Atomic tests on one side, detections on the other, one key

Purple teaming is supposed to be a conversation between attack and defence. If the model will only write the detection, you are not running an exercise, you are running a documentation generator.

Detection engineers and red teamers who share a calendar and a scope, usually inside one company.

Why the mainstream APIs fail here

Asking for the attack step is refused. Asking for the detection is allowed. The two halves of the exercise no longer share a model, so they no longer share assumptions, and the gap you meant to find is the one the safety filter introduced.

How Redline is used for this

One key for the exercise window. Generate the atomic step, the expected telemetry, and the detection in the same thread. Cap it at the cost of the week. Revoke it on Friday.

A working loop

  1. Pick a TTP from the backlog.
  2. Ask for the attack, the log line, and the rule, in that order.
  3. Ship the rule. Delete the key.

Prompts are not stored. A signed receipt of the hash comes back on every call, so you can prove later what Redline logged. Details are on the privacy page. Per-model prices are on /models and the pricing model is on /pricing.

Related