Penetration testing tells you where the vulnerabilities and misconfigurations are. Purple teaming asks a different question: when an attacker is actually operating inside your environment, what can your tools see, and what slips right past them? Sarah Hume has built her career around that second question.
Sarah leads the Purple Team program at Security Risk Advisors. Her path into cybersecurity started with a single week at a summer camp at Dakota State University, which her dad talked her into against her wishes and which ended up changing everything. She went on to study cybersecurity at Penn State and began her career in network, physical, and OT/ICS penetration testing before moving into purple teaming as a red operator and eventually leading the practice.
In this episode, Sarah breaks down how her team runs purple teams at scale, roughly 200 a year, working through TTPs across the full attack chain alongside a client's blue team. She explains why she favors smart automation over fully automated testing, how her team builds detections that hold up instead of breaking on a single command string or file hash, and why remediation only matters if it is actionable. She also covers living off the land binaries, her grounded take on AI in offensive testing, and real advice for breaking into the field, from home labs and certifications to taking down imposter syndrome and building the communication skills that separate a good tester from a useful one.
=========================
Connect with Sarah Hume:LinkedIn: https://www.linkedin.com/in/sarah-hume1 =========================
Connect with your host, Phillip Wylie:LinkedIn: https://linkedin.com/in/phillipwylieX: https://x.com/PhillipWylieInstagram: https://www.instagram.com/phillipwylie
=========================
Sponsored by Suzu Labs
=========================
All the ways to connect with @Suzulabs
https://suzulabs.com
https://x.com/suzulabs
https://www.linkedin.com/company/suzu-labs/