Purple Teaming with OWASP PurpleTeam

Oct 27, 2021 · Christchurch, New Zealand

PurpleTeam is a security regression testing CLI and SaaS targeting Web applications and APIs.
The CLI is specifically targeted at sitting within your build pipelines but can also be run manually.
The SaaS that does the security testing of your applications and/or APIs can be deployed anywhere.

Kim will briefly discuss the three year journey that has brought purpleteam from a proof of concept to where it is now.

An overview of the NodeJS micro-services with a pluggable tester architecture will be provided. Additional Testers can be contributed by the community (that's you!).

## Why would I want it in my build pipelines?

In this section Kim will discus the problem that purpleteam solves,
along with the cost savings of finding and fixing your application security defects early (as you're introducing them) as opposed to late (weeks months later with external penetration testing) or not at all.

## OK, I want it, how do we/I set it up?

Kim will walk you through all of the components and how to get them set-up and configured

## Great, but what do the work flows look like?

Let's walk through the different ways purpleteam can be run and utilised, such as:

* Running purpleteam standalone (with UI)
* Running purpleteam from within your pipelines as a spawned sub process (headless: without UI)
* Running all of the purpleteam components, including debugging each and every one of them if and when the need arises

There'll be pizza and drinks from 5.30 with the talk to start around 6pm. Thanks to Media Suite for the food & beers, and thanks to Web Tools for the use of The Loft space.

Kim also has some sweet swag for us ;)

p.s. Media Suite is hiring - https://careers.mediasuite.co.nz/jobs

