The Cybersecurity Color Wheel


The Core Model (Primary Roles)


1 Red Team (Offense)

- Focuses on simulated attacks, penetration testing, and ethical hacking to identify vulnerabilities before real attackers do.


2 Blue Team (Defense)

- Focuses on active defense, continuous monitoring, threat detection, and incident response (SOC).


3 Yellow Team (Build & Architecture)

- Focuses on software engineering, system design, and infrastructure development.

The Extended Framework (Hybrid Roles)


4 Purple Team (Red + Blue)

- Fosters collaboration between offensive and defensive teams to improve detection mechanisms and validate security controls in real time.


5 Green Team (Blue + Yellow)

- Integrates defense directly into software development (DevSecOps) to ensure infrastructure is built securely by design.


6 Orange Team (Red + Yellow)

- Focuses on secure coding education, using offensive techniques to train developers on how attackers think.


7 White Team (Governance & Oversight)

- Manages policy, compliance, logistics, and acts as the impartial referee/organizer for security exercises.

Additional Specialist Teams


*8 Black Team

- Handles physical security assessment, facility lockpicking, and real-world social engineering scenarios.


*9 Gold Team

- Comprises C-level executive management, legal advisors, and PR representatives responsible for strategic crisis management.


*10 Brown Team

- Focuses on day-to-day operations, systems administration, and patching infrastructure to keep networks running cleanly.

made by P.E