Ransomware response — a branching 60-minute drill
Interactive scenario built from real IR playbooks I've worked from. Four decision points — detect, identify, contain, recover — with three branching choices each. Wrong call and the blast radius grows, right call and you close the incident with the postmortem intact.
Decision points
4
Branch outcomes
12
Scoring range
-9 → +12
Replay value
High
Take a live ransomware page from first EDR ping to closed incident. Every decision you make changes what happens next.
- 01 · First signal
- 02 · Identify the strain
- 03 · Widen containment
- 04 · Recover or negotiate
EDR just fired: vssadmin delete shadows /all on SRV-FS01, and 40+ endpoints are opening thousands of files per minute. Backup jobs paused. Nobody's on-call except you.
- Alert source
- Defender XDR · Ransomware canary
- Impacted hosts
- 43 (files) · 1 (vssadmin)
- Domain admin sessions
- 2 active — svc_backup, j.admin
Your call, operator ↓
Tools
- Defender XDR
- Sentinel
- Live Response
- MISP / VT
- Immutable Veeam backups
Platforms
- Windows Server
- Entra ID
- Palo Alto NGFW
- 01
Modeled real BlackFang-family behavior — vssadmin canary, JA3-fingerprinted C2, admin-token abuse.
- 02
Each stage exposes real IR levers (isolation, JA3 block, token revocation, immutable restore) with realistic trade-offs.
- 03
Scorecard grades containment speed vs. business impact so you can see the shape of your own decisions.
Interactive lab — your call at every branch, real scorecard at the end, with decision trace for review.
- Network isolation beats process-kill — persistence hooks respawn the process, but not the socket.
- Identity revocation is a first-class containment lever, not a cleanup step.
- Immutable backups make 'don't pay' a real option instead of a slogan.
Next case · PHISH-001
Phishing kit dissection — anatomy of a credential harvester
Open →
