security professionals need to be able to admit that a detection failed.

They need to acknowledge that a log source was missing.

They need to say that an investigation took too long.

They need to recognize that an attacker found a path nobody expected.

A culture that punishes those admissions can encourage people to hide problems.

A culture that rewards learning can expose them early.

Bringing Red and Blue Teams Together

Physical Proximity Changes the Relationship

One of

That may sound like an organizational detail, but it can have a major impact.

Teams that rarely interact can easily develop stereotypes about each other.

Red teams may view defenders as overly cautious.

Blue teams may view offensive testers as disruptive.

Regular interaction can replace those assumptions with professional familiarity.

Collaboration Becomes Part of Daily Operations

When offensive and defensive professionals work near one another, communication becomes easier.

A question does not necessarily require a formal meeting.

A detection engineer can discuss an observation with an offensive operator.

An attacker can explain why a particular technique was chosen.

A defender can point out exactly where telemetry disappeared.

The exercise becomes a conversation rather than a postmortem.

The “Trusted Agent” Model

Observers Enter the Offensive Environment

Walmart’s trusted-agent approach introduces defensive personnel into the red team’s operating environment during adversarial simulations.

For example, members of the blue team can observe the red team while an exercise is happening.

They are not necessarily there to stop the attack.

Their role is to understand what is happening and evaluate whether the organization can actually see the activity.

Telemetry Becomes Part of the Experiment

This creates an important opportunity.

While the red team performs offensive activity, trusted observers can examine telemetry in real time.

Are endpoint events being generated?

Are authentication records available?

Are network connections visible?

Are security alerts firing?

Can analysts distinguish malicious activity from legitimate administrative behavior?

These questions are much easier to answer when defenders can correlate offensive actions with the evidence those actions produce.

Protecting the Business While Testing It

Realistic Does Not Mean Reckless

One of the most important advantages of having trusted observers involved is operational safety.

Adversarial testing can create risks.

A poorly designed action can affect production systems, generate unexpected load, trigger automated responses, or accidentally disrupt business operations.

The trusted-agent model provides another layer of control.

Defensive observers can help ensure that the exercise remains within agreed boundaries.

The Goal Is Controlled Realism

The best security exercises simulate realistic attacks without becoming uncontrolled incidents.

That balance is difficult.

An exercise that is too artificial teaches very little.

An exercise that is too aggressive can create unnecessary operational risk.

Trusted agents help bridge that gap.

Why Real-Time Feedback Changes Everything

The Old Model Stops at the Report

In a conventional penetration test, the offensive team may conduct an operation, document its findings, and eventually deliver a report.

That report can be valuable.

But it creates a delay between attack and learning.

The defenders may not see exactly what the attackers did.

They may only see a summary.

Walmart Turns Feedback Into a Loop

The trusted-agent approach changes that sequence.

The red team performs an action.

The blue team observes it.

The defenders evaluate their visibility.

The red team learns what was detected.

The defenders learn what was missed.

The offensive team adapts.

The defensive team improves.

Then the cycle repeats.

That feedback loop can produce continuous improvement rather than a one-time assessment.

Red Teams Get Better Too

Offensive Security Is Not Just About Breaking Things

It is easy to assume that only the blue team benefits from this model.

That is not necessarily true.

Red teams can also learn from defensive feedback.

If an offensive technique is immediately detected because of a specific telemetry source, the red team gains a better understanding of how defenders operate.

That knowledge can make subsequent simulations more realistic.

Attackers Learn to Adapt

When defenders improve, attackers need to adapt.

The red team must consider alternative paths, different techniques, and ways of reducing detection opportunities.

That creates a natural training environment.

Instead of repeatedly executing the same playbook, offensive professionals are encouraged to evolve.

Blue Teams Get Better Too

Defenders See Attacks From the Inside

Blue teams benefit from seeing exactly how an adversary thinks.

A security analyst may know that a certain attack technique exists.

Seeing that technique executed against the organization can be very different.

They can observe the sequence of actions, identify the relevant logs, understand the attacker’s objectives, and determine where detection should have occurred.

Detection Engineering Becomes More Practical

This can directly improve detection engineering.

Rather than creating rules based only on theoretical indicators, analysts can build detections around observed behavior.

The difference matters.

Real attacks rarely follow perfect textbook patterns.

Attackers adapt to the environment.

Security teams must do the same.

Purple Teaming as a Continuous Learning System

More Than a Security Exercise

Purple teaming is often described as collaboration between offensive and defensive teams.

Walmart’s approach takes that idea further.

The exercise becomes a learning system where each side improves because of the other’s actions.

That is fundamentally different from treating purple teaming as simply another cybersecurity assessment.

Tabletop Exercises Fit the Same Philosophy

The same concept can apply beyond technical adversary emulation.

Tabletop exercises can bring security operations, engineering, legal, communications, executives, and business teams into the same conversation.

Everyone learns where the

The objective is not to identify who made a mistake.

The objective is to identify what needs to change.

Adversary Emulation Creates Realistic Pressure

Simulating the Enemy

Adversary emulation attempts to reproduce the behaviors of real-world threat actors rather than simply scanning for vulnerabilities.

That makes it particularly useful for mature security organizations.

Instead of asking, “Do we have this vulnerability?” teams can ask, “Could an attacker use this technique against us, and would we recognize it?”

That is a much harder question.

The Attack Chain Matters

A modern attack rarely consists of one isolated action.

It can involve initial access, credential theft, privilege escalation, lateral movement, persistence, discovery, data access, and exfiltration.

Purple teaming allows organizations to test detection and response across that entire chain.

Trust Is the Hidden Technology

Security Tools Cannot Solve Culture Problems

Modern security operations centers have access to enormous amounts of technology.

EDR platforms.

SIEM systems.

Cloud security tools.

Identity monitoring.

Threat intelligence.

Network detection.

Automated response.

Artificial intelligence.

Yet technology alone cannot guarantee effective defense.

If teams do not trust one another, important information may remain isolated.

If employees fear admitting mistakes, vulnerabilities can remain hidden.

If security exercises become political competitions, learning slows down.

Trust becomes part of the security architecture.

Better Retention Through Continuous Learning

Security Professionals Need Growth

Cybersecurity is a high-pressure field.

Professionals can burn out when every incident feels like a crisis and every exercise feels like an examination.

Walmart’s collaborative model provides another dynamic.

Both red and blue team members can continuously learn from each other.

That creates opportunities for professional development without requiring people to leave their current roles.

Learning Can Become a Retention Strategy

Employees who feel that they are developing their skills are more likely to see long-term value in their work.

That makes collaborative purple teaming potentially useful beyond security outcomes.

It can become part of talent strategy.

The Business Value of Purple Teaming

Security Must Serve the Organization

ODells philosophy extends beyond technical security.

The larger objective is to make security an enabler for the business.

A security program that constantly creates friction can eventually become an obstacle.

But a security organization that understands business operations can make smarter decisions about risk.

Security Exercises Should Improve Business Resilience

The best outcome of a purple-team exercise is not a beautiful report.

It is a more resilient organization.

That means faster detection.

Better response.

More reliable telemetry.

Clearer escalation procedures.

Better communication.

Reduced operational risk.

And stronger confidence when a genuine incident eventually occurs.

Deep Analysis

Turning Purple Teaming Into an Engineering Feedback Loop

Walmart’s model can be understood as a continuous feedback architecture rather than a traditional security exercise.

The basic cycle looks like this:

Attack → Observe → Detect → Analyze → Adapt → Attack Again

That cycle can be integrated directly into security engineering.

Check Security Telemetry

Security teams can begin by verifying whether relevant logs exist.

For Linux environments, administrators can inspect authentication activity with:

sudo journalctl --since "1 hour ago"

They can review recent SSH authentication events with:

sudo journalctl -u ssh --since "1 hour ago"

The exact service name may differ between distributions.

Examine Authentication Events

Identity attacks are central to many modern intrusion scenarios.

Teams can review recent authentication records with:

last

On systems using standard authentication logs:

sudo grep -i "failed" /var/log/auth.log

These commands are useful for controlled defensive validation, not for attacking systems.

Inspect Active Network Connections

Defenders can also examine current connections:

ss -tulpen

This helps identify listening services and active network sockets.

During an authorized exercise, defenders can compare expected connections with the activity generated by the red team.

Review Running Processes

A basic process inventory can be obtained with:

ps aux

For more focused investigation:

ps aux --sort=-%cpu | head

The objective is not simply to find a suspicious process.

The more important question is whether the

Search Security Logs

Teams can search logs for specific events:

sudo journalctl | grep -i "authentication"

In larger environments, centralized logging is preferable because individual hosts rarely provide the complete picture.

Validate Detection Coverage

A mature purple-team program should map offensive actions to expected telemetry.

For every simulated technique, teams should ask:

What happened?

What evidence did it generate?

Where was that evidence stored?

Did our detection platform receive it?

Did an alert fire?

How quickly did an analyst notice it?

Could the activity be investigated afterward?

Measure Detection Instead of Assuming It

Security teams should avoid assuming that a control works simply because it is deployed.

A security product may be installed while producing incomplete telemetry.

A detection rule may exist while failing against a slightly modified attack.

A log source may exist while retention is too short for effective investigation.

Purple teaming exposes those gaps.

Measure Mean Time to Detect

Organizations can track metrics such as:

MTTD: Mean Time to Detect

This measures how long it takes for suspicious activity to become known.

They can also measure:

MTTR: Mean Time to Respond

This measures how quickly the organization takes meaningful response action.

These metrics become more useful when measured against realistic simulations.

Test Detection Logic

Detection teams can use controlled indicators to validate whether monitoring systems respond as expected.

For example, defenders can search their centralized logging platform for known test events rather than relying entirely on production incidents.

A simple local search might look like:

sudo journalctl --since today | grep -Ei "failed|denied|authentication"

The exact queries should be adapted to the organization’s logging architecture.

Build an Attack-to-Detection Matrix

A mature purple-team program can maintain a matrix containing:

Offensive Action Expected Telemetry Detection Alert Investigation Result
Authentication anomaly Identity logs Rule A Yes/No Yes/No Improve
Suspicious process EDR telemetry Rule B Yes/No Yes/No Improve
Unusual network connection Network logs Rule C Yes/No Yes/No Improve
Privilege change Identity/system logs Rule D Yes/No Yes/No Improve

This transforms a security exercise into measurable engineering work.

The Biggest Lesson

The most important lesson from

It is that security improvement accelerates when information moves quickly between people.

The red team understands offensive behavior.

The blue team understands detection.

Security engineering understands infrastructure.

Business teams understand operational consequences.

Bringing those perspectives together creates a stronger security system than allowing each group to optimize independently.

What Undercode Say:

  1. Purple Teaming Is More Valuable When It Is Continuous

A single annual security exercise can expose weaknesses, but continuous collaboration has the potential to turn those weaknesses into an ongoing improvement program.

2. Competition Can Distort Security Results

If teams care more about winning than learning, they may optimize for the exercise rather than the organization’s actual security.

3. Trust Can Improve Technical Outcomes

Trust is not merely a cultural benefit. It can directly influence how quickly information moves during security testing.

4. Red Teams Need Defensive Feedback

Offensive operators become stronger when they understand what defenders can see and how detection mechanisms respond.

5. Blue Teams Need Offensive Context

Defenders can build better detections when they understand how an attack actually unfolds rather than relying exclusively on theoretical models.

6. Physical Proximity Is Surprisingly Powerful

Putting teams in the same environment can reduce communication barriers that formal organizational structures sometimes create.

  1. Trusted Agents Create a Useful Middle Ground

They can preserve the realism of adversarial testing while reducing unnecessary operational risk.

8. Telemetry Is the Foundation of Detection

An organization cannot reliably detect activity that it cannot observe.

9. Logging Alone Is Not Enough

A system can generate millions of events and still fail to provide useful security visibility.

10. Context Makes Security Data Valuable

Defenders need to understand what an event means, not simply that an event occurred.

11. Real-Time Observation Reduces Learning Delays

The faster defenders understand an offensive action, the faster they can improve their defenses.

12. Security Exercises Should Produce Engineering Tasks

Every meaningful discovery should eventually become an actionable improvement.

  1. Detection Gaps Should Be Treated as Engineering Problems

A missed attack should trigger investigation rather than blame.

14. Psychological Safety Can Encourage Better Reporting

Employees are more likely to expose weaknesses when they believe the purpose is improvement rather than punishment.

  1. Security Leaders Must Manage Culture as Carefully as Technology

Even the best security tools can underperform inside a dysfunctional team structure.

  1. Purple Teams Can Help Break Organizational Silos

Security departments often contain specialists who rarely see the full attack lifecycle.

17. Collaboration Improves Institutional Knowledge

Every exercise can transfer knowledge between offensive and defensive specialists.

18. Security Talent Benefits From Cross-Team Exposure

People develop broader skills when they understand how other security disciplines operate.

19. Retention Is an Important Secondary Benefit

Employees who continuously learn may have stronger reasons to remain engaged with the organization.

  1. Realistic Exercises Are Better Than Theoretical Exercises

Simulating realistic behavior reveals problems that checklists can miss.

21. Operational Safety Must Remain a Priority

Adversarial testing should never become an excuse for reckless disruption.

  1. Trusted Agents Help Balance Realism and Safety

That makes their role particularly valuable in large, complex environments.

23.

A retailer operating at enormous scale cannot treat security exercises as isolated laboratory experiments.

24. Business Context Matters

A technically successful attack simulation can still be a poor exercise if it ignores operational consequences.

25. Security Must Understand the Business

The best defensive decisions balance security risk with operational realities.

  1. Red and Blue Teams Should Share Success

When a detection improves because of an offensive exercise, both teams contributed to the outcome.

27. Failure Can Become a Success

Discovering a weakness during a controlled exercise is far better than discovering it during a real breach.

28. Reports Should Start Conversations

A security report should not be the final destination of an exercise.

29. Continuous Feedback Is the Real Advantage

The most powerful aspect of

30. Detection Engineering Should Be Evidence Driven

Real observations provide better evidence than assumptions.

31. Security Metrics Need Context

MTTD and MTTR are useful, but they should be connected to realistic attack scenarios.

32. Security Teams Need Shared Objectives

A common mission can reduce destructive internal competition.

33. The “Enemy” Should Be the Risk

Red teams and blue teams are not truly enemies.

The real adversary is the threat actor outside the organization.

  1. Collaboration Can Make Both Sides More Adversarial

Paradoxically, better cooperation internally can create stronger adversarial capabilities externally.

  1. Mature Security Programs Should Repeat the Cycle

Attack, observe, detect, analyze, improve, and attack again.

36. Purple Teaming Can Become Security Training

Every exercise can serve as a practical lesson for analysts, engineers, and offensive specialists.

37. Culture Can Become a Security Control

A team that communicates effectively can respond to threats more effectively.

38.

The approach requires trust, discipline, leadership, and clear boundaries.

39. Other Enterprises Can Learn From It

Organizations do not necessarily need

  1. The Future of Purple Teaming Is Collaborative

The strongest security organizations may increasingly treat offensive and defensive operations as two sides of the same learning system.

✅ Walmart Uses a Collaborative Purple-Team Philosophy

The article accurately describes Jason O’Dell’s emphasis on trust, psychological safety, and organizational improvement rather than treating red-versus-blue exercises as simple competitions.

✅ Red and Blue Teams Can Work Together During Exercises

The described trusted-agent model involves blue-team personnel observing red-team activity and checking telemetry, detections, and operational safety while the exercise is underway.

✅ The Approach Can Benefit Both Teams

The central claim that offensive and defensive professionals can improve through iterative feedback is technically sound. A well-designed purple-team exercise can strengthen detection, response, attack simulation, and institutional knowledge at the same time.

⚠️ The Model Still Requires Strong Governance

Collaboration does not eliminate risk. Production boundaries, authorization, scope, emergency procedures, and separation of duties remain essential during adversarial testing.

Prediction

(+1) Purple Teaming Will Become More Collaborative

As security organizations move away from isolated penetration tests, more enterprises are likely to integrate red and blue teams into continuous security validation programs.

(+1) Real-Time Detection Validation Will Grow

Security teams will increasingly want to know whether their telemetry and detections work during an attack simulation rather than discovering weaknesses weeks later in a report.

(+1) Trusted-Agent Models Could Spread

The idea of allowing selected defensive personnel to observe offensive operations while maintaining strict boundaries could become increasingly attractive to large enterprises.

(+1) Security Culture Will Become a Competitive Advantage

Organizations that successfully combine technical expertise with psychological safety may be better positioned to retain talent and respond to sophisticated attacks.

(+1) Purple Teaming Will Move Closer to Security Engineering

The future is unlikely to be defined by occasional red-team reports alone. Continuous validation, measurable detection coverage, automated testing, and rapid remediation will increasingly connect offensive security directly with everyday engineering.

(-1) Poorly Managed Collaboration Could Backfire

If organizations copy the model without establishing trust, authorization, operational boundaries, and clear responsibilities, collaboration could create confusion rather than resilience.

Final Perspective: The Real Enemy Is Not the Other Team

Walmart’s approach highlights a fundamental truth about modern cybersecurity: red teams and blue teams should challenge each other without becoming enemies.

The red team exists to expose weaknesses.

The blue team exists to find and contain threats.

Security engineering exists to strengthen the underlying systems.

Leadership exists to make sure all of those efforts serve the business.

When those groups operate independently, organizations can end up with disconnected expertise. When they work together under a trusted-agent model, every attack simulation can become a lesson, every missed detection can become an engineering improvement, and every defensive success can make the next offensive test more sophisticated.

That is the deeper value of

Purple teaming is not really about deciding who wins.

It is about making sure the organization wins when the real attacker eventually arrives.

▶️ Related Video (86% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.reddit.com/r/AskReddit
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube