โšก
SURPRISE LIVE INJECT
Surprise Event Detonated
Incident description details.
TTX TOOLKIT Ransomware Tabletop Exercise & Defense Control
SEV-1 LIVE
Enterprise Cyber Incident Crisis Drill

Loan Operations Ransomware & Data Exfiltration Tabletop Exercise

An end-to-end tactical simulation of an off-site loan officer targeted by social engineering via Telegram. The exercise walks through initial payload execution, internal network reconnection, C2 exfiltration of 5.2GB customer data, active file encryption, and multi-tier SOC & Crisis Command response aligned with formal RACI authority matrices.

๐Ÿ“ฅ Download PPTX Deck
6
Exercise Injects
11
Defined Roles
< 15 min
L1 SLA Escalation
72 hrs
Extortion Window
100%
Containment Target
TTX Core Objectives & KPIs
  • Triage Velocity: Validate SOC L1 triage accuracy & escalation to L2 in <15 minutes.
  • 4-Pillar Containment: Execute synchronized host isolation, AD revocation, firewall C2 blocks, and storage share locks.
  • Crisis Command: Establish Incident WAR Room bridge within <30 minutes and maintain 30-min executive cadence.
  • Business Recovery: Verify clean immutable backup snapshot integrity and obtain CIO/Business sign-off.
  • Regulatory Compliance: Comply with mandatory National Bank of Cambodia (NBC) and CamCERT statutory breach reporting within 24 hours.
RACI Authority Matrix Boundaries

Strict containment boundaries distinguish technical responders from operational command and executive authority:

  • SOC L1/L2 Technical: Triage & Playbook Execution (<15m SLA, endpoint isolation).
  • SOC Lead / L3: Senior forensics, threat hunting, and RCA co-authority.
  • SOC Manager: Overall operational command, SEV-1 declaration, and containment authorization.
  • Incident Communicator: WAR Room moderation & executive notices (NO containment authority).
  • CIO & CISO: Final production recovery sign-off, Board briefing, and regulatory governance.
High-Level Attack Lifecycle & Technical Flow Interactive Pipeline
flowchart LR A["๐ŸŽฃ Telegram Phish"] --> B["๐Ÿฆ  Trojan Execution"] B --> C["๐Ÿ”Œ Connect Corporate LAN"] C --> D["๐Ÿ“ค 5.2GB Data Exfiltration"] D --> E["๐Ÿ”’ Active Ransomware Encrypt"] E --> F["๐Ÿšจ EDR SEV-1 Alert"] F --> G["๐Ÿš’ Containment & Recovery"]
Step 1
Telegram Phish
Off-site Payload
Step 2
Trojan Launch
Silent DLL Injection
Step 3
LAN Recon
Kerberos Token Abuse
Step 4
Data Exfil
HTTPS C2 Tunnel
Step 5
Encryption
5 BTC Ransom Note
Step 6
Recovery
Immutable Snapshot
Threat Evidence & Forensic Mockups Vault
Telegram Phishing Archive
Inject 1 ยท Initial Access
Telegram Phishing Archive
Archive: Customer_Documents_2026.zip | Disguised Executable: Signed_Agreement.pdf.exe
Adversary lures senior loan officer Sok Dara via Telegram using fake applicant account '@chanthy_loan_applicant', delivering a passwordless zip containing a disguised Trojan payload.
Fake Adobe Acrobat Reader Error
Inject 1 ยท Deception & Persistence
Fake Adobe Acrobat Reader Error
Error: 0x80070005 Access Denied | Process: explorer.exe -> svchost.exe DLL Injection
Social engineering decoy error window displayed to the user when opening the disguised PDF. Behind the error popup, silent registry run keys and C2 beaconing are established under standard user context.
Corporate Network Topology & Threat Map
Inject 2 ยท LAN Reconnaissance
Corporate Network Topology & Threat Map
Domain: ADMFI.LOCAL | DC: ADMFI-DC01 | File Server: \\ADMFI-FS01\Loan_Share$
Architectural topology of ADMFI Microfinance network, showing VLAN segmentation, Active Directory Domain Services, Core Banking connections, and file share pathways targeted during lateral recon.
6-Stage Ransomware Attack Kill-Chain
Lifecycle ยท End-to-End Progression
6-Stage Ransomware Attack Kill-Chain
MITRE ATT&CK: T1566.002 -> T1059 -> T1078 -> T1048 -> T1486 -> T1490
High-level visual diagram detailing the sequential kill-chain stages: Offsite Phishing -> Trojan Execution -> LAN Connection -> SMB Data Exfiltration -> Ransomware Detonation -> Containment & Recovery.
QRadar SIEM Anomaly & 5.2GB Egress Dashboard
Inject 3 ยท Exfiltration Detection
QRadar SIEM Anomaly & 5.2GB Egress Dashboard
Alert: Outbound HTTPS Spike | Ext. IP: 185.220.101.45:443 | Volume: 5.2 GB Compressed
Security Information & Event Management (SIEM) dashboard correlating abnormal outbound traffic volume with simultaneous elevated SMB read requests on corporate file shares.
CrowdStrike Falcon EDR Critical SEV-1 Alert
Inject 4 ยท Ransomware Detection
CrowdStrike Falcon EDR Critical SEV-1 Alert
Severity: SEV-1 CRITICAL | Host: LOAN-LAPTOP-042 | Behavior: Rapid Mass File Encryption (50 f/s)
Endpoint Detection and Response (EDR) alert console detecting active mass encryption patterns, shadow copy deletion commands, and triggering immediate behavioral prevention alerts.
ADMFI_LOCKED Ransomware Extortion Note
Inject 4 ยท Impact & Extortion
ADMFI_LOCKED Ransomware Extortion Note
Demand: $50,000 USD (5.0 BTC / USDT) | Deadline: 72 Hours | Extension: .ADMFI_LOCKED
Desktop lock screen and HOW_TO_DECRYPT_ADMFI.txt note demanding $50,000 in cryptocurrency within 72 hours under threat of publishing customer land titles, ID cards, and loan agreements on the dark web.
Incident Command WAR Room Active Bridge
Inject 5 ยท Crisis Escalation
Incident Command WAR Room Active Bridge
Bridge: MS Teams 'TTX Incident Command' | Commander: SOC Manager | Status: Active SEV-1
Virtual incident command operations center showing real-time containment workstream tracking, executive notification timestamps, and decision logs.
Incident Command RACI Authority Matrix
Governance ยท Authority Boundaries
Incident Command RACI Authority Matrix
Framework: RACI Matrix (Responsible, Accountable, Consulted, Informed)
Clear organizational matrix establishing containment decision boundaries between SOC Analysts (technical), SOC Manager (operational), Business Owners (production), and CIO/CISO (executive).
Technical WAR Room Network Architecture
Inject 5 ยท Bridge Architecture
Technical WAR Room Network Architecture
Channels: Secure OOB Comms + Primary Bridge + Executive Briefing Channel
Infrastructure blueprint for isolated out-of-band communication channels, SOC triage workbenches, and secure evidence storage vaults during a live cyber incident.
4 Pillars of Cyber Containment Execution
Inject 5 ยท Containment Execution
4 Pillars of Cyber Containment Execution
Pillars: 1. Endpoint Isolation | 2. Identity Revocation | 3. Network Block | 4. Share Read-Only
Synchronized 4-pillar containment framework ensuring that compromised endpoints, user credentials, network C2 routes, and storage shares are simultaneously severed to stop lateral spread.
'What If / Then If' Branching Decision Tree
Facilitator ยท Branching Matrix
'What If / Then If' Branching Decision Tree
Paths: Branch A (Best Case) | Branch B (Default TTX) | Branch C (Catastrophic Worst)
Dynamic decision roadmap guiding facilitators on how participant choices pivot the scenario trajectory across detection, containment, backup recovery, and regulatory reporting.
Veeam Immutable Snapshot Backup Restoration Pipeline
Inject 6 ยท Eradication & Recovery
Veeam Immutable Snapshot Backup Restoration Pipeline
Snapshot: T-6 Hours Clean (Air-Gapped Immutable) | Hash: SHA256 Verified Clean
Technical workflow for scanning air-gapped immutable backup repositories, verifying snapshot cleanliness against known attacker IOCs, and restoring loan file shares with zero data loss.
Disaster Recovery Portal 98% Clean Verification
Inject 6 ยท Business Restoration
Disaster Recovery Portal 98% Clean Verification
Recovery Status: 98% Restored | Integrity: 100% Passed | Sign-off: CIO & Asset Owner Approved
Disaster Recovery management console confirming completed file restoration, customer database consistency validation, and business owner operational sign-off prior to production reactivation.
Ransom Countdown: 71:59:45
SLA Window: 15:00
Active Role:
SOC L1 Sentinel
Target: ADMFI Microfinance Plc.
STAGE 01 ยท ORIENTATION ADMFI Headquarters ยท Executive Boardroom Internal HQ / Strategic
๐ŸŽฏ Attack Stage: Exercise Orientation & Threat Landscape
Defender Objective: Align 11 RACI roles & establish SEV-1 incident baseline.
STAGE 01 / 15
SIMULATION ORIENTATION โ€ข SLIDE 01
๐Ÿ›ก๏ธ Ransomware Incident Tabletop Exercise (TTX)
ADMFI Microfinance Plc. ยท Phnom Penh HQ ยท August 2026
๐Ÿšจ CRISIS EXERCISE SCENARIO
CRITICAL SEV-1 DRILL
Adversary Threat Group: Ransomus
Adversaries targeted off-site Loan Officers via Telegram phishing archives. Ransomware detonated on corporate file shares (\\\\ADMFI-FS01\\Loan_Share$) and extorted $50,000 USD in crypto with customer data exfiltration.
MITRE T1566.002 Phishing MITRE T1486 Data Encrypted MITRE T1048 Exfiltration

๐ŸŽฏ Core Exercise Objectives:

  • Validate SOC L1 alert triage & escalation SLA <15 minutes
  • Execute 4-pillar synchronized containment (Host, AD, NGFW, Storage)
  • Establish Incident Command WAR Room within <30 minutes
  • Navigate dynamic live Plot Twists and branching injects
  • Practice mandatory regulatory notification (National Bank of Cambodia & CamCERT)
โŒจ๏ธ Arrow keys / Space to navigate  |  F = Facilitator Panel  |  Click images to inspect
Incident Command War Room
๐Ÿ–ผ๏ธ Incident Command WAR Room DashboardCLICK TO INSPECT
SCENARIO PHASE 1 โ€ข INITIAL ACCESS
๐Ÿ“ฑ Telegram Phishing & Off-site Compromise
Simulated Time: 09:15 AM ยท Off-site Coffee Shop ยท Host: LOAN-LAPTOP-042 ยท User: sok.dara
๐Ÿ“ฑ TELEGRAM DESKTOP HOOK
UNSANCTIONED INGRESS 09:12:18 AM
Suspicious Archive Received via Direct Message
Senior Loan Officer Sok Dara received compressed archive Customer_Documents_2026.zip from apparent client profile @chanthy_loan_applicant_2026 containing disguised executable Customer_Agreement_2026.pdf.exe.
Target HostLOAN-LAPTOP-042
User Accountsok.dara
Network ZoneOff-site / Public Wi-Fi
Payload NameSigned_Agreement.pdf.exe
T1566.002 Spearphishing Link T1204.002 User Execution
[09:12:01] TG_IN: Direct message received from @chanthy_loan_applicant_2026
[09:12:05] SAVE: Customer_Documents_2026.zip written to C:\\Users\\sok.dara\\Downloads\\
[09:12:18] EXTRACT: Archive unpacked containing Signed_Agreement.pdf.exe (42.1 MB)
[09:12:30] EXEC: User double-clicked disguised PDF executable under standard user context
Telegram Phishing Payload
๐Ÿ“ธ Telegram Chat Payload AttachmentDISGUISED PDF.EXE
SCENARIO PHASE 2 โ€ข PERSISTENCE & C2 ACTIVATION
โŒ Fake Adobe Error & Covert C2 Beaconing
Trojan displays fake format error 0x80070005 while dropping persistence DLL into svchost.exe
Fake Adobe Error
๐Ÿ“ธ Fake Adobe Acrobat Format Error 0x80070005STEALTH POPUP
๐Ÿ›ก๏ธ ENDPOINT BEHAVIORAL MONITOR
MEDIUM ANOMALY 09:12:35 AM
Silent DLL Injection & Registry Run Key Written
Trojan launched fake Adobe dialog to deceive user, while injecting enc_loader.dll into svchost.exe and establishing persistent registry key. Covert HTTPS beacon initiated to external C2 185.220.101.45:443.
Process LineageSigned_Agreement.exe โ†’ svchost.exe
Registry KeyHKCU\\..\\Run\\AdobeUpdater
C2 Callback185.220.101.45:443
Beacon Interval60s Jittered
T1055 Process Injection T1547.001 Registry Run Keys T1071.001 Web Protocols
[09:12:32] REG_ADD: HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\AdobeUpdater
[09:12:35] C2_TLS: Handshake established with 185.220.101.45:443 (CN: mal-c2.admfi-verify.com)
[09:12:40] BEACON: Payload dormant โ€” awaiting corporate domain ADMFI.LOCAL signal
[09:12:41] USER: sok.dara assumes corrupted PDF and continues work
๐Ÿ”ด LIVE INJECT 01 โ€ข LAN RECONNECTION & RECONNAISSANCE
๐Ÿข Infected Laptop Connects to Corporate LAN
Simulated Time: 02:00 PM ยท HQ Office LAN (10.15.34.120) ยท Domain: ADMFI.LOCAL
๐Ÿข ACTIVE DIRECTORY / SIEM CORRELATION
HIGH SEV-2 02:00:12 PM
Abnormal Kerberos TGS Requests & SMB Share Enumeration
Host LOAN-LAPTOP-042 plugged into corporate LAN. Dormant malware detected domain controller AD-DC01, queried AD for file shares using user sok.dara's Kerberos token, and discovered \\\\ADMFI-FS01\\Loan_Share$ (12,450 files).
Source IP10.15.34.120
Target Share\\\\ADMFI-FS01\\Loan_Share$
Kerberos TGS48 queries / sec
SLA Escalate< 15 Minutes
T1087 Account Discovery T1558.003 Kerberoasting T1135 Network Share Discovery
โšก Choose Branch Based on Team Response:
โœ… Branch A: Rapid Host Isolation
SOC L2 issues EDR isolation within 5 minutes. Ransomware aborted mid-enumeration. Only 5 local files on Sok Dara's laptop encrypted. Shared drives remain 100% clean. Workstation reimaged cleanly in 2 hours.
โš ๏ธ Branch B: Delayed Containment (Scenario Continues)
SOC L1/L2 hesitates awaiting Business Owner permission for 30+ minutes. Attacker gains full access to file shares and begins staging exfiltration. โ†’ Proceed to Inject 02.
๐Ÿ”ด Branch C: Domain-Wide Privilege Escalation
Attacker dumps LSASS memory, harvests Domain Admin Kerberos ticket. GPO deploys malware to 45 workstations and 6 servers across Phnom Penh & Siem Reap branches simultaneously. Total disaster recovery required.
SIEM Dashboard
๐Ÿ“Š Splunk / QRadar SIEM Event CorrelationANOMALY SPIKE
๐Ÿ”ด LIVE INJECT 02 โ€ข SENSITIVE DATA EXFILTRATION
๐Ÿ“ค 5.2 GB Customer Loan Data Siphoned Outbound
Simulated Time: 02:25 PM ยท Palo Alto NGFW & SIEM Offense #48291 Fired
๐Ÿ”ฅ PALO ALTO NEXT-GEN FIREWALL
HIGH DATA LOSS 02:28:44 PM
High-Bandwidth Outbound Data Spike to Uncategorized IP
Firewall detected compressed multi-stream TLS upload transferring 5.2 GB from internal host LOAN-LAPTOP-042 to foreign C2 IP 185.220.101.45:443. Data staged in %TEMP%\\enc_payload.dll containing customer national IDs, land titles, and financial filings.
Exfiltrated Size5.2 GB (Archive)
Destination C2185.220.101.45:443
Records Stolen~3,500 Customer Files
Protocol / PortHTTPS / TCP 443
T1048.002 Exfiltration Over C2 T1074 Data Staged T1005 Data from Local System
โšก Choose Branch:
โœ… Branch A: Partial Exfiltration Blocked
Network team pushes firewall block at 500MB. 90% of customer files saved. Blast radius contained.
โš ๏ธ Branch B: Full 5.2GB Transferred (Default)
Exfiltration completes before perimeter blocks are applied. Threat actor secures full customer database. โ†’ Double extortion leverage established.
Network Threat Topology Map
๐Ÿ—บ๏ธ Enterprise Threat & Exfiltration Topology MapDATA FLOW
๐Ÿ”ด LIVE INJECT 03 โ€ข RANSOMWARE ENCRYPTION
๐Ÿ”’ CrowdStrike SEV-1: Mass File Encryption Detected!
Simulated Time: 02:32 PM ยท File Share \\ADMFI-FS01\\Loan_Share$ & Workstation Locked
๐Ÿ›ก๏ธ CROWDSTRIKE FALCON SENSOR
CRITICAL SEV-1 02:32:15 PM
Active Ransomware Detonation & Mass File Rename
Multi-threaded AES-256 encryption encrypting files on LOAN-LAPTOP-042 and traversing network share \\\\ADMFI-FS01\\Loan_Share$. Files renamed with .ADMFI_LOCKED extension at 50 files / second.
Incident SeverityCRITICAL SEV-1
Encryption EngineAES-256 + RSA-4096
File Extension.ADMFI_LOCKED
WAR Room SLA< 30 Minutes
T1486 Data Encrypted for Impact T1490 Inhibit System Recovery
โšก Choose Branch:
โœ… Branch A: L2 Pre-Approved Containment
L2 triggers CrowdStrike isolation immediately. Encryption stopped at 2,300 files.
โš ๏ธ Branch B: Approval Hesitation (Default)
L2 delays 15 minutes seeking management approval. All 12,000 files in Loan_Share$ encrypted. Major Incident declared.
CrowdStrike EDR Alert
๐Ÿšจ CrowdStrike EDR Console AlertCRITICAL SEV-1
๐Ÿšจ SEQUENTIAL SOC ALERT STREAM โ€ข LIVE REPLAY
โšก Real-Time Security Alert Stream & Event Timeline
Interactive SOC alarm sequence player โ€” step through or auto-play incoming telemetry in chronological order
๐Ÿ”ด RANSOM EXTORTION & DEMAND
๐Ÿ’€ Workstation Screen Frozen โ€” $50,000 USD Demand
Victim display locked ยท 72-hour countdown timer ยท Bitcoin / USDT payment demanded
Ransomware Lock Screen
๐Ÿ’€ Victim Dell Workstation Lock Screen72-HR COUNTDOWN
โ˜Ž๏ธ IT HELPDESK / INCIDENT ESCALATION
EXTORTION DEMAND 02:33:10 PM
Ransom Note: Demand 5.0 BTC (~$50,000 USD)
Workstation LOAN-LAPTOP-042 locked with ransom screen. Attacker provides Bitcoin address 1F1tAaz5x1HUXrCNLvtMDqcw6955Hnt9Dk. Threatens to publish all 3,500 customer records on dark web leak site if unpaid.
Demand Sum$50,000 USD (5.0 BTC)
Deadline72 Hours Countdown
Exfiltration LeverageDouble Extortion
Payment PolicyStrictly Prohibited
T1486 Ransom Extortion Regulatory Violation if Paid
โšก Choose Branch:
โœ… Branch A: Immutable Backup Restoration Approved
CIO & CISO reject ransom negotiation. IT prepares clean restore from 12:00 PM immutable storage snapshot.
๐Ÿ”ด Branch C: Ransom Paid โ€” Corrupt Key Failure
Executive pays $50,000 in USDT. Attacker key fails on 40% of database files. OFAC / NBC sanction inquiry triggered.
๐ŸŒ€ UNEXPECTED PLOT TWIST 01
๐Ÿ“ฒ Attacker Hijacks Loan Head's Telegram Account!
Threat actor abuses stolen session tokens to impersonate Head of Loans (BEC)
๐Ÿ“ฑ TELEGRAM IDENTITY HIJACK (BEC)
IDENTITY HIJACK 02:35:10 PM
Malicious Broadcast Sent to 45 Loan Officers
While SOC contains Sok Dara's laptop, the threat actor uses stolen session cookies to authenticate as Head of Loans (@vuthy_loan_head). He broadcasts: "โš ๏ธ Emergency IT maintenance. Download and run the updated VPN patch immediately: [malicious link]"
Compromised Account@vuthy_loan_head
Recipients Targeted45 Commercial Officers
Auth Source185.220.101.45
OOB ActionEmergency SMS Alert
T1534 Internal Spearphishing T1539 Steal Web Session Cookie
[14:35:10] TG_AUTH: @vuthy_loan_head logged in from 185.220.101.45
[14:35:44] BROADCAST: Malicious VPN update link sent to 45 loan staff
[14:37:02] CLICKS: 3 loan officers clicked before warning issued
โšก Choose Branch:
โœ… Branch A: Rapid Flash Warning
Incident Communicator sends emergency SMS blast. Threat stopped. Vuthy session terminated.
โš ๏ธ Branch B: Secondary Infection Wave
3 additional laptops infected across provincial branches. Threat hunting scope expanded.
  • 1Who has mandatory authority to issue an emergency broadcast to all employees?
  • 2Do we have an established Out-of-Band (SMS/Signal) communication channel?
๐ŸŒ€ UNEXPECTED PLOT TWIST 02
๐Ÿ’พ Attacker Wipes Shadow Copies & Targets Backup NAS
Malware executes VSSAdmin delete shadows & attempts Domain Admin login to \\\\ADMFI-BKP01
๐Ÿ’พ STORAGE & BACKUP CONTROLLER MONITOR
BACKUP SABOTAGE 02:40:02 PM
VSSAdmin Shadow Copy Purge & NAS Authentication Probe
Malware executed vssadmin delete shadows /all /quiet to destroy local restore points. Attacker simultaneously probed secondary backup NAS server at \\\\ADMFI-BKP01 using stolen Domain Admin credentials.
Target Backup Server\\\\ADMFI-BKP01
Local Shadow CopiesPurged via VSSAdmin
NAS Auth ResultDENIED (MFA Protected)
Immutable Snapshots12:00 PM Clean
T1490 Inhibit System Recovery T1078 Valid Accounts
โšก Choose Branch:
โœ… Branch A: Immutable WORM Snapshots Intact
Backup NAS uses segregated non-domain credentials and MFA. 12:00 PM snapshot verified 100% clean. Restore time: 4 hours.
๐Ÿ”ด Branch B: Backup NAS Wiped
NAS was joined to corporate AD domain. Attacker deleted all backup volumes. Full BCP disaster recovery required (RTO 48h).
Backup Recovery Dashboard
๐Ÿ’พ Clean Backup Verification PortalIMMUTABLE SNAPSHOT
๐Ÿ”ด LIVE INJECT 04 โ€ข SYNCHRONIZED CONTAINMENT
๐Ÿš’ 4-Pillar Parallel Containment Operations
Simultaneous execution: Endpoint Isolation ยท Identity Revocation ยท Firewall Block ยท Storage Lock
๐Ÿ›๏ธ INCIDENT COMMAND WAR ROOM
PARALLEL WORKSTREAMS 02:45:00 PM
Synchronized 4-Pillar Containment Execution
To prevent enterprise-wide spread, 4 workstreams must execute in parallel:
  • 1. Endpoint: CrowdStrike isolate LOAN-LAPTOP-042, kill Trojan processes
  • 2. Identity: Disable sok.dara AD account, invalidate Kerberos tickets
  • 3. Network: Firewall drop for IP 185.220.101.45, quarantine VLAN
  • 4. Storage: Stop SMB sessions on \\\\ADMFI-FS01\\Loan_Share$, lock snapshot
โšก Choose Branch:
โœ… Branch A: Flawless Execution
Containment completed in 12 minutes. Zero lateral movement.
โš ๏ธ Branch B: Communication Delay
Firewall ticket delayed 25 minutes. Attacker exfiltrates additional 1.5GB data.
4-Pillar Parallel Containment
๐Ÿ›ก๏ธ 4-Pillar Parallel Containment FrameworkOPERATIONAL MATRIX
๐ŸŒ€ UNEXPECTED PLOT TWIST 03
๐Ÿ“ข Threat Actor Leaks 50 Customer ID Records on Telegram!
Double extortion: Attacker publishes customer land titles & national IDs on public channel
๐ŸŒ CTI & DARK WEB THREAT MONITOR
PUBLIC EXTORTION LEAK 03:15:20 PM
50 Customer National IDs & Land Titles Published Publicly
To escalate extortion pressure, Ransomus posted 50 customer loan dossiers on a public Telegram channel and dark web blog, threatening to release all 3,500 records in 24 hours.
Leaked Data50 National IDs & Titles
Ultimatum24-Hour Full Dump
Regulatory TriggerNBC & CamCERT Mandatory
Public PROfficial Statement Req.
Double Extortion Data Privacy Breach
  • 1Under National Bank of Cambodia rules, what is the mandatory breach disclosure timeframe?
  • 2Who approves the public PR statement and coordinates with customer call centers?
Crisis War Room Map
๐Ÿ—บ๏ธ Threat Landscape & Extortion Exposure MapGLOBAL CTI
๐Ÿ”ด LIVE INJECT 05 โ€ข REGULATORY GOVERNANCE & EXEC COMMS
๐Ÿ›๏ธ Regulatory Notification & Board Escalation
CISO & CIO briefing National Bank of Cambodia (NBC) & CamCERT
๐Ÿ›๏ธ LEGAL & REGULATORY COMPLIANCE
REGULATORY SLA 03:45:00 PM
Mandatory Incident Notification Pack Submission
CISO and Legal must submit preliminary notification pack to NBC & CamCERT:
  • Incident Severity Assessment (CRITICAL SEV-1)
  • Impacted customer count and data categories
  • Containment status and backup restoration progress
  • Draft customer advisory communication
โšก Choose Branch:
โœ… Branch A: Regulatory Compliance Met
CISO contacts NBC via secured channel. Formal statement approved. Supervisory penalty avoided.
โš ๏ธ Branch B: Delayed Submission
Notification exceeds deadline. NBC initiates supervisory audit.
Incident Command RACI
๐Ÿ›๏ธ Incident Command Hierarchy & RACI MatrixGOVERNANCE
๐Ÿ”„ RECOVERY PHASE โ€ข DISASTER RECOVERY PIPELINE
๐Ÿ’พ Clean Backup Restoration & Controlled Return-to-Service
6-Stage Clean Restoration Workflow ยท Business Validation ยท Joint CIO & CISO Sign-off
๐Ÿ”„ DISASTER RECOVERY CONTROLLER
RECOVERY IN PROGRESS Day 2 โ€” 09:00 AM
6-Stage Clean Restoration Preconditions Met
  1. Eradication Verified: Malware killed, laptop reimaged, credentials rotated
  2. Immutable Backup: 12:00 PM WORM snapshot verified uncompromised
  3. Sandbox Mount: Restored in isolated staging environment
  4. Integrity Check: Antivirus & heuristic scan of database files clean
  5. Business Sign-off: Asset Owner confirms data reconciliation
  6. 72h Monitoring: Real-time telemetric watch in SIEM
Clean Backup Restoration Flow
๐Ÿ”„ Clean Backup Restoration & DR PipelineSERVICE RESUMPTION
EXERCISE CONCLUSION โ€ข DEBRIEF & AAR
๐Ÿ After-Action Review (AAR) & Action Tracker
Evaluating SLA performance, process gaps, and post-PIR remediation roadmap
๐Ÿ“Š DRILL SLA SCORECARD
EVALUATION
  • P1 ยท L1 Alert Triage <15m: Not recorded
  • P2 ยท Host & Identity Containment: Not recorded
  • P3 ยท WAR Room & Exec Briefing <30m: Not recorded
  • P4 ยท Regulatory Compliance Disclosure: Not recorded
โš™๏ธ Top 5 Gaps Identified:
  1. Unsanctioned Telegram messaging allowed .exe downloads
  2. EDR double-extension rule (.pdf.exe) needed tuning
  3. Lack of pre-approved BEC / Telegram hijack playbook
  4. Backup NAS credentials required complete AD air-gapping
  5. Regulatory disclosure template needed pre-approval
๐Ÿ“Œ Post-PIR Corrective Actions:
  1. Enforce MDM blocking of unsigned downloads via messaging apps
  2. Strengthen CrowdStrike behavioral rules for process injection
  3. Establish pre-approved SOC L2 host isolation authority matrix
  4. Air-gap backup storage credentials with dedicated hardware MFA
  5. Standardize rapid notification pack for NBC & CamCERT
Cyber Saving Throw Combat Deck
Final Boss Encounter
๐Ÿ’€ Ransomus the Encryptor
Boss Health Pool
10,000 / 10,000 HP
ROLL D20 COMBAT DIE
20
Nat 20: 2,250 DMG (Crit!)
10โ€“19: 1,500 DMG (Pass)
1โ€“9: 0 DMG (Corruption)
Combat Battle Log
[09:15] ๐Ÿ›ก๏ธ DUNGEON MASTER: A remote loan officer receives Customer_Documents_2026.zip on Telegram... [09:15] ๐ŸŽฒ ENCOUNTER I: SOC L1 Sentinel must make a Perception Check (DC 14)! [09:16] โš”๏ธ Ready your party. Click the D20 die to roll for initiative!
Master Knowledge Hub

๐Ÿ“š Comprehensive TTX Guides, SOPs & Documentation

Access all facilitator guides, readiness checklists, player briefing handouts, branching decision matrices, localized scenario variants, and executive presentation materials.

Select Manual / Guide
Facilitator Guide & Master Script Markdown View

๐ŸŽ“ Ransomware Tabletop Exercise (TTX) - Facilitator Guide

๐Ÿ“Œ Exercise Overview

  • Scenario: Off-site Loan Officer Ransomware & Customer Data Exfiltration Incident.
  • Target Audience: SOC L1, SOC L2, SOC Lead/L3, Incident Communicator, SOC Manager, Business/Asset Owner, Network/System Team, CTI Team, CIO, CISO, Executive Management.
  • Duration: 2 to 3 Hours.
  • Goal: Test organizational readiness, SOP adherence, RACI containment authority enforcement, decision-making velocity, and cross-departmental coordination during a multi-stage ransomware attack.

  • ๐Ÿ‘ฅ Role Assignment & Authority Matrix Summary

    Role TitleFocus / ScopeMandatory Core Responsibilities (SOP Aligned)Containment Authority
    SOC L1 (Tier 1 / Shift Duty) Shift TriageMonitor alerts continuously, validate FP vs TP, enrich context (asset, user, IP, impact), create ITSM ticket, escalate to L2 < 15 min, execute playbook containment for low/med severity, escalate directly to SOC Manager if L2 unavailable.Low/Med Playbook Predefined
    SOC L2 (Tier 2 Analyst) Lead InvestigationLead investigation, validate legitimacy & scope, confirm severity level, threat intel correlation, forensic log analysis & timeline reconstruction, assess business impact, recommend containment, execute high-severity containment per authority matrix, lead eradication, draft technical reports.High Severity (per matrix)
    SOC Lead / L3 Senior ForensicsSupport complex investigations, guide deep forensic analysis, authorize major containment actions, assist scoping & root cause analysis (RCA), escalation support for L2 uncertainty, share full authority with SOC Manager during SEV1.Major Containment Authorized
    Incident Communicator Comms & WAR RoomOwn all incident communications, create & manage WAR Room, coordinate stakeholders, notify executives per SLA, prepare & distribute Interim/Final reports, manage recovery comms, track action items.โŒ NO Containment Authority
    SOC Manager Operational AuthorityOverall operational authority during incidents, approve major containment actions, declare Major Incidents, engage BCP/DR process, coordinate executive escalation, oversee execution & reporting, ensure overdue action escalation.Full Operational Approval
    Business / Asset Owner Business ContextProvide business/application context, participate in impact assessment, approve containment affecting production systems/apps, execute remediation & recovery, validate restoration & business recovery before closure.Production System Approval
    Network & System Team Infrastructure OpsExecute network and system containment requested by SOC, perform firewall blocks, account changes, or system actions when SOC lacks permission, support eradication & recovery, coordinate with SOC.Technical Execution
    CTI Team Threat IntelligenceProvide IOC enrichment & campaign intelligence, support attribution analysis, track industry-wide threats & campaigns, assist threat intelligence correlation during investigations.Intelligence Support
    CIO Core System AuthorityFinal authority during crises impacting core systems, approve recovery for SEV1 and SEV2 incidents, receive executive notifications, participate in BCP/DR discussions.Final Recovery Sign-Off
    CISO Cyber GovernanceStrategic oversight of cybersecurity response, regulatory & risk alignment, mandatory SEV1/SEV2 notification, approve recovery for SEV1 & SEV2, review reports & recommendations.Strategic & Recovery Sign-Off
    Executive Management Board & GovernanceCIO/CRO/CISO/Cyber Head/Heads of Division provide business & risk oversight, approve strategic decisions, make regulatory decisions, participate in high-severity governance.Strategic & Regulatory

    ๐ŸŽฌ Exercise Injects & Facilitator Script

    ๐Ÿ“ Inject 1: Unsanctioned Communication & Malicious Payload Arrival

  • Simulated Time: 09:15 AM (Day 1 - Offsite)
  • Context: A loan officer working remotely receives Customer_Documents_2026.zip via Telegram from what appears to be an urgent customer loan applicant.
  • Visual Asset:
    Telegram PhishingTelegram Phishing
  • Event: The officer extracts the archive and double-clicks Signed_Agreement.pdf (disguised .exe). An Adobe Reader error pop-up appears: "Unable to render document format (0x80070005)". The user ignores the error and closes the app.
  • Visual Asset:
    Fake PDF ErrorFake PDF Error
  • Participant Role Focus:
  • SOC L1: Continuously monitor SIEM/EDR, triage FP vs TP, enrich context, create ITSM ticket, and prepare L2 escalation < 15 min.

  • ๐Ÿ“ Inject 2: LAN Reconnection & Reconnaissance

  • Simulated Time: 02:00 PM (Day 1 - Office)
  • Context: The loan officer returns to the corporate office and plugs the laptop (LOAN-LAPTOP-042) into the corporate LAN.
  • Event: Malware detects local network domain, enumerates Active Directory, and discovers accessible file shares (\\ADMFI-FS01\Loan_Share$). It abuses existing Kerberos tokens under account sok.dara.
  • Participant Role Focus:
  • CTI Team: Track campaign patterns and cross-reference domain callback infrastructure.

  • ๐Ÿ“ Inject 3: Data Exfiltration & SIEM Anomalies

  • Simulated Time: 02:25 PM (Day 1)
  • Context: Attacker initiates compressed archive exfiltration of 5GB customer data to external IP 185.220.101.45 (C2 domain: mal-c2.admfi-verify.com).
  • Visual Asset:
    SIEM DashboardSIEM Dashboard
  • Event: SIEM triggers correlation alerts: Outbound HTTPS Traffic Spike to Uncategorized IP + Abnormal SMB Read Volume.
  • Participant Role Focus:
  • SOC L2: Lead investigation, validate scope, confirm severity level, perform threat intel correlation, and conduct log analysis.

  • ๐Ÿ“ Inject 4: Active Encryption & HelpDesk Crisis

  • Simulated Time: 02:32 PM (Day 1)
  • Context: Attacker launches ransomware component. Local files on LOAN-LAPTOP-042 and \\ADMFI-FS01\Loan_Share$ are encrypted with .ADMFI_LOCKED extensions.
  • Visual Asset:
    EDR AlertEDR Alert
  • Visual Asset:
    Ransomware NoteRansomware Note
  • Event: EDR fires CRITICAL SEV-1: Ransomware Execution Detected. At the same time, Sok Dara's laptop (LOAN-LAPTOP-042) freezes and displays a ransom note demanding $50,000 USD (USDT/Bitcoin) within 72 hours.
  • Participant Role Focus:
  • SOC Lead / L3: Guide deep forensic analysis and authorize major containment actions.
  • SOC Manager: Declare Major Incident and approve major containment.

  • ๐Ÿ“ Inject 5: Major Incident WAR Room & Multi-Team Containment

  • Simulated Time: 02:45 PM (Day 1)
  • Context: SOC Manager declares SEV-1 Major Incident. Incident Communicator launches WAR Room and notifies CISO/CIO per SLA.
  • Visual Asset:
    War Room DashboardWar Room Dashboard
  • Participant Role Focus:
  • Incident Communicator: Create and manage WAR Room, notify CISO/CIO < 15 min, issue 30-60 min updates (NO containment authority).
  • Network & System Team: Execute firewall blocks (185.220.101.45), AD account lockouts (sok.dara), and host isolation requested by SOC.
  • Business Owner: Provide application context and approve containment affecting production systems (\\ADMFI-FS01\Loan_Share$ Read-Only mode).

  • ๐Ÿ“ Inject 6: Eradication, Recovery & Business Sign-Off

  • Simulated Time: Day 2 โ€“ Day 3
  • Context: System clean-up, laptop reimaging, file restoration from uncorrupted backups, business sign-off, and 72-hour SEV1 monitoring.
  • Participant Role Focus:
  • SOC L2 & System Team: Lead eradication and reimage workstation.
  • Business Owner: Validate restoration and confirm business operational recovery prior to closure.
  • CIO & CISO: Provide mandatory final recovery approval for SEV1 incident return to production.
  • Incident Communicator & SOC Manager: Distribute Final Report and enforce tracking of overdue post-PIR action items.

  • ๐ŸŒ€ Plot Twists & When to Trigger Them

    Plot Twists are optional facilitator escalations to be injected dynamically based on SOC team performance. Use them to challenge a team responding well, or to pivot the scenario trajectory.

    #Plot TwistTrigger ConditionBest Injection Point
    ๐ŸŒ€ 1Telegram BEC Hijack: Attacker uses stolen session cookies to log into Head of Loans Telegram account (@vuthy_loan_head) and broadcasts a malicious fake VPN link to 45 loan officers.SOC has successfully isolated Sok Dara's laptop.Between Inject 2 and 3.
    ๐ŸŒ€ 2Shadow Copy & Backup NAS Wipe: Malware runs vssadmin delete shadows /all /quiet and attempts to authenticate to \\ADMFI-BKP01 using cached Domain Admin credentials.Team starts discussing backup restoration.After Inject 4, when recovery planning begins.
    ๐ŸŒ€ 3Public Customer Data Leak: Threat actor posts 50 customer ID cards and land titles on a public Telegram channel with a 24-hour ultimatum to dump all 3,500 records.Ransom demand discussion begins.After Inject 5, to escalate Legal/CISO/CIO governance pressure.
    Tip: ๐Ÿ’ก Facilitator Tip: You do NOT need to trigger all three twists. If the team is struggling with Injects 1โ€“3, skip Twist 1 and let them stabilize. Twists work best when the team feels confident โ€” they reset the energy in the room.

    ๐Ÿ“Š TTX Evaluation & KPI Scoring Rubric

    Metric / KPITarget SLAEvaluation Criteria
    L1 Alert Validation< 15 MinsDid L1 determine TP and escalate to L2 within 15 mins (or SOC Mgr if L2 unavailable)?
    L2/L3 Containment Authority< 30 MinsDid L2 lead investigation and Network/System team execute firewall/AD actions per authority matrix?
    Executive Notification< 15 MinsDid Incident Communicator notify CISO, CIO, and Cyber Head per SLA?
    WAR Room Setup< 30 MinsWas central WAR Room established with key role stakeholders represented?
    Business Recovery ConfirmationPre-ClosureDid Asset Owner validate restoration and CIO/CISO approve SEV1 recovery before closure?
    Overdue Action TrackingPost-PIRDid SOC Manager and Communicator establish tracking escalation for overdue PIR actions?

    ๐Ÿ“‹ TTX Readiness & Required Materials Checklist

    ๐Ÿ›ก๏ธ Pre-Exercise Setup, Communication Channels & Resource Checklist

    Important: Use this checklist 24 to 48 hours prior to launching the Tabletop Exercise (TTX) to ensure all technical infrastructure, communication channels, role assignments, and facilitator materials are fully prepared.

    1. ๐Ÿ“ข Communication Channels & Contact Lists

    CategoryChannel / ToolPurpose & DetailsStatus / Action Item
    Primary Exercise ChatMS Teams / Slack Channel: #TTX-Ransomware-2026Real-time text communications during exercise injects.โฌœ Ready
    Out-of-Band (OOB) CommsDedicated Telegram / Signal GroupSimulated emergency comms when primary IT networks are "down".โฌœ Ready
    Incident WAR RoomMS Teams / Zoom Bridge: TTX Incident CommandVirtual bridge activated during Phase 3 Crisis Escalation.โฌœ Ready
    Executive Contact RosterPrinted / PDF Escalation RosterPhone numbers for CISO, CIO, SOC Lead, Legal, PR & BCP Officer.โฌœ Ready
    Regulatory ContactsPre-drafted Contact SheetContact emails/phones for National Bank of Cambodia (NBC) & CamCERT.โฌœ Ready

    2. ๐Ÿ“œ Scenario Documents & Role Handbooks

    ๐ŸŽ“ Facilitator Guide: facilitator_guide.md (Facilitator script, inject timing & discussion prompts).
    ๐Ÿ“œ Core Scenario & Flowcharts: ransom_ttx.md & khmer_ransomware_scenario.md .
    ๐Ÿ›ก๏ธ SOC Orientation Slide Deck: soc_ttx_briefing_slides.md (Slide presentation for team briefing).
    ๐ŸŽญ 11 Character Role Cards (Printed or distributed digitally from roles/ ):
    SOC L1 Analyst Handbook (SOC_L1_Analyst.md)
    SOC L2 Analyst Handbook (SOC_L2_Analyst.md)
    SOC Lead / L3 Handbook (SOC_Lead_L3.md)
    Incident Communicator Handbook (IR_Communicator.md)
    SOC Manager Handbook (SOC_Manager.md)
    Business / Asset Owner Handbook (Business_Asset_Owner.md)
    Network & System Team Handbook (Network_System_Team.md)
    CTI Team Handbook (CTI_Team.md)
    CIO Handbook (CIO.md)
    CISO Handbook (CISO.md)
    Executive Management Handbook (Executive_Management.md)
    ๐Ÿ“˜ Internal SOPs & Playbooks:
    Ransomware Incident Response Playbook
    Account Compromise & Identity Isolation Playbook
    Business Continuity & Disaster Recovery Plan (BCP/DR)

    3. ๐Ÿ–ฅ๏ธ Hardware, Visual Assets & Room Infrastructure

    code
                                      [ MAIN PRESENTATION SCREEN ]
                                      (Runs index.html Portal & Mockups)
                                                   โ”‚
                   โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
                   โ–ผ                               โ–ผ                               โ–ผ
           [ Facilitator Desk ]            [ SOC Operations Desk ]         [ Executive Command Desk ]
         - Facilitator Guide            - Laptops & SOP Playbooks       - Executive Escalation Sheet
         - Master Inject Clock          - ITSM / SIEM Mockup Access     - Legal & NBC Notification Forms
         - Scribe / Minute Notebook     - EDR Isolation Controls        - BCP Decision Matrix
    ๐Ÿ“บ Main Display / Projector: Open interactive web portal index.html for full-screen slide presentations.
    ๐Ÿ“ธ Visual Threat Mockups (Located in assets/ ):
    telegram_phishing.jpg (Telegram payload screenshot)
    fake_pdf_error.jpg (Adobe error window)
    edr_ransomware_alert.jpg (CrowdStrike alert console)
    ransomware_note.jpg (Victim lock screen)
    siem_dashboard.jpg (QRadar correlation dashboard)
    war_room_dashboard.jpg (Incident Command board)
    โฑ๏ธ Timer / Countdown Clock: Visible timer to enforce SLA decision windows (e.g. 15-min escalation, 30-min WAR room setup).
    ๐Ÿ–๏ธ Whiteboard / Virtual Canvas: To track the 4 containment workstreams (Endpoint, Identity, Network, File Server).

    4. ๐Ÿ“ Administrative, Scribing & Evaluation Materials

    โœ๏ธ Dedicated Scribe / Minute Taker: Assigned person to capture exact timestamps, decision rationale, and debate points.
    ๐Ÿ“‹ Scribe Log Sheet:
  • Time Inject Released
  • Action Taken & Decision Owner
  • Tool / Playbook Referenced
  • SLA Target Met (Yes / No)
  • Identified Process Gap
  • ๐Ÿ“Š Participant Feedback Survey: Post-exercise feedback forms evaluating scenario realism and playbook clarity.
    ๐Ÿ“„ After-Action Report (AAR) Template: Prepared document structure for post-exercise reporting.

    5. ๐Ÿš€ Pre-TTX Kickoff Checklist (T-Minus 30 Minutes)

    1. [ ] Confirm all participants are logged into the primary chat channel (#TTX-Ransomware-2026).

    2. [ ] Test video/audio bridge if conducting a hybrid or virtual exercise.

    3. ] Verify main presentation screen is displaying [index.html .

    4. [ ] Distribute role handbooks to designated participants.

    5. ] Deliver the SOC Team Briefing Slides ([soc_ttx_briefing_slides.md ) to set exercise ground rules and objectives.

    6. [ ] Release Inject 1 and start the exercise master clock!


    marp: true

    theme: default

    paginate: true

    header: "๐Ÿ›ก๏ธ SOC Briefing | Ransomware Tabletop Exercise (TTX)"

    footer: "Confidential - Cybersecurity Operations Center"


    ๐Ÿ›ก๏ธ SOC Team Briefing: Ransomware Tabletop Exercise (TTX)

    ๐ŸŽฏ Executive & Operational Orientation Slide Deck

    Presenter: SOC Lead / Facilitator

    Target Audience: SOC L1, SOC L2, SOC Lead/L3, SOC Manager, IR Communicator, CTI Team

    Exercise Context: Off-site Phishing, C2 Beaconing, SMB Exfiltration & Ransomware Outbreak

    Date: August 2026


    ๐Ÿ“Œ 1. Why Are We Running This TTX?

    Background & Operational Reality

  • Off-site Workforce Vulnerability: Loan officers and remote staff rely heavily on messaging platforms (e.g., Telegram) for customer interactions.
  • Silent Malware Execution: Attackers disguise malicious executables inside archives (Customer_Documents_2026.zip), triggering fake error messages while establishing covert background persistence.
  • LAN Reconnection Hazard: Upon returning to the office network, malware abuses existing user authentication to target corporate file shares (Loan_Share$).
  • ๐ŸŽฏ Core Purpose: To test, evaluate, and refine our SOC Incident Response SOPs, detection capabilities, team escalation SLAs, and crisis communication in a simulated, zero-risk environment.

    ๐ŸŽฏ 2. Core Exercise Objectives

    #ObjectiveSuccess Criteria / SLA Target
    1โฑ๏ธ Validate SLA SpeedSOC L1 โ†’ L2 escalation in <15 mins; Executive notification in <15 mins for SEV-1.
    2๐Ÿš’ Test Containment PlaybooksRapid execution of EDR host isolation, AD session revocation, C2 IP blocking, and file share restrictions.
    3๐Ÿ’ฌ Practice Crisis CommsIncident WAR Room creation within 30 mins; stakeholder status updates every 30โ€“60 mins.
    4๐Ÿ” Scoping & Threat HuntingAccurate mapping of initial access vector, lateral movement attempts, and compromised assets.
    5๐Ÿ“ Identify Gaps & ImproveUncover friction points between SOC, IT Infrastructure, Legal, and Business teams.

    ๐Ÿ“– 3. Scenario At A Glance: "ADMFI Ransomware Incident"

    code
    [ Telegram Phishing ] โ”€โ”€> [ Fake PDF Error ] โ”€โ”€> [ Silent C2 Connection ]
                                                                โ”‚
    [ Shared Folder Encryption ] <โ”€โ”€ [ Data Exfiltration ] <โ”€โ”€ [ LAN Reconnection ]
                โ”‚
                โ”œโ”€โ”€> ๐Ÿšจ CrowdStrike EDR Critical Alert (Host Isolated)
                โ”œโ”€โ”€> ๐Ÿ“Š QRadar SIEM Event Correlation (Anomalous SMB Access)
                โ””โ”€โ”€> ๐Ÿ’€ Ransom Note Displayed ($50,000 USD Demand)
  • Victim User: Sok Dara (Senior Loan Officer)
  • Initial Vector: Received Customer_Documents_2026.zip containing Loan_Agreement.pdf.exe via Telegram.
  • Impact: Files encrypted with .ADMFI_LOCKED extension across local workstation and shared drive (\\ADMFI-FS01\Loan_Share$).

  • ๐ŸŽญ 4. SOC Roles & Expectations Matrix

    RoleKey FocusPrimary Responsibilities During TTX
    SOC L1 AnalystInitial TriageMonitor SIEM/EDR, validate alerts, enrich context, open ITSM ticket, escalate to L2 <15m.
    SOC L2 AnalystLead InvestigationScope blast radius, create forensic timeline, execute host isolation, block IOCs.
    SOC Lead / L3Deep ForensicsReverse engineer malware sample, lead enterprise threat hunting, assist complex containment.
    SOC ManagerIncident CommandDeclare SEV-1 Major Incident, authorize production containment, engage CISO/CIO & BCP.
    IR CommunicatorComms & WAR RoomSetup MS Teams WAR Room <30m, issue interim updates every 30-60m, draft AAR.
    CTI AnalystThreat IntelEnrich IOCs, correlate threat actor TTPs, search external campaign intelligence.

    ๐Ÿ‘จโ€๐Ÿ’ป 5. Deep Dive: SOC L1 & SOC L2 Execution Responsibilities

    ๐Ÿ”น SOC L1 Analyst (Tier 1 Duty)

    1. Acknowledge & Validate: Confirm EDR alert (CrowdStrike) & SIEM correlation (QRadar) are True Positive.

    2. Enrich Context: Gather Endpoint Name, IP address, User Account (sok.dara), Hash, and Alert Severity.

    3. Log & Escalate: Create ITSM Ticket (#INC-2026-0814) with provisional SEV-1 rating and transfer to L2 in <15 minutes.

    ๐Ÿ”น SOC L2 Analyst (Tier 2 Incident Lead)

    1. Forensic Timeline: Reconstruct timeline from Telegram download โ†’ C2 beacon โ†’ LAN connection โ†’ SMB enumeration.

    2. Execute Containment: Isolate infected endpoint in EDR console immediately.

    3. Enforce Restrictions: Request AD account lock, active token revocation, C2 domain/IP firewall block, and SMB write restriction.


    ๐Ÿ‘” 6. Deep Dive: SOC L3, SOC Manager & IR Communicator

    ๐Ÿ”ฌ SOC Lead / L3 Analyst

  • Perform memory/file artifact analysis on Loan_Agreement.pdf.exe.
  • Conduct threat hunt across all corporate endpoints for IOC hashes (e3b0c442...).
  • ๐Ÿ‘” SOC Manager (Incident Commander)

  • Formally declare SEV-1 Major Incident.
  • Notify CISO & CIO by phone within 15 minutes.
  • Authorize high-impact containment actions (e.g., disconnecting file server segments).
  • ๐Ÿ’ฌ Incident Communicator

  • Establish WAR Room within 30 minutes of SEV-1 declaration.
  • Maintain Incident Action Log and publish periodic executive briefings every 30โ€“60 minutes.

  • ๐Ÿ“œ 7. Exercise Ground Rules & Mindset

    Tip: ๐ŸŸข Safe Learning Environment: This TTX is an evaluation of processes and playbooks, NOT an individual performance audit.

    1. Speak Up & Participate: Explain your actions step-by-step: "I am checking X log file, issuing Y command, and notifying Z role."

    2. Focus on SOP Alignment: Reference our official playbooks (Ransomware SOP & Account Compromise SOP).

    3. Challenge Assumptions: If a procedure is unclear, redundant, or missing authorization, raise it during the inject discussion.

    4. No Real Production Impact: All actions discussed are hypotheticalโ€”no live systems will be disrupted.


    ๐Ÿ”„ 8. SOC Response Workflow Summary

    flowchart LR A["๐Ÿšจ Alert / Report"] --> B["๐Ÿ‘จโ€๐Ÿ’ป L1 Triage & Ticket<br/>โฑ๏ธ <15 mins"] B --> C["๐Ÿ” L2 Investigation<br/>& EDR Host Isolation"] C --> D["๐Ÿ“ข SOC Mgr SEV-1<br/>WAR Room Comms"] D --> E["๐Ÿงน Eradication,<br/>Re-image & Restore"] E --> F["๐Ÿ“‹ 72-Hour Monitor<br/>& Lessons Learned"] classDef detect fill:#E2F0D9,stroke:#548235,color:#375623; classDef contain fill:#FFF2CC,stroke:#BF8F00,color:#7F6000; classDef crisis fill:#F4CCCC,stroke:#C00000,color:#7F0000; classDef recover fill:#D9EAF7,stroke:#2F75B5,color:#17365D; class A,B detect; class C contain; class D crisis; class E,F recover;

    ๐Ÿ 9. Post-TTX Deliverables & Next Steps

    1. ๐Ÿ“„ After-Action Report (AAR): Documenting key observations, SLA compliance, and technical findings.

    2. ๐Ÿ› ๏ธ SOP & Playbook Updates: Refining containment matrix, containment delegation authority, and communication templates.

    3. ๐ŸŽฏ Detection Engineering Tuning: Adding custom EDR prevention rules and SIEM correlation alerts for double-extension files (.pdf.exe).

    4. ๐Ÿ“Œ Action Item Tracking: Assigning clear ownership and deadlines for all identified gaps.


    โ“ Questions & Readiness Check

    Are all SOC team members clear on their roles and objectives? Let's begin Inject 1!

    ๐ŸŒณ "What If... / Then If..." Branching Injects & Decision Tree Guide

    ๐Ÿ›ก๏ธ Tabletop Exercise (TTX) Dynamic Decision Paths & Scenario Outcomes

    Important: ๐ŸŽฏ Purpose for Facilitators: Use this guide during the Tabletop Exercise to pivot the scenario dynamically based on participant choices. If the SOC team responds quickly, choose Branch A. If they hesitate or make a mistake, pivot to Branch B or Branch C!

    ๐Ÿงญ Decision Tree Overview

    flowchart TD Start["๐ŸŽฌ Start: Telegram Payload Receipt"] --> P1{"Phase 1 Decision\nOff-site Execution"} P1 -- "EDR Blocks File" --> P1_A["1A: Clean EDR Quarantine\nLow Impact"] P1 -- "User Opens File (Default)" --> P1_B["1B: Silent C2 Beaconing\nPersistence Set"] P1 -- "OAuth Credential Theft" --> P1_C["1C: Telegram/M365 Account Hijack\nBEC Escalation"] P1_B --> P2{"Phase 2 Decision\nLAN Reconnection"} P2 -- "SOC Isolates Host under 5 mins" --> P2_A["2A: Containment Success\nLocal PC Only"] P2 -- "Isolation Delayed over 30 mins" --> P2_B["2B: Shared Folder Encrypted\nSEV-1 Major Incident"] P2 -- "Pass-the-Ticket Exploit" --> P2_C["2C: Domain Controller Lockdown\nCatastrophic Outage"] P2_B --> P3{"Phase 3 Decision\nEncryption and Backup"} P3 -- "Immutable Backup Clean" --> P3_A["3A: Restore in 4 Hours\nZero Ransom Paid"] P3 -- "VSSAdmin Shadow Copy Wiped" --> P3_B["3B: Backup Restoration Fails\nBCP/DR Activation"] P3_B --> P4{"Phase 4 Decision\nDouble Extortion Leak"} P4 -- "Attacker Leaks IDs on Telegram" --> P4_A["4A: NBC Regulatory Breach Alert\n24-Hour PR Crisis"] P4 -- "CTI Takedown Successful" --> P4_B["4B: Dark Web Leak Site Only\nControlled Comms"] classDef ideal fill:#E2F0D9,stroke:#548235,color:#375623; classDef moderate fill:#FFF2CC,stroke:#BF8F00,color:#7F6000; classDef severe fill:#F4CCCC,stroke:#C00000,color:#7F0000; class P1_A,P2_A,P3_A,P4_B ideal; class P1_B,P2_B moderate; class P1_C,P2_C,P3_B,P4_A severe;

    ๐Ÿ“ Phase 1: Off-site Telegram Payload Receipt

    ๐Ÿ”น Branch 1A: EDR Auto-Quarantine (Best Case)

  • โ“ WHAT IF: CrowdStrike EDR off-site endpoint policy blocks Customer_Agreement_2026.pdf.exe immediately upon extraction?
  • โžก THEN IF:
  • 1. Malware execution fails; no persistence or C2 beacon is established.

    2. EDR generates Alert #1042 (Medium Severity).

    3. SOC L1 Action: Quarantines hash enterprise-wide and notifies Loan Department to issue warning about Telegram account @chanthy_loan_applicant.

    4. Exercise Outcome: Incident contained at Phase 1. Proceed to Threat Hunting verification.

    ๐Ÿ”น Branch 1B: Silent Persistence & Background C2 (Default Path)

  • โ“ WHAT IF: User ignores Windows Adobe error 0x80070005 and malware establishes silent registry run key persistence under standard user context?
  • โžก THEN IF:
  • 1. Malware connects covertly to C2 IP 185.220.101.45:443.

    2. Malware goes dormant, polling C2 every 60 seconds waiting for corporate domain ADMFI.LOCAL signal.

    3. SOC L1 Action: No alert generated yet (stealth payload). Proceed to Phase 2 LAN Reconnection.

    ๐Ÿ”น Branch 1C: Telegram Session & Credential Hijack (Plot Twist Variant)

  • โ“ WHAT IF: Payload includes a phishing URL prompting user for M365/Telegram OAuth authentication to "view loan file"?
  • โžก THEN IF:
  • 1. Attacker steals active session tokens for Senior Loan Officer Sok Dara.

    2. Attacker logs into Sok Dara's Telegram account and sends malicious payload .zip files to 30 other loan officers!

    3. SOC L2 Action: Must execute immediate credential revocation, active session teardown, and internal broadcast warning.


    ๐Ÿ“ Phase 2: Corporate LAN Reconnection & SMB Scanning

    ๐Ÿ”น Branch 2A: Host Isolation <5 Minutes (Ideal SOC Response)

  • โ“ WHAT IF: SOC L2 Analyst detects anomalous SMB traffic to \\ADMFI-FS01\Loan_Share$ and executes EDR host isolation within 5 minutes?
  • โžก THEN IF:
  • 1. Ransomware execution on Shared Drive is aborted mid-process.

    2. Only 5 local files on Sok Dara's laptop are encrypted; corporate file server remains 100% clean.

    3. Impact: Minor workstation re-image required. Incident resolved within 2 hours.

    ๐Ÿ”น Branch 2B: Delayed Containment >30 Minutes (High Impact - Default)

  • โ“ WHAT IF: SOC L1/L2 hesitates or delays host isolation waiting for Business Owner permission?
  • โžก THEN IF:
  • 1. Ransomware encrypts 12,000 files across 4 shared folders (Loan_Share$, HR_Share$, Finance_Share$) in 4 minutes.

    2. File extension changes to .ADMFI_LOCKED.

    3. EDR triggers CRITICAL SEV-1 alert; SOC Manager declares Major Incident & activates WAR Room.

    ๐Ÿ”น Branch 2C: Pass-The-Ticket Domain Admin Escalation (Catastrophic Path)

  • โ“ WHAT IF: Attacker dumps LSASS memory on Sok Dara's laptop and harvests a cached Domain Admin Kerberos ticket?
  • โžก THEN IF:
  • 1. Attacker deploys ransomware Domain-wide via Active Directory Group Policy Objects (GPO).

    2. 45 workstations and 6 servers across Phnom Penh & Siem Reap branches freeze simultaneously.

    3. CIO Action: Authorizes total isolation of corporate network and mandates full BCP/DR activation.


    ๐Ÿ“ Phase 3: Ransom Demand & Backup Restoration

    ๐Ÿ”น Branch 3A: Immutable Backup Clean Restoration (Recovery Success)

  • โ“ WHAT IF: Infrastructure team confirms Loan_Share$ immutable storage snapshots taken at 12:00 PM are uncompromised?
  • โžก THEN IF:
  • 1. CIO & CISO approve clean data restoration.

    2. IT re-images laptop, wipes infected shared folders, and restores from immutable snapshot in 4 hours.

    3. Ransom Outcome: Zero ransom paid. Operations restored cleanly.

    ๐Ÿ”น Branch 3B: Shadow Copy & Secondary Backup Wipe (Plot Twist 2)

  • โ“ WHAT IF: Malware executes vssadmin delete shadows /all /quiet and wipes connected network backup NAS drives?
  • โžก THEN IF:
  • 1. Local volume shadow copies and hot NAS backups are destroyed.

    2. IT must fallback to off-site tape / cold cloud backup (RTO increases to 24-48 hours).

    3. Executive Action: BCP Committee convenes to manage manual paper-based loan processing workarounds.

    ๐Ÿ”น Branch 3C: Ransom Negotiation Dilemma

  • โ“ WHAT IF: Executive management considers paying $50,000 USD in USDT to obtain decryption key?
  • โžก THEN IF:
  • 1. CISO & Legal advise that paying violates NBC cybersecurity compliance guidelines and OFAC sanctions.

    2. Attacker provides test decryption key, but key fails on 40% of large database files (corrupt decryption).

    3. Outcome: Financial loss without guaranteed data recovery.


    ๐Ÿ“ Phase 4: Double Extortion & Public Data Leak

    ๐Ÿ”น Branch 4A: Telegram Public Customer Data Leak (Plot Twist 3)

  • โ“ WHAT IF: Threat actor leaks 50 sample Cambodian customer ID cards and land title certificates on a public Telegram channel?
  • โžก THEN IF:
  • 1. Media and social media pick up the leak within 2 hours.

    2. Legal & CISO Action: Mandatory notification to National Bank of Cambodia (NBC) and CamCERT within 24 hours.

    3. PR Action: Release official press statement reassuring customers and setting up dedicated customer inquiry hotline.

    ๐Ÿ”น Branch 4B: CTI Takedown & Managed Disclosure

  • โ“ WHAT IF: CTI team successfully works with Telegram abuse team to take down the leak channel within 1 hour?
  • โžก THEN IF:
  • 1. Public exposure is contained to dark web leak site only (admfi-leaks.onion).

    2. PR holds press statement while Legal fulfills NBC regulatory briefing requirements privately.


    ๐Ÿ“Š Summary Decision Matrix for Facilitators

    Scenario PhaseBranch ChoiceTrigger ConditionOperational ConsequenceRecommended Discussion Prompt
    Phase 11A / 1B / 1CSOC EDR Policy EnforcementClean Quarantine vs. Silent C2 vs. Telegram BECHow do we secure Telegram off-site workflows?
    Phase 22A / 2B / 2CSOC Isolation Speed (<5m vs >30m)Local PC Only vs. Shared Drive Lock vs. Domain WipeDoes SOC L2 have pre-approved isolation authority?
    Phase 33A / 3B / 3CBackup Air-gap Status4-Hour Recovery vs. Disaster Recovery vs. Ransom LossHow do we verify backup immutability under attack?
    Phase 44A / 4BPublic Leak OccurrenceNBC Audit & PR Crisis vs. Private Regulatory BriefingWhat is our NBC regulatory notification timeline?

    ๐Ÿ‡ฐ๐Ÿ‡ญ แžšแž”แžถแž™แž€แžถแžšแžŽแŸแžŸแŸแžŽแžถแžšแžธแž™แŸ‰แžผ Simulation Ransomware แž”แŸ‚แž”แžแŸ’แž˜แŸ‚แžš (Khmer-Style Cyber Ransomware TTX Scenario)

    Important: ๐Ÿข แžขแž„แŸ’แž‚แž—แžถแž–แžŸแŸแžŽแžถแžšแžธแž™แŸ‰แžผแžŸแž˜แŸ’แž˜แžแžทแž€แž˜แŸ’แž˜ (Fictional Organization): แž’แž“แžถแž‚แžถแžš แžขแž„แŸ’แž‚แžš แžขแž—แžทแžœแžŒแŸ’แžแž“แŸ แž˜แžธแž€แŸ’แžšแžผแž แžทแžšแž‰แŸ’แž‰แžœแžแŸ’แžแžป แž—แžธแžขแžทแž›แžŸแŸŠแžธ (Angkor Development Microfinance Institution Plc. - ADMFI) ๐Ÿ“… แž€แžถแž›แž”แžšแžทแž…แŸ’แž†แŸแž‘ (Scenario Date): แžแŸ’แž„แŸƒแž‘แžธแŸกแŸค แžแŸ‚แžŸแžธแž แžถ แž†แŸ’แž“แžถแŸ†แŸขแŸ แŸขแŸฆ โš ๏ธ แž€แž˜แŸ’แžšแžทแžแžขแžถแžŸแž“แŸ’แž“ (Severity Level): CRITICAL SEV-1 (แž€แžถแžšแžœแžถแž™แž”แŸ’แžšแž แžถแžš Ransomware แž›แžพแž”แžŽแŸ’แžแžถแž‰แž•แŸ’แž‘แŸƒแž€แŸ’แž“แžปแž„ แž“แžทแž„แžฏแž€แžŸแžถแžšแžขแžแžทแžแžทแž‡แž“) ๐Ÿ”— แžฏแž€แžŸแžถแžšแž–แžถแž€แŸ‹แž–แŸแž“แŸ’แž’ (Related Docs): ransom_ttx.md | facilitator_guide.md | index.html

    1. แžŸแž„แŸ’แžแŸแž”แžŸแŸแžŽแžถแžšแžธแž™แŸ‰แžผ (Executive Summary)

    แž˜แž“แŸ’แžแŸ’แžšแžธแžฅแžŽแž‘แžถแž“แž‡แžถแž“แŸ‹แžแŸ’แž–แžŸแŸ‹ แž›แŸ„แž€ แžŸแžปแž แžŠแžถแžšแŸ‰แžถ แž“แŸƒแž‚แŸ’แžšแžนแŸ‡แžŸแŸ’แžแžถแž“แž˜แžธแž€แŸ’แžšแžผแž แžทแžšแž‰แŸ’แž‰แžœแžแŸ’แžแžป ADMFI แž”แŸ’แžšแž…แžถแŸ†แžšแžถแž‡แž’แžถแž“แžธแž—แŸ’แž“แŸ†แž–แŸแž‰ แž”แžถแž“แž”แŸ†แž–แŸแž‰แž—แžถแžšแž€แžทแž…แŸ’แž…แž‡แžฝแž”แžขแžแžทแžแžทแž‡แž“แž“แŸ…แž€แŸ’แžšแŸ…แž€แžถแžšแžทแž™แžถแž›แŸแž™ (Off-site) แž“แŸ…แž แžถแž„แž€แžถแž แŸ’แžœแŸแž˜แžฝแž™แž€แž“แŸ’แž›แŸ‚แž„แŸ” แžŠแžผแž…แž‡แžถแž‘แž˜แŸ’แž›แžถแž”แŸ‹แž‘แžผแž‘แŸ…แž“แŸƒแž”แŸ’แžšแžแžทแž”แžแŸ’แžแžทแž€แžถแžšแžฅแžŽแž‘แžถแž“แž“แŸ…แž€แž˜แŸ’แž–แžปแž‡แžถ แž˜แž“แŸ’แžแŸ’แžšแžธแžฅแžŽแž‘แžถแž“แžšแžผแž”แž“แŸแŸ‡แžแŸ‚แž„แžแŸ‚แž”แŸ’แžšแžพแž”แŸ’แžšแžถแžŸแŸ‹ Telegram แžŠแžพแž˜แŸ’แž”แžธแž‘แžถแž€แŸ‹แž‘แž„ แž•แŸ’แž‰แžพ-แž‘แž‘แžฝแž› แžฏแž€แžŸแžถแžšแžŸแŸ’แž“แžพแžŸแžปแŸ†แž€แž˜แŸ’แž…แžธ แžขแžแŸ’แžแžŸแž‰แŸ’แž‰แžถแžŽแž”แŸแžŽแŸ’แžŽ แžšแžผแž”แžแžแž‘แŸ’แžšแž–แŸ’แž™แž’แžถแž“แžถ แž“แžทแž„แž”แŸแžŽแŸ’แžŽแž€แž˜แŸ’แž˜แžŸแžทแž‘แŸ’แž’แžทแžŠแžธแž’แŸ’แž›แžธ (แž”แŸ’แž›แž„แŸ‹แžšแžนแž„/แž”แŸ’แž›แž„แŸ‹แž‘แž“แŸ‹)แŸ”

    แž€แŸ’แž“แžปแž„แžขแŸ†แžกแžปแž„แž–แŸแž›แž’แŸ’แžœแžพแž€แžถแžš แž›แŸ„แž€ แžŸแžปแž แžŠแžถแžšแŸ‰แžถ แž”แžถแž“แž‘แž‘แžฝแž›แžŸแžถแžš Telegram แž–แžธแžขแžแžทแžแžทแž‡แž“แžแŸ’แž˜แžธแž˜แŸ’แž“แžถแž€แŸ‹แžŠแŸ‚แž›แž”แŸ’แžšแžพแž”แŸ’แžšแžถแžŸแŸ‹แžˆแŸ’แž˜แŸ„แŸ‡ "แž›แŸ„แž€แžŸแŸ’แžšแžธ แž‚แžนแž˜ แž…แžถแž“แŸ‹แž’แžธ" แžŠแŸ„แž™แž”แžถแž“แž•แŸ’แž‰แžพ file แžˆแŸ’แž˜แŸ„แŸ‡ แžฏแž€แžŸแžถแžš_แžŸแŸ’แž“แžพแžŸแžปแŸ†_แžฅแžŽแž‘แžถแž“_แŸขแŸ แŸขแŸฆ.zipแŸ” แž”แŸ‰แžปแž“แŸ’แžแŸ‚ แž“แŸ…แž€แŸ’แž“แžปแž„ zip file แž“แŸ„แŸ‡แž˜แžถแž“ file แž”แž„แŸ’แž€แž”แŸ‹แž€แžผแžŠแž˜แŸแžšแŸ„แž‚ (Malware Exe) แžŠแŸ‚แž›แž€แŸ’แž›แŸ‚แž„แž”แž“แŸ’แž›แŸ†แž‡แžถ file PDF แžˆแŸ’แž˜แŸ„แŸ‡ แž›แž€แŸ’แžแžแžŽแŸ’แžŒ_แž€แž˜แŸ’แž…แžธ_แžขแžแžทแžแžทแž‡แž“.pdf.exeแŸ”

    แž“แŸ…แž–แŸแž›แž›แŸ„แž€ แžŠแžถแžšแŸ‰แžถ แž…แžปแž…แž”แžพแž€ file แž“แŸ„แŸ‡ แž€แž˜แŸ’แž˜แžœแžทแž’แžธแž”แžถแž“แž”แž„แŸ’แž แžถแž‰แž•แŸ’แž‘แžถแŸ†แž„ Error แž€แŸ’แž›แŸ‚แž„แž€แŸ’แž›แžถแž™แžแžถ "แž˜แžทแž“แžขแžถแž…แž”แžพแž€แžฏแž€แžŸแžถแžš PDF แž”แžถแž“แž‘แŸ แžŠแŸ„แž™แžŸแžถแžšแžฏแž€แžŸแžถแžšแžแžผแž… (Corrupted File)"แŸ” แžŠแŸ„แž™แž‚แžทแžแžแžถแžขแžแžทแžแžทแž‡แž“แž•แŸ’แž‰แžพ file แžแžผแž… แž›แŸ„แž€ แžŠแžถแžšแŸ‰แžถ แž€แŸแž”แžถแž“แžšแŸ†แž›แž„ แž แžพแž™แž”แž“แŸ’แžแž’แŸ’แžœแžพแž€แžถแžšแž’แž˜แŸ’แž˜แžแžถแŸ” แž”แŸ‰แžปแž“แŸ’แžแŸ‚แž“แŸ…แž–แžธแž€แŸ’แžšแŸ„แž™แžแŸ’แž“แž„ แž˜แŸแžšแŸ„แž‚แž”แžถแž“แž…แžถแž”แŸ‹แž•แŸ’แžแžพแž˜ run แžŠแŸ„แž™แžŸแŸ’แž„แžถแžแŸ‹แŸ— แž‡แŸ’แžšแŸ‚แž€แž…แžผแž›แž”แŸ’แžšแž–แŸแž“แŸ’แž’ laptop แžšแž”แžŸแŸ‹แž›แŸ„แž€ แžŠแžถแžšแŸ‰แžถ แž“แžทแž„แž—แŸ’แž‡แžถแž”แŸ‹แž‘แŸ†แž“แžถแž€แŸ‹แž‘แŸ†แž“แž„แž‘แŸ…แž€แžถแž“แŸ‹ attacker Command & Control (C2) ServerแŸ”

    แž›แžปแŸ‡แžšแžŸแŸ€แž›แžกแžพแž„ แž›แŸ„แž€ แžŠแžถแžšแŸ‰แžถ แž”แžถแž“แžแŸ’แžšแžกแž”แŸ‹แž˜แž€แž€แžถแž“แŸ‹แž€แžถแžšแžทแž™แžถแž›แŸแž™แž€แžŽแŸ’แžแžถแž› ADMFI (Head Office) แž แžพแž™แž”แžถแž“แžŠแŸ„แžแžแŸ’แžŸแŸ‚แž”แžŽแŸ’แžแžถแž‰ LAN แž…แžผแž›แž‘แŸ…แž€แŸ’แž“แžปแž„แž”แžŽแŸ’แžแžถแž‰แž•แŸ’แž‘แŸƒแž€แŸ’แž“แžปแž„ (Corporate Network 10.20.0.0/16)แŸ” แž—แŸ’แž›แžถแž˜แŸ—แž“แŸ„แŸ‡ แž˜แŸแžšแŸ„แž‚ Ransomware แž”แžถแž“แžŠแžนแž„แžแžถ laptop แž”แžถแž“แž—แŸ’แž‡แžถแž”แŸ‹แž…แžผแž›แž”แžŽแŸ’แžแžถแž‰แž’แž“แžถแž‚แžถแžš แž แžพแž™แžœแžถแž”แžถแž“แŸ–

    1. แžŸแŸ’แžœแŸ‚แž„แžšแž€ Shared Drives แžšแž”แžŸแŸ‹แž“แžถแž™แž€แžŠแŸ’แž‹แžถแž“แžฅแžŽแž‘แžถแž“ (\\ADMFI-FS01\Loan_Share$)

    2. แž”แŸ†แž–แžถแž“แžŸแžทแž‘แŸ’แž’แžท (Abuse Authenticated Token) แžšแž”แžŸแŸ‹แž›แŸ„แž€ แžŠแžถแžšแŸ‰แžถ แžŠแžพแž˜แŸ’แž”แžธแž›แžฝแž…แž‘แžทแž“แŸ’แž“แž“แŸแž™แžขแžแžทแžแžทแž‡แž“ (Data Exfiltration) แž•แŸ’แž‰แžพแž‘แŸ… C2 Server

    3. แž…แžถแž”แŸ‹แž•แŸ’แžแžพแž˜ Encrypt (แžŸแžšแžŸแŸแžšแž€แžผแžŠแž…แŸ„แžš) แž›แžพแžšแžถแž›แŸ‹แžฏแž€แžŸแžถแžšแž‘แžถแŸ†แž„แžขแžŸแŸ‹แž“แŸ…แž›แžพ Laptop แž“แžทแž„ Shared Folder แžšแž”แžŸแŸ‹แž€แŸ’แžšแžปแž˜แžฅแžŽแž‘แžถแž“ แžŠแŸ„แž™แž”แŸ’แžแžผแžš extension แž‘แŸ…แž‡แžถ .ADMFI_LOCKED

    4. แž”แž„แŸ’แž แžถแž‰ Ransom Note แž‘แžถแžšแž”แŸ’แžšแžถแž€แŸ‹แž…แŸ†แž“แžฝแž“ $50,000 USD แž‡แžถ Bitcoin/USDTแŸ”


    2. แžแžฝแžขแž„แŸ’แž‚ แž“แžทแž„ แž€แŸ’แžšแžปแž˜แž€แžถแžšแž„แžถแžšแž€แŸ’แž“แžปแž„แžŸแŸแžŽแžถแžšแžธแž™แŸ‰แžผ (Key Persona & Roles)

    แžˆแŸ’แž˜แŸ„แŸ‡ / แžแžฝแž“แžถแž‘แžธแž—แžถแžŸแžถแžขแž„แŸ‹แž‚แŸ’แž›แŸแžŸแž—แžถแžšแž€แžทแž…แŸ’แž…แž€แŸ’แž“แžปแž„แžŸแŸแžŽแžถแžšแžธแž™แŸ‰แžผ
    แž›แŸ„แž€ แžŸแžปแž แžŠแžถแžšแŸ‰แžถSenior Loan Officerแž‡แž“แžšแž„แž‚แŸ’แžšแŸ„แŸ‡แžŠแŸ†แž”แžผแž„ (Initial Victim) แžŠแŸ‚แž›แž”แžถแž“แž”แžพแž€ file แž˜แŸแžšแŸ„แž‚แžแžถแž˜ Telegram แž–แŸแž›แž’แŸ’แžœแžพแž€แžถแžš off-site
    แž›แŸ„แž€แžŸแŸ’แžšแžธ แž‚แžนแž˜ แž…แžถแž“แŸ‹แž’แžธ (Fake)Threat Actor / Phisherแž‚แžŽแž“แžธ Telegram แž€แŸ’แž›แŸ‚แž„แž€แŸ’แž›แžถแž™แžŠแŸ‚แž›แž•แŸ’แž‰แžพ payload แž˜แŸแžšแŸ„แž‚ Ransomware
    แž›แŸ„แž€ แž€แŸ‚แžœ แž…แžถแž“แŸ‹แž“แžธSOC L1 AnalystแžขแŸ’แž“แž€แž‘แž‘แžฝแž›แž”แžถแž“ Alert แžŠแŸ†แž”แžผแž„แž–แžธ EDR/SIEM แž“แžทแž„แž‡แžถแžขแŸ’แž“แž€แž”แž„แŸ’แž€แžพแž ITSM Incident Ticket
    แž›แŸ„แž€ แžˆแŸ€แž„ แžœแžปแžŒแŸ’แžแžธSOC L2 AnalystแžขแŸ’แž“แž€แžŠแžนแž€แž“แžถแŸ†แž€แžถแžšแžŸแŸŠแžพแž”แžขแž„แŸ’แž€แŸแžแž”แž…แŸ’แž…แŸแž€แž‘แŸแžŸ แž’แŸ’แžœแžพ Forensic Timeline แž“แžทแž„ Isolate Host
    แž›แŸ„แž€ แž แŸŠแžถแž„ แžŸแžปแž•แž›SOC Lead / L3แžขแŸ’แž“แž€แžœแžทแž—แžถแž‚แž˜แŸแžšแŸ„แž‚แž‡แž˜แŸ’แžšแŸ…แž‡แŸ’แžšแŸ… (Malware Reverse Engineering) แž“แžทแž„แž‡แžฝแž™แžŸแž˜แŸ’แžšแŸแž… containment
    แž›แŸ„แž€แžŸแŸ’แžšแžธ แž”แŸŠแžปแž”แŸ’แž•แžถCISOแžขแŸ’แž“แž€แž‚แŸ’แžšแž”แŸ‹แž‚แŸ’แžšแž„แž™แžปแž‘แŸ’แž’แžŸแžถแžŸแŸ’แžแŸ’แžš แžŸแžปแžœแžแŸ’แžแžทแž—แžถแž–แž–แŸแžแŸŒแž˜แžถแž“ แž“แžทแž„แžšแžถแž™แž€แžถแžšแžŽแŸแž‡แžผแž“ แž’แž“แžถแž‚แžถแžšแž‡แžถแžแžทแž“แŸƒแž€แž˜แŸ’แž–แžปแž‡แžถ (NBC)
    แž›แŸ„แž€ แž…แžถแž“แŸ‹ แžœแžทแžŸแžถแž›CIOแžขแŸ’แž“แž€แžŸแž˜แŸ’แžšแŸแž…แž…แžทแžแŸ’แžแž›แžพแž”แŸ’แžšแž–แŸแž“แŸ’แž’ Core Banking, IT Infrastructure แž“แžทแž„แž€แžถแžšแž”แŸ’แžšแž€แžถแžŸ BCP

    3. แž›แŸ†แž แžผแžšแž“แŸƒแž€แžถแžšแžœแžถแž™แž”แŸ’แžšแž แžถแžš (Attack Progression Flowchart)

    flowchart TD A["๐Ÿ‘จโ€๐Ÿ’ผ แž›แŸ„แž€ แžŸแžปแž แžŠแžถแžšแŸ‰แžถ แž”แŸ†แž–แŸแž‰แž—แžถแžšแž€แžทแž…แŸ’แž… Off-site<br/>๐Ÿ“ฑ แž”แŸ’แžšแžพแž”แŸ’แžšแžถแžŸแŸ‹ Telegram แž‘แŸ†แž“แžถแž€แŸ‹แž‘แŸ†แž“แž„แžขแžแžทแžแžทแž‡แž“"] B["๐ŸŽฃ Telegram แž€แŸ’แž›แŸ‚แž„แž€แŸ’แž›แžถแž™แž•แŸ’แž‰แžพ file<br/>๐Ÿ“ฆ แžฏแž€แžŸแžถแžš_แžŸแŸ’แž“แžพแžŸแžปแŸ†_แžฅแžŽแž‘แžถแž“_แŸขแŸ แŸขแŸฆ.zip"] C["โš ๏ธ แž›แŸ„แž€ แžŠแžถแžšแŸ‰แžถ แž…แžปแž…แž”แžพแž€ file PDF แž€แŸ’แž›แŸ‚แž„แž€แŸ’แž›แžถแž™<br/>โŒ แž…แŸแž‰แž•แŸ’แž‘แžถแŸ†แž„ Error แž€แŸแžšแŸ†แž›แž„แž…แŸ„แž›"] D["๐Ÿฆ  แž˜แŸแžšแŸ„แž‚แžšแžแŸ‹แžŠแŸ„แž™แžŸแŸ’แž„แžถแžแŸ‹แŸ— (Silent Execution)<br/>๐ŸŒ แž—แŸ’แž‡แžถแž”แŸ‹แž‘แŸ… C2 Server (Attacker Infrastructure)"] E["๐Ÿข แžแŸ’แžšแžกแž”แŸ‹แž˜แž€แž€แžถแžšแžทแž™แžถแž›แŸแž™แž€แžŽแŸ’แžแžถแž› ADMFI<br/>๐Ÿ”Œ แžŠแŸ„แžแžแŸ’แžŸแŸ‚ LAN แž…แžผแž›แž”แžŽแŸ’แžแžถแž‰ Corporate Network"] F["๐Ÿ“‚ แž˜แŸแžšแŸ„แž‚แžŸแŸ’แž€แŸ‚แž“แžšแž€ Shared Drive<br/>๐Ÿ”‘ แž”แŸ†แž–แžถแž“แžŸแžทแž‘แŸ’แž’แžทแžŠแž€แžŸแŸ’แžšแž„แŸ‹แž‘แžทแž“แŸ’แž“แž“แŸแž™ (Abuse SMB Access)"] G["๐Ÿ“‘ แž‘แžทแž“แŸ’แž“แž“แŸแž™แž€แž˜แŸ’แž…แžธ แž“แžทแž„ แž”แŸ’แž›แž„แŸ‹แžŠแžธแžขแžแžทแžแžทแž‡แž“<br/>๐Ÿ“ค แžแŸ’แžšแžผแžœแž‚แŸแž›แžฝแž…แž•แŸ’แž‰แžพแž…แŸแž‰ (Data Exfiltrated)"] H["๐Ÿ”’ Ransomware แžŠแŸ†แžŽแžพแžšแž€แžถแžš Encryption<br/>แžšแžถแž›แŸ‹แžฏแž€แžŸแžถแžšแž”แŸ’แžšแŸ‚แž‡แžถ file .ADMFI_LOCKED"] I["๐Ÿšจ EDR CrowdStrike แž†แŸ‚แž€แžƒแžพแž‰ Ransomware Activity<br/>๐Ÿ“Š SIEM QRadar แž‘แž‘แžฝแž›แž”แžถแž“ Alert แž…แŸ’แžšแžพแž“แž‘แžทแžŸแžŠแŸ…"] J["๐Ÿ’€ Laptop แž€แž€แžŸแŸ’แž‘แŸ‡ แž“แžทแž„ แž”แž„แŸ’แž แžถแž‰ Ransom Note<br/>๐Ÿ’ฐ แž‘แžถแžšแž”แŸ’แžšแžถแž€แŸ‹ $50,000 แžแžถแž˜ Crypto"] K["โ˜Ž๏ธ แž›แŸ„แž€ แžŠแžถแžšแŸ‰แžถ แžšแžถแž™แž€แžถแžšแžŽแŸแž‘แŸ… IT Helpdesk<br/>๐Ÿ‘ฎ SOC แž”แŸ’แžšแž€แžถแžŸแžขแžถแžŸแž“แŸ’แž“ SEV-1 Incident"] A --> B --> C --> D --> E E --> F --> G --> H H --> I --> J J --> K classDef user fill:#E8F1FB,stroke:#2F75B5,color:#17365D; classDef threat fill:#FCE4D6,stroke:#C00000,color:#7F0000; classDef detect fill:#E2F0D9,stroke:#548235,color:#375623; classDef response fill:#E4DFEC,stroke:#7030A0,color:#3F1D5A; class A,C,K user; class B,D,F,G,H threat; class I detect; class J response;

    4. แžŠแŸ†แžŽแžพแžšแž€แžถแžšแž†แŸ’แž›แžพแž™แžแž”แžขแžถแžŸแž“แŸ’แž“ SOP (Incident Response SOP Flowchart)

    flowchart TD subgraph Phase1["๐Ÿ›ก๏ธ แžŠแŸ†แžŽแžถแž€แŸ‹แž€แžถแž›แž‘แžธ แŸกแŸ– แž€แžถแžšแžŸแŸ’แžœแŸ‚แž„แžšแž€ แž“แžทแž„ แž•แŸ’แž‘แŸ€แž„แž•แŸ’แž‘แžถแžแŸ‹ (Detection & Triage)"] P1_1["๐Ÿšจ CrowdStrike EDR & SIEM Alert<br/>โ˜Ž๏ธ แž›แŸ„แž€ แžŠแžถแžšแŸ‰แžถ แžšแžถแž™แž€แžถแžšแžŽแŸแž˜แž€ Helpdesk"] P1_2["๐Ÿ‘จโ€๐Ÿ’ป SOC L1 (แž›แŸ„แž€ แž…แžถแž“แŸ‹แž“แžธ) แž•แŸ’แž‘แŸ€แž„แž•แŸ’แž‘แžถแžแŸ‹ Alert<br/>แž”แž„แŸ’แž€แžพแž ITSM Ticket #INC-2026-0814"] P1_3["โฑ๏ธ แž”แž‰แŸ’แž‡แžผแž“แž‘แŸ… SOC L2 (แž›แŸ„แž€ แžœแžปแžŒแŸ’แžแžธ)<br/>แž€แŸ’แž“แžปแž„แžšแž™แŸˆแž–แŸแž›แž€แŸ’แžšแŸ„แž˜ แŸกแŸฅ แž“แžถแž‘แžธ"] P1_1 --> P1_2 --> P1_3 end subgraph Phase2["๐Ÿš’ แžŠแŸ†แžŽแžถแž€แŸ‹แž€แžถแž›แž‘แžธ แŸขแŸ– แž€แžถแžšแž‘แž”แŸ‹แžŸแŸ’แž€แžถแžแŸ‹แž‡แžถแž”แž“แŸ’แž‘แžถแž“แŸ‹ (Containment Workstreams)"] P2_1["๐Ÿ”Œ EDR Network Isolation<br/>แž€แžถแžแŸ‹แž•แŸ’แžŠแžถแž…แŸ‹ Laptop แž›แŸ„แž€ แžŠแžถแžšแŸ‰แžถ แž…แŸแž‰แž–แžธแž”แžŽแŸ’แžแžถแž‰"] P2_2["๐Ÿ”‘ Lock AD Account 'sok.dara'<br/>แž“แžทแž„ Revoke Active Tokens/Sessions"] P2_3["๐ŸŒ Firewall Block C2 IPs<br/>(185.220.101.45 & mal-c2.admfi-verify.com)"] P2_4["๐Ÿ“‚ แž”แžทแž‘ SMB Write Access แž›แžพ File Server<br/>`\\ADMFI-FS01\Loan_Share$`"] P1_3 --> P2_1 & P2_2 & P2_3 & P2_4 end subgraph Phase3["๐Ÿ‘” แžŠแŸ†แžŽแžถแž€แŸ‹แž€แžถแž›แž‘แžธ แŸฃแŸ– แž€แžถแžšแž‚แŸ’แžšแž”แŸ‹แž‚แŸ’แžšแž„แžœแžทแž”แžแŸ’แžแžท แž“แžทแž„ แžšแžถแž™แž€แžถแžšแžŽแŸ (Crisis Management)"] P3_1["๐Ÿ“ข SOC Manager แž”แŸ’แžšแž€แžถแžŸ MAJOR INCIDENT SEV-1"] P3_2["๐Ÿ’ฌ แž”แž„แŸ’แž€แžพแž WAR Room (Microsoft Teams / Incident Command Board)"] P3_3["๐Ÿ“ž แž‡แžผแž“แžŠแŸ†แžŽแžนแž„แžŠแž›แŸ‹ CIO (แž›แŸ„แž€ แžœแžทแžŸแžถแž›) & CISO (แž›แŸ„แž€แžŸแŸ’แžšแžธ แž”แŸŠแžปแž”แŸ’แž•แžถ)"] P3_4["๐Ÿ›๏ธ แžšแŸ€แž”แž…แŸ†แž›แžทแžแžทแžแž‡แžผแž“แžŠแŸ†แžŽแžนแž„แž•แŸ’แž›แžผแžœแž€แžถแžšแž‘แŸ… **แž’แž“แžถแž‚แžถแžšแž‡แžถแžแžทแž“แŸƒแž€แž˜แŸ’แž–แžปแž‡แžถ (NBC)** & **CamCERT**"] P2_1 & P2_2 & P2_3 & P2_4 --> P3_1 --> P3_2 --> P3_3 --> P3_4 end subgraph Phase4["๐Ÿ”„ แžŠแŸ†แžŽแžถแž€แŸ‹แž€แžถแž›แž‘แžธ แŸคแŸ– แž€แžถแžšแžŸแŸ’แžแžถแžšแž”แŸ’แžšแž–แŸแž“แŸ’แž’แžกแžพแž„แžœแžทแž‰ (Eradication & Recovery)"] P4_1["๐Ÿงน Re-image Laptop แžšแž”แžŸแŸ‹แž›แŸ„แž€ แžŠแžถแžšแŸ‰แžถ แžกแžพแž„แžœแžทแž‰"] P4_2["๐Ÿ’พ Restore File Server `Loan_Share$` แž–แžธ Clean Immutable Backup"] P4_3["๐Ÿ” แž•แŸ’แž›แžถแžŸแŸ‹แž”แŸ’แžแžผแžšแž›แŸแžแžŸแž˜แŸ’แž„แžถแžแŸ‹ (Credential Rotation) แž‚แžŽแž“แžธแž–แžถแž€แŸ‹แž–แŸแž“แŸ’แž’"] P4_4["โœ… CISO & CIO แžขแž“แžปแž˜แŸแžแžฒแŸ’แž™แž”แŸ’แžšแž–แŸแž“แŸ’แž’แžŠแŸ†แžŽแžพแžšแž€แžถแžšแžกแžพแž„แžœแžทแž‰"] P3_4 --> P4_1 --> P4_2 --> P4_3 --> P4_4 end classDef detect fill:#E2F0D9,stroke:#548235,color:#375623; classDef contain fill:#FFF2CC,stroke:#BF8F00,color:#7F6000; classDef crisis fill:#F4CCCC,stroke:#C00000,color:#7F0000; classDef recover fill:#D9EAF7,stroke:#2F75B5,color:#17365D; class P1_1,P1_2,P1_3 detect; class P2_1,P2_2,P2_3,P2_4 contain; class P3_1,P3_2,P3_3,P3_4 crisis; class P4_1,P4_2,P4_3,P4_4 recover;

    5. แž”แŸ’แžšแž’แžถแž“แž”แž‘ แž“แžทแž„ แž…แŸ„แž‘แžŸแžฝแžšแžŸแž˜แŸ’แžšแžถแž”แŸ‹แž–แžทแž—แžถแž€แŸ’แžŸแžถ (TTX Discussion Injects)

    Tip: ๐ŸŽฏ แž‚แŸ„แž›แž”แŸ†แžŽแž„แžšแŸ€แž”แž…แŸ† TTX: แžŠแžพแž˜แŸ’แž”แžธแžŸแžถแž€แž›แŸ’แž”แž„แž—แžถแž–แžšแžฝแž…แžšแžถแž›แŸ‹แžšแž”แžŸแŸ‹แž€แŸ’แžšแžปแž˜แž€แžถแžšแž„แžถแžšแž”แž…แŸ’แž…แŸแž€แž‘แŸแžŸ (SOC, Network, System), แž€แŸ’แžšแžปแž˜แž€แžถแžšแž„แžถแžšแžฅแžŽแž‘แžถแž“, แž“แžถแž™แž€แžŠแŸ’แž‹แžถแž“แž…แŸ’แž”แžถแž”แŸ‹, แž“แžทแž„ แžแŸ’แž“แžถแž€แŸ‹แžŠแžนแž€แž“แžถแŸ†แž‡แžถแž“แŸ‹แžแŸ’แž–แžŸแŸ‹ แž€แŸ’แž“แžปแž„แž€แžถแžšแž†แŸ’แž›แžพแž™แžแž”แž“แžนแž„แž€แžถแžšแžœแžถแž™แž”แŸ’แžšแž แžถแžš Cyber IncidentแŸ”

    ๐Ÿ”น Inject 1: แž”แž‰แŸ’แž แžถแž”แŸ’แžšแžˆแž˜แž“แŸƒแž€แžถแžšแž”แŸ’แžšแžพแž”แŸ’แžšแžถแžŸแŸ‹ Telegram แž€แŸ’แž“แžปแž„แž”แŸ’แžšแžแžทแž”แžแŸ’แžแžทแž€แžถแžšแžฅแžŽแž‘แžถแž“ (Off-site Work Risks)

  • แžŸแŸ’แžแžถแž“แž—แžถแž–: แž˜แž“แŸ’แžแŸ’แžšแžธแžฅแžŽแž‘แžถแž“แž‘แžผแž‘แžถแŸ†แž„แž”แŸ’แžšแž‘แŸแžŸแž€แž˜แŸ’แž–แžปแž‡แžถ แž”แŸ’แžšแžพแž”แŸ’แžšแžถแžŸแŸ‹ Telegram แžŠแžพแž˜แŸ’แž”แžธแž•แŸ’แž‰แžพแžฏแž€แžŸแžถแžšแžขแžแžทแžแžทแž‡แž“แŸ” แžแžพแž’แž“แžถแž‚แžถแžš ADMFI แž˜แžถแž“แž‚แŸ„แž›แž€แžถแžšแžŽแŸ Security Policy แž“แžทแž„ Mobile Device Management (MDM) แž™แŸ‰แžถแž„แžŽแžถแžแŸ’แž›แŸ‡แžŠแžพแž˜แŸ’แž”แžธแž€แžถแžšแž–แžถแžšแžฏแž€แžŸแžถแžšแž‘แžถแŸ†แž„แž“แŸแŸ‡?
  • แžŸแŸ†แžŽแžฝแžšแž–แžทแž—แžถแž€แŸ’แžŸแžถ:
  • 1. แžแžพแžแŸ’แžšแžผแžœแž€แŸ†แžŽแžแŸ‹แžŸแž˜แŸ’แžšแŸแž…แž™แŸ‰แžถแž„แžŽแžถ แž…แŸ†แž–แŸ„แŸ‡แž€แžถแžšแžขแž“แžปแž‰แŸ’แž‰แžถแž แžฌ แž แžถแž˜แžƒแžถแžแŸ‹แž€แžถแžšแž‘แžถแž‰แž™แž€ file แž–แžธ Telegram แž…แžผแž›แž€แŸ’แž“แžปแž„ Laptop แž€แŸ’แžšแžปแž˜แž แŸŠแžปแž“?

    2. แž”แŸ’แžšแžŸแžทแž“แž”แžพแžขแžแžทแžแžทแž‡แž“แž•แŸ’แž‰แžพ file .zip แžฌ .rar แžแžพแž”แŸ’แžšแž–แŸแž“แŸ’แž’แžŸแžปแžœแžแŸ’แžแžทแž—แžถแž–แžขแžปแžธแž˜แŸ‚แž› แžฌ Endpoint Defender แž‚แžฝแžšแžแŸ‚แž’แŸ’แžœแžพแž€แžถแžšแž‘แž”แŸ‹แžŸแŸ’แž€แžถแžแŸ‹แžŠแŸ„แž™แžŸแŸ’แžœแŸแž™แž”แŸ’แžšแžœแžแŸ’แžแžทแžŠแŸ‚แžšแžฌแž‘แŸ?


    ๐Ÿ”น Inject 2: แž€แžถแžšแž‘แž”แŸ‹แžŸแŸ’แž€แžถแžแŸ‹แž–แŸแž› Ransomware แž…แžถแž”แŸ‹แž•แŸ’แžแžพแž˜ encrypt file แž›แžพ Shared Drive

  • แžŸแŸ’แžแžถแž“แž—แžถแž–: EDR แžƒแžพแž‰ Egress Connection แžแžปแžŸแž”แŸ’แžšแž€แŸ’แžšแžแžธ แž“แžทแž„แžƒแžพแž‰แžฏแž€แžŸแžถแžšแž€แŸ’แž“แžปแž„ Shared Folder \\ADMFI-FS01\Loan_Share$ แžแŸ’แžšแžผแžœแž”แŸ’แžšแŸ‚แžˆแŸ’แž˜แŸ„แŸ‡แž‡แžถ .ADMFI_LOCKED แž€แŸ’แž“แžปแž„แž›แŸ’แž”แžฟแž“ แŸฅแŸ  files/แžœแžทแž“แžถแž‘แžธแŸ”
  • แžŸแŸ†แžŽแžฝแžšแž–แžทแž—แžถแž€แŸ’แžŸแžถ:
  • 1. แžแžพ SOC L1/L2 แž˜แžถแž“แžŸแžทแž‘แŸ’แž’แžทแžขแŸ†แžŽแžถแž…แž–แŸแž‰แž›แŸแž‰แž€แŸ’แž“แžปแž„แž€แžถแžš Isolate Laptop แžšแž”แžŸแŸ‹แž›แŸ„แž€ แžŠแžถแžšแŸ‰แžถ แžŠแŸ„แž™แž˜แžทแž“แž”แžถแž…แŸ‹แžšแž„แŸ‹แž…แžถแŸ†แž€แžถแžšแž™แž›แŸ‹แž–แŸ’แžšแž˜แž–แžธ Business Owner แžŠแŸ‚แžšแžฌแž‘แŸ?

    2. แžแžพแžแŸ’แžšแžผแžœแž’แŸ’แžœแžพแžŠแžผแž…แž˜แŸ’แžแŸแž…แžŠแžพแž˜แŸ’แž”แžธแž€แžถแžšแž–แžถแžš Shared Drives แž•แŸ’แžŸแŸแž„แž‘แŸ€แž (แžŠแžผแž…แž‡แžถ HR, Finance, Core Banking Backups) แž˜แžทแž“แžฒแŸ’แž™แžšแž›แžถแž›แž†แŸ’แž›แž„แžŠแž›แŸ‹?


    ๐Ÿ”น Inject 3: แž€แžถแžšแž‚แŸ’แžšแž”แŸ‹แž‚แŸ’แžšแž„แžœแžทแž”แžแŸ’แžแžท แž“แžทแž„ แž€แžถแžแž–แŸ’แžœแž€แžทแž…แŸ’แž…แž…แŸ’แž”แžถแž”แŸ‹/แž”แž‘แž”แŸ’แž”แž‰แŸ’แž‰แžแŸ’แžแžท (NBC Compliance & Data Leak)

  • แžŸแŸ’แžแžถแž“แž—แžถแž–: Attacker แž”แžถแž“แž•แŸ’แž‰แžพแžŸแžถแžšแž‚แŸ†แžšแžถแž˜แžแžถ แž–แžฝแž€แž‚แŸแž”แžถแž“แž›แžฝแž…แž™แž€แž‘แžทแž“แŸ’แž“แž“แŸแž™แžขแžแŸ’แžแžŸแž‰แŸ’แž‰แžถแžŽแž”แŸแžŽแŸ’แžŽ แž“แžทแž„แž”แŸ’แž›แž„แŸ‹แžŠแžธแžšแž”แžŸแŸ‹แžขแžแžทแžแžทแž‡แž“แž…แŸ†แž“แžฝแž“ แŸฃ,แŸฅแŸ แŸ  แž“แžถแž€แŸ‹ แž แžพแž™แž“แžนแž„แž‘แžถแžšแž”แŸ’แžšแžถแž€แŸ‹ $50,000 แž‡แžถแžแŸ’แž“แžผแžšแž“แžนแž„แž€แžถแžšแž˜แžทแž“แž‘แž˜แŸ’แž›แžถแž™แž›แžพ Dark WebแŸ”
  • แžŸแŸ†แžŽแžฝแžšแž–แžทแž—แžถแž€แŸ’แžŸแžถ:
  • 1. แžแžพแž’แž“แžถแž‚แžถแžš ADMFI แž˜แžถแž“แž‚แŸ„แž›แž€แžถแžšแžŽแŸ "แž˜แžทแž“แž”แž„แŸ‹แž”แŸ’แžšแžถแž€แŸ‹แž›แŸ„แŸ‡ (No-Ransom Policy)" แžŠแŸ‚แžšแžฌแž‘แŸ?

    2. แžแžพแž“แžถแž™แž€แžŠแŸ’แž‹แžถแž“แž…แŸ’แž”แžถแž”แŸ‹ แž“แžทแž„ CISO แžแŸ’แžšแžผแžœแžšแžถแž™แž€แžถแžšแžŽแŸแž‡แžผแž“ แž’แž“แžถแž‚แžถแžšแž‡แžถแžแžทแž“แŸƒแž€แž˜แŸ’แž–แžปแž‡แžถ (NBC) แž“แžทแž„ CamCERT แž€แŸ’แž“แžปแž„แžšแž™แŸˆแž–แŸแž›แž”แŸ‰แžปแž“แŸ’แž˜แžถแž“แž˜แŸ‰แŸ„แž„แž”แž“แŸ’แž‘แžถแž”แŸ‹แž–แžธแžŠแžนแž„แžแžถแž˜แžถแž“แž‘แžทแž“แŸ’แž“แž“แŸแž™แž›แŸแž…แž’แŸ’แž›แžถแž™?

    3. แžแžพแžแŸ’แžšแžผแžœแž†แŸ’แž›แžพแž™แžแž”แž“แžนแž„แžŸแžถแžšแž–แŸแžแŸŒแž˜แžถแž“ (Public Relations) แž™แŸ‰แžถแž„แžŠแžผแž…แž˜แŸ’แžแŸแž… แž”แŸ’แžšแžŸแžทแž“แž”แžพแž–แŸแžแŸŒแž˜แžถแž“แž“แŸแŸ‡แž›แŸแž…แž’แŸ’แž›แžถแž™แž›แžพแž”แžŽแŸ’แžแžถแž‰แžŸแž„แŸ’แž‚แž˜ Facebook/Telegram?


    6. แžŸแžผแž…แž“แžถแž€แžšแž”แž…แŸ’แž…แŸแž€แž‘แŸแžŸแž“แŸƒแž€แžถแžšแžœแžถแž™แž”แŸ’แžšแž แžถแžš (Technical IOCs Table)

    แž”แŸ’แžšแž—แŸแž‘ (Type)แž–แŸแžแŸŒแž˜แžถแž“แž”แž…แŸ’แž…แŸแž€แž‘แŸแžŸ (Indicator / Value)แž€แžถแžšแž–แžทแž–แžŽแŸŒแž“แžถ (Description)
    File Nameแžฏแž€แžŸแžถแžš_แžŸแŸ’แž“แžพแžŸแžปแŸ†_แžฅแžŽแž‘แžถแž“_แŸขแŸ แŸขแŸฆ.zipArchive file แžŠแŸ‚แž›แž‘แž‘แžฝแž›แž”แžถแž“แžแžถแž˜ Telegram
    Payload Executableแž›แž€แŸ’แžแžแžŽแŸ’แžŒ_แž€แž˜แŸ’แž…แžธ_แžขแžแžทแžแžทแž‡แž“.pdf.exeDouble extension malware executable
    SHA-256 Hashe3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Malicious Trojan Loader Hash
    C2 Domainmal-c2.admfi-verify.comAttacker Command and Control Server Domain
    C2 IP Address185.220.101.45External Malicious IP (Blocked at Firewall)
    Encrypted Extension.ADMFI_LOCKEDFile extension after ransomware encryption
    Ransom Note FileREAD_ME_FOR_DECRYPT.txtInstructions left by attackers on desktop and file shares
    Attacker Telegram ID@chanthy_loan_applicant_2026Phishing Account used to target Loan Officers

    7. แžแžถแžšแžถแž„ RACI Matrix แžŸแž˜แŸ’แžšแžถแž”แŸ‹ Incident Response (ADMFI Context)

    แžŠแŸ†แžŽแžถแž€แŸ‹แž€แžถแž› (Phase)SOC (L1/L2/L3)Network & IT SysBusiness Owner (Loan)CISO / LegalCIO / ExCo
    แŸก. Detection & TriageAccountable / ResponsibleInformedInformedInformedInformed
    แŸข. Host & User ContainmentResponsibleConsultedInformedInformedInformed
    แŸฃ. Network & Server IsolationConsultedResponsibleInformedInformedInformed
    แŸค. Crisis Escalation & NBC CommsConsultedInformedInformedResponsibleAccountable
    แŸฅ. Eradication & Backup RecoveryConsultedResponsibleConsultedConsultedAccountable
    แŸฆ. Final RCA & ClosureResponsibleConsultedConsultedConsultedAccountable

    Tip: ๐Ÿ“ แž…แŸ†แžŽแžถแŸ†แž”แž“แŸ’แžแŸ‚แž˜ (Note): แžฏแž€แžŸแžถแžšแž“แŸแŸ‡แžแŸ’แžšแžผแžœแž”แžถแž“แž”แž„แŸ’แž€แžพแžแžกแžพแž„แžŸแž˜แŸ’แžšแžถแž”แŸ‹แž”แž˜แŸ’แžšแžพแžฒแŸ’แž™แž€แžถแžšแžŸแžทแž€แŸ’แžŸแžถ แž“แžทแž„แž€แžถแžšแž’แŸ’แžœแžพแž›แŸ†แž แžถแžแŸ‹แžŸแž˜แž™แžปแž‘แŸ’แž’ (Tabletop Exercise) แž•แŸ’แž“แŸ‚แž€แžŸแžปแžœแžแŸ’แžแžทแž—แžถแž–แžŸแžถแž™แž”แŸแžšแžแŸ‚แž”แŸ‰แžปแžŽแŸ’แžŽแŸ„แŸ‡แŸ” แžšแžถแž›แŸ‹แžˆแŸ’แž˜แŸ„แŸ‡ แž’แž“แžถแž‚แžถแžš แž“แžทแž„แž”แžปแž‚แŸ’แž‚แž›แž“แŸ…แž€แŸ’แž“แžปแž„แžŸแŸแžŽแžถแžšแžธแž™แŸ‰แžผแž“แŸแŸ‡แž‚แžบแž‡แžถแžˆแŸ’แž˜แŸ„แŸ‡แžŸแž˜แŸ’แž˜แžแžทแž€แž˜แŸ’แž˜ (Fictional Scenario)แŸ”

    ๐Ÿ›ก๏ธ TTX Ransomware Exercise Scenario

    Tip: ๐Ÿ“– Interactive Storybook: Read ttx_story_book.md for chapter prose, dramatic plot twists, character twist questions, and visual assets. ๐Ÿ‰ D&D Style Campaign Guide: See dnd_campaign_guide.md for full start-to-finish gamified roleplay scripts and D20 dice mechanics. ๐Ÿ“Š PowerPoint Presentation: Download Ransomware_Incident_TTX_Presentation.pptx for executive briefings. ๐Ÿš€ Interactive TTX Portal & Slide Deck: Open index.html in your browser for full-screen slide presentations and interactive injects. ๐ŸŽ“ Facilitator Guide: See facilitator_guide.md for step-by-step facilitator scripts and discussion prompts. ๐ŸŽญ Role Cards: Explore character roles in roles/ . ๐Ÿ“ธ Visual Screenshots: View high-resolution threat mockups in assets/ .

    Summary

    Loan officers regularly work off-site to meet customers and primarily use Telegram to communicate and exchange loan applications, contracts, identification records, and supporting documents. He receives a compressed archive named Customer_Documents_2026.zip through Telegram from what appears to be a legitimate customer. The archive contains a malicious executable disguised as a PDF document.

    The employee extracts the archive and opens the apparent PDF file. A fake document error appears, leading the employee to assume that the customer sent a corrupted document. No administrator credentials are requested, and no software installation window appears. The employee ignores the error and continues working.

    Behind the fake error message, malware begins running silently under the employee's standard user account. It establishes user-level persistence, communicates with attacker-controlled command-and-control infrastructure, and waits for access to the corporate environment.

    Later, the employee returns to the office and reconnects the infected laptop to the corporate LAN. The malware detects the corporate network and begins several activities in parallel, It discovers accessible Loan Team file shares and abuses the employee's existing authenticated access. It collects sensitive loan and customer documents and attempts to exfiltrate them. It targets available authentication information and attempts to access other systems authorized to the employee. After completing its initial discovery and data-collection activities, the attacker activates the ransomware. The ransomware begins encrypting files stored locally on the Loan Team laptop and documents within accessible Loan Team shared folders.

    EDR detects the ransomware behavior and generates a critical alert. At the same time, the SIEM receives and correlates multiple security events from EDR, the firewall, Active Directory, and file servers. These events indicate suspicious external communication, abnormal authentication activity, unusually high file access, and rapid modification of shared documents.

    The employee's laptop becomes unresponsive and displays a ransom note. The employee reports the issue to the Help Desk, while the SOC begins reviewing the EDR and SIEM alerts. The SOC validates the ransomware activity, contains the affected endpoint and identity, activates the Incident Response process, assesses the potential impact on Loan Team file shares and customer data, and informs cybersecurity and management stakeholders.

    Scenarios Flow

    flowchart TD A["๐Ÿ‘จโ€๐Ÿ’ผ Loan works off-site<br/>๐Ÿ“ฑ Telegram for Comm."] B["๐ŸŽฃ Fake customer sends<br/>๐Ÿ“ฆ Customer_Doc_2026.zip"] C["โš ๏ธ He opens file<br/>โŒ Got error but ignored"] D["๐Ÿฆ  Malware run silently<br/>๐ŸŒ Connect to C2"] E["๐Ÿข He returns office<br/>๐Ÿ”Œ Connects PC to LAN"] F["๐Ÿ“‚ Malware got FileShare<br/>๐Ÿ”‘ Abuses Auth access"] G["๐Ÿ“‘ Loan/customer Info<br/>๐Ÿ“ค Collected & exfiltrated"] H["๐Ÿ–ฅ๏ธ Attacker attempts on <br/>โžก๏ธ Other internal systems"] I["๐Ÿ”’ Ransomware encrypts<br/> Loan PC & Shared Folders"] J["๐Ÿ›ก๏ธ EDR detects Ransom<br/>๐Ÿšจ Critical SecAlert"] K["๐Ÿ“Š SIEM/Firewall/AD/FileShare<br/>โšก Multiple alerts"] L["๐Ÿ’€ Laptop freezes<br/>๐Ÿ’ฐ Ransom note appears"] M["โ˜Ž๏ธ Employee reports<br/>๐Ÿ› ๏ธ HelpDesk"] N["๐Ÿ‘ฎ SOC Triage/containt<br/>๐Ÿšจ IR Activated<br/>๐Ÿ“ข Inform Management"] A --> B --> C --> D --> E E --> F --> I E --> G --> I E --> H --> I I --> J --> L I --> K --> L L --> M --> N classDef user fill:#E8F1FB,stroke:#2F75B5,color:#17365D; classDef threat fill:#FCE4D6,stroke:#C00000,color:#7F0000; classDef internal fill:#FFF2CC,stroke:#BF8F00,color:#7F6000; classDef detect fill:#E2F0D9,stroke:#548235,color:#375623; classDef response fill:#E4DFEC,stroke:#7030A0,color:#3F1D5A; class A,C,M user; class B,D,F,G,H,I threat; class L internal; class J,K detect; class N response;

    Responding Action

    flowchart TD %% ========================== %% Detection %% ========================== subgraph P1["๐Ÿ›ก๏ธ Phase 1 - Detection & Validation"] direction TB A["๐Ÿšจ EDR / SIEM Alert<br/>โ˜Ž๏ธ User Report"] B["๐Ÿ‘จโ€๐Ÿ’ป L1 validates & enriches alert"] C["๐Ÿ“ ITSM Incident Created<br/>โš ๏ธ Provisional SEV1"] D["๐Ÿ“ž L2 notified<br/>โฑ๏ธ Within 15 minutes"] A --> B --> C --> D end %% ========================== %% Containment %% ========================== subgraph P2["๐Ÿš’ Phase 2 - Initial Containment"] direction TB E["๐Ÿ“š Invoke Ransomware &<br/>Account Compromise Playbooks"] F["๐Ÿ“ธ Capture volatile evidence<br/>while containment begins"] G["๐Ÿ”Œ Isolate endpoint<br/>๐Ÿ”‘ Revoke user sessions"] H["๐ŸŒ Block C2 traffic<br/>๐Ÿ“‚ Stop File Server sessions"] E --> F --> G --> H end %% ========================== %% Crisis Management %% ========================== subgraph P3["๐Ÿ‘” Phase 3 - Crisis Management"] direction TB I["๐Ÿšจ SOC Manager declares<br/>Major Incident"] J["๐Ÿ’ฌ Incident Communicator<br/>Creates WAR Room"] K["๐Ÿ“ข Notify CISO, CIO & Cybersecurity Head<br/>โฑ๏ธ Within 15 minutes"] I --> J --> K end %% ========================== %% Investigation %% ========================== subgraph P4["๐Ÿ” Phase 4 - Investigation"] direction TB L["๐Ÿงญ L2 scopes affected<br/>Endpoints, Identities,<br/>Data & Infrastructure"] M["๐ŸŽฏ CTI & Threat Hunting<br/>Search enterprise-wide"] N["๐Ÿค Engage Business,<br/>Legal, Risk & BCP"] L --> M --> N end %% ========================== %% Recovery %% ========================== subgraph P5["๐Ÿ”„ Phase 5 - Recovery"] direction TB O["๐Ÿงน Eradicate malware<br/>๐Ÿ’ป Reimage laptop"] P["๐Ÿ” Rotate credentials<br/>๐Ÿ›ก๏ธ Strengthen detections"] Q["๐Ÿ’พ Restore known-good data<br/>โœ… CIO/CISO approval"] R["โœ”๏ธ Business Owner validates<br/>Service & Data"] O --> P --> Q --> R end %% ========================== %% Closure %% ========================== subgraph P6["๐Ÿ“‹ Phase 6 - Closure"] direction TB S["๐Ÿ‘€ 72-hour SEV1 Monitoring"] T["๐Ÿ“„ Final Report<br/>๐Ÿ“š Lessons Learned<br/>๐Ÿ“Œ Corrective Actions"] S --> T end %% Main Flow D --> E H --> I K --> L N --> O R --> S %% Colors classDef detect fill:#E2F0D9,stroke:#548235,color:#375623; classDef contain fill:#FFF2CC,stroke:#BF8F00,color:#7F6000; classDef crisis fill:#F4CCCC,stroke:#C00000,color:#7F0000; classDef investigate fill:#D9EAD3,stroke:#38761D,color:#274E13; classDef recover fill:#D9EAF7,stroke:#2F75B5,color:#17365D; classDef close fill:#EADCF8,stroke:#7030A0,color:#3F1D5A; class A,B,C,D detect; class E,F,G,H contain; class I,J,K crisis; class L,M,N investigate; class O,P,Q,R recover; class S,T close;

    Response Action (SOP Aligned)

    What action should do when ransomware happend, ensure SoP is follow.

    flowchart TD %% ========================= %% 1. DETECTION AND TRIAGE %% ========================= A["CrowdStrike EDR alert, QRadar offense,<br/>file-server alert, or employee report"] B["SOC L1 acknowledges alert<br/>Identify host, user, IP, time, and alert type"] C["SOC L1 validates and enriches<br/>EDR, SIEM, IPAM, asset, AD, firewall, file-server logs"] D{"Credible potential or<br/>confirmed incident?"} D0["Document false-positive reasoning<br/>Close alert without ITSM incident"] E["Open ITSM cybersecurity incident<br/>Attach evidence and reference playbooks"] F["Assign provisional SEV1<br/>Complete formal severity scoring"] G["Escalate to SOC L2 immediately<br/>Within 15 minutes of credible validation"] A --> B --> C --> D D -- "No" --> D0 D -- "Yes" --> E --> F --> G %% ========================= %% 2. ANALYSIS AND COMMAND %% ========================= H["SOC L2 confirms ransomware<br/>C2, persistence, credential access, mass file changes"] I["Reconstruct attack timeline<br/>Telegram download to detection and containment"] J["Define endpoint, identity,<br/>data, and infrastructure scope"] K["SOC Manager confirms major incident<br/>SOC Lead or L3 supports investigation"] L["Incident Communicator creates WAR Room<br/>Within 30 minutes of severity confirmation"] M["Notify Cybersecurity Head, CISO, and CIO<br/>By phone within 15 minutes of SEV1 confirmation"] M1["Provide factual initial update<br/>Impact, actions, uncertainty, decisions, next update"] G --> H --> I --> J --> K K --> L K --> M --> M1 %% ========================= %% 3. EVIDENCE + CONTAINMENT %% ========================= N["Rapid evidence assessment<br/>Preserve critical logs and artifacts where feasible"] O{"Active ransomware, exfiltration,<br/>or lateral movement?"} P["Contain immediately<br/>Evidence capture continues in parallel"] P0["Capture basic evidence first<br/>Then contain under approved playbook"] J --> N --> O O -- "Yes" --> P O -- "No or unclear" --> P0 subgraph CT["Parallel Containment Workstreams"] direction LR Q1["Endpoint<br/>Isolate host in EDR<br/>Kill malicious process<br/>Block hash<br/>Hunt other endpoints"] Q2["Identity<br/>Disable or restrict account<br/>Revoke sessions and tokens<br/>Reset credentials<br/>Review privileges"] Q3["Network<br/>Block malicious IP and domain<br/>Preserve traffic logs<br/>Assess exfiltration<br/>Restrict segment if needed"] Q4["File Server<br/>Stop malicious sessions<br/>Protect unaffected shares<br/>Restrict writes if required<br/>Check backups and snapshots"] end P --> Q1 P --> Q2 P --> Q3 P --> Q4 P0 --> Q1 P0 --> Q2 P0 --> Q3 P0 --> Q4 Q1 --> R["SOC L2 updates scope and ITSM<br/>Record action, justification, approval, time, and result"] Q2 --> R Q3 --> R Q4 --> R %% ========================= %% 4. SPECIALIST ACTIONS %% ========================= S1["CTI and Threat Hunting<br/>Enrich IOCs, identify campaign,<br/>search enterprise-wide"] S2["Loan Business Owner<br/>Assess loan-operation impact,<br/>workarounds, priorities, and tolerance"] S3["Legal, Privacy, Risk, Compliance<br/>Assess customer-data exposure,<br/>notification and regulatory risk"] S4{"Large-scale ransomware,<br/>critical system, or outage<br/>beyond tolerance?"} S5["SOC informs BCP Officer<br/>BCP Committee decides activation"] S6["Continue incident response<br/>without full BCP activation"] R --> S1 R --> S2 R --> S3 S2 --> S4 S4 -- "Yes" --> S5 S4 -- "No" --> S6 %% ========================= %% 5. COMMUNICATION LOOP %% ========================= T["Incident Communicator issues updates<br/>Every 30 to 60 minutes"] T1["Interim report<br/>SEV1: 6 to 12 hours<br/>Off-hours emergency override: within 2 hours"] M1 --> T R --> T T --> T1 %% ========================= %% 6. ERADICATION %% ========================= U{"Containment stable and<br/>scope sufficiently understood?"} U0["Continue containment, hunting,<br/>scoping, and executive updates"] V1["SOC L2 removes malicious artifacts<br/>and validates no persistence or C2"] V2["IT Support reimages Loan laptop<br/>Patch, harden, install EDR, enable logging"] V3["IAM rotates exposed credentials,<br/>tokens, and privileged access"] V4["SOC Engineering adds IOCs<br/>and improves SIEM and EDR detections"] W["Verify eradication<br/>No malicious process, traffic, persistence,<br/>or additional infected systems"] S1 --> U S2 --> U S3 --> U S5 --> U S6 --> U U -- "No" --> U0 --> R U -- "Yes" --> V1 U -- "Yes" --> V2 U -- "Yes" --> V3 U -- "Yes" --> V4 V1 --> W V2 --> W V3 --> W V4 --> W %% ========================= %% 7. RECOVERY %% ========================= X{"Recovery preconditions met?<br/>Root cause mitigated, clean backup,<br/>business ready, CIO and CISO approval"} X0["Do not restore<br/>Resolve gaps and obtain approval"] Y1["IT restores from known-good backup<br/>in a controlled manner"] Y2["SOC validates security controls<br/>and monitors reconnection in real time"] Y3["Loan Business Owner validates<br/>functionality, data integrity, and reconciliation"] Z["Controlled return to service"] ZA["Enhanced monitoring window<br/>SEV1: minimum 72 hours"] ZB{"Any malicious indicator<br/>or recurrence?"} W --> X X -- "No" --> X0 --> W X -- "Yes" --> Y1 --> Y2 --> Y3 --> Z --> ZA --> ZB ZB -- "Yes" --> P %% ========================= %% 8. CLOSURE %% ========================= ZC["Recovery declared stable<br/>Business validation and CIO/CISO approval"] ZD["Final incident report<br/>SEV1: within 5 business days"] ZE["Lessons learned and action tracker<br/>Owners, due dates, validation evidence"] ZF["Secure evidence and reports<br/>Update ITSM and SOC Knowledge Base"] ZG["Close incident only after<br/>all SOP closure criteria are met"] ZB -- "No" --> ZC --> ZD --> ZE --> ZF --> ZG %% ========================= %% STYLING %% ========================= classDef detect fill:#E2F0D9,stroke:#548235,color:#375623; classDef triage fill:#E8F1FB,stroke:#2F75B5,color:#17365D; classDef decision fill:#FFF2CC,stroke:#BF8F00,color:#7F6000; classDef contain fill:#FCE4D6,stroke:#C00000,color:#7F0000; classDef command fill:#E4DFEC,stroke:#7030A0,color:#3F1D5A; classDef recovery fill:#DDEBF7,stroke:#1F4E78,color:#17365D; classDef close fill:#E2EFDA,stroke:#548235,color:#375623; class A detect; class B,C,E,F,G,H,I,J triage; class D,O,S4,U,X,ZB decision; class D0,P0 triage; class P,Q1,Q2,Q3,Q4,R,U0 contain; class K,L,M,M1,T,T1 command; class N,S1,S2,S3,S5,S6,V1,V2,V3,V4,W triage; class X0,Y1,Y2,Y3,Z,ZA recovery; class ZC,ZD,ZE,ZF,ZG close;

    ๐Ÿ“– The Ransomus Protocol: An Interactive Cyber Crisis Storybook

    A Narrative Tabletop Exercise Book with Dramatic Plot Twists, Character Interrogations, and Visual Incident Mockups.

    Incident Response Command TeamIncident Response Command Team

    ๐Ÿ“˜ Prologue: The Anatomy of a Modern Cyber Attack

    It was a rainy Tuesday morning at Loan Corp Headquarters. Loan officers operated on the frontlines of commercial lending, constantly closing high-value mortgage deals and business credit lines. To stay nimble in a hyper-competitive market, loan officers frequently met VIP clients off-site at coffee shops, hotel lobbies, and remote branches.

    To expedite documentation exchanges, loan officers relied heavily on corporate Telegram desktop channelsโ€”a convenient, unsanctioned shadow IT channel for sending signed PDF applications, tax records, and identity archives.

    Unbeknownst to the team, a sophisticated nation-state threat group known as Ransomus was monitoring these informal channels, waiting for the perfect moment to slip through the castle gates...


    ๐Ÿ“ธ Chapter 1: The Telegram Phishing Payload & Disguised Execution

    Telegram Phishing VectorTelegram Phishing Vector

    ๐Ÿ“– The Narrative

    At 09:15 AM, Alex, a senior commercial loan officer, was working remotely from a downtown coffee shop. A notification popped up on his Telegram app from a verified customer contact profile named "VIP Client - Horizon Real Estate".

    Attached was a compressed archive titled Customer_Documents_2026.zip (size: 42 MB). The message read:

    "Alex, attached are our signed commercial loan agreements and bank statements for the $12M property acquisition. Please review urgently before noon!"

    Eager to close the deal, Alex extracted the archive. Inside was a file with a familiar Adobe PDF icon named Signed_Agreement.pdf.exe. Double-clicking it triggered a brief spinner, followed by a Windows system error dialog:

    Fake Adobe PDF ErrorFake Adobe PDF Error

    System Error: Adobe Acrobat Reader DC - Unable to render document format (0x80070005). File may be corrupted.

    Alex assumed the client sent a broken file, closed the error box, sent a quick Telegram message asking for a resend, and moved on to other emails.

    Behind the screen, the trap was sprung. The disguised executable silently injected a malicious DLL into svchost.exe, established user-level registry persistence, and initiated encrypted HTTPS beacons to 185.123.45.6:443.


    ๐ŸŒ€ Dramatic Plot Twist 1: The Insider Credentials Leak

    TWIST: The Telegram profile that sent the file belonged to an actual high-value client whose personal Telegram account had been hijacked 24 hours earlier! Furthermore, EDR telemetry reveals that the Trojan payload harvested Alex's saved Active Directory credentials and Chrome browser tokens during the error popup!

    โ“ Hot-Seat Character Interrogation Questions (Chapter 1)

    Character RoleHot-Seat Twist Question for the Player
    SOC L1SOC L1

    SOC L1 Analyst
    "An EDR alert fires for LOAN-LAPTOP-042 showing an unrecognized process spawn (explorer.exe -> Signed_Agreement.exe -> svchost.exe). The user reports it as a harmless Adobe glitch. Do you dismiss it as a False Positive or escalate? What is your 15-minute SLA protocol?"
    SOC L2SOC L2

    SOC L2 Analyst
    "The malware did not request admin privileges and ran under standard user permissions (j.smith). How do you validate whether this is a commodity Trojan or an targeted APT payload?"
    CTI TeamCTI Team

    CTI Team Analyst
    "Threat intel links IP 185.123.45.6 to a known ransomware syndicate. What campaign indicators do you immediately feed to L1/L2?"

    ๐Ÿ—บ๏ธ Chapter 2: The Corporate LAN Reconnection & Silent Reconnaissance

    Global Cyber Threat MapGlobal Cyber Threat Map

    ๐Ÿ“– The Narrative

    By 02:00 PM, Alex finished his off-site meetings and returned to corporate headquarters. He sat down at his desk and plugged LOAN-LAPTOP-042 directly into an Ethernet jack connected to the corporate LAN.

    The moment the laptop obtained an internal IP (10.15.34.120), the dormant malware spirit detected the corporate domain controller (AD-DC01).

    Exploiting Alex's existing Kerberos session tokens, the Trojan launched automated network reconnaissance. It mapped accessible network shares, discovered \\FS01\LoanShares, and performed Kerberoasting queries to harvest service account ticket hashes.


    ๐ŸŒ€ Dramatic Plot Twist 2: The Unpatched Domain Controller

    TWIST: The attacker utilizes the compromised j.smith account to query Active Directory for Domain Admin service accounts. The SOC discovers that AD-DC01 is missing a critical patch for a known privilege escalation vulnerability (CVE-2026-1102), allowing a standard user account to request elevated Kerberos TGS tickets!

    โ“ Hot-Seat Character Interrogation Questions (Chapter 2)

    Character RoleHot-Seat Twist Question for the Player
    Network SystemNetwork System

    Network & System Team
    "Active Directory reports 50+ Kerberos TGS requests per second originating from LOAN-LAPTOP-042. Do you instantly isolate the network switch port or wait for SOC Manager approval?"
    Business OwnerBusiness Owner

    Business / Asset Owner
    "The network team proposes isolating \\FS01\LoanShares. This will halt 200 loan officers nationwide from closing deals today. Do you authorize this operational freeze?"
    SOC ManagerSOC Manager

    SOC Manager
    "L2 requests host isolation for LOAN-LAPTOP-042 and account lockout for j.smith. Who holds mandatory operational authority to approve this action under the RACI matrix?"

    ๐Ÿ“Š Chapter 3: The 5GB Exfiltration Shadow & SIEM Alarm

    IBM QRadar SIEM DashboardIBM QRadar SIEM Dashboard

    ๐Ÿ“– The Narrative

    At 02:25 PM, the attacker activated the exfiltration module. Compressed archives containing 5.2 GB of confidential customer loan applications, tax filings, and corporate financial statements were staged in C:\Users\j.smith\AppData\Local\Temp\enc_payload.dll.

    The malware opened multi-threaded SSL/TLS outbound streams, pushing the siphoned data to external C2 server 185.123.45.6:443.

    At 02:28 PM, the IBM QRadar SIEM console flared red. A CRITICAL SEV-1 Offense #48291 correlated multiple anomalies:

    1. Palo Alto Firewall: Outbound HTTPS data spike (5.2 GB to uncategorized IP 185.123.45.6).

    2. Active Directory: Abnormal Kerberos TGS ticket request burst under j.smith.

    3. File Server FS01: High-volume file read operations on \\FS01\LoanShares.

    4. Loan Application System (LOS): Bulk customer record export event.


    ๐ŸŒ€ Dramatic Plot Twist 3: The Media Extortion Threat

    TWIST: Simultaneously, the CTI team uncovers a post on a dark web leak site where the Ransomus group claims they have already exfiltrated 5,000 customer PII records and threatens to leak them to financial news media in 2 hours if contact is not made!

    โ“ Hot-Seat Character Interrogation Questions (Chapter 3)

    Character RoleHot-Seat Twist Question for the Player
    SOC LeadSOC Lead

    SOC Lead / L3
    "SIEM shows 5.2 GB of data exfiltrated in 3 minutes. How do you determine whether customer PII was included in the exfiltration bundle versus internal system logs?"
    IR CommunicatorIR Communicator

    Incident Communicator
    "A tech journalist calls your press desk asking if Loan Corp is experiencing a ransomware data breach. How do you respond without violating executive communication SLAs?"
    CISOCISO

    CISO
    "Dark web extortion claims 5,000 customer records were stolen. At what point does regulatory data breach notification (e.g., GDPR / SEC / banking regulators) become mandatory?"

    ๐Ÿ”’ Chapter 4: The Encryption Catalyst & HelpDesk Midnight Call

    CrowdStrike EDR Alert ConsoleCrowdStrike EDR Alert Console

    ๐Ÿ“– The Narrative

    At 02:32 PM, having completed data exfiltration, the attacker launched the ransomware payload.

    Using multi-threaded AES-256 encryption, the malware began locking local files on LOAN-LAPTOP-042 and rapidly traversed network shares on \\FS01\LoanShares. Thousands of documents, spreadsheets, and database backups were renamed with a .lock extension.

    Seconds later, CrowdStrike EDR triggered a CRITICAL SEV-1 ALERT: Ransomware Execution & Mass File Encryption Detected.

    Alex's Dell laptop froze completely. The display transformed into a terrifying blood-red lock screen:

    Dell Laptop Ransomware Lock ScreenDell Laptop Ransomware Lock Screen

    RANSOM LOCK NOTICE: ALL YOUR FILES HAVE BEEN ENCRYPTED BY RANSOMUS! A unique encryption key has locked access. Submit 5.0 BTC (~$325,000 USD) to wallet 1F1tAaz5x1HUXrCNLvtMDqcw6955Hnt9Dk within 72 hours or the key will be permanently destroyed!

    ๐ŸŒ€ Dramatic Plot Twist 4: The Corrupted Shadow Copies

    TWIST: When system administrators attempt to trigger local Volume Shadow Copies (VSS) on FS01, they discover the ransomware executed vssadmin delete shadows /all /quiet via a compromised Domain Admin service account prior to encryption!

    โ“ Hot-Seat Character Interrogation Questions (Chapter 4)

    Character RoleHot-Seat Twist Question for the Player
    SOC ManagerSOC Manager

    SOC Manager
    "Local shadow copies on FS01 are wiped and the ransomware note demands 5 BTC. Do you immediately declare a Major SEV-1 Incident and invoke the Business Continuity Plan (BCP)?"
    ExecutiveExecutive

    Executive Management
    "A board member asks if the company should pay the 5 BTC ransom to regain immediate access before market opening. What is executive policy regarding ransom negotiations?"
    CIOCIO

    CIO
    "Core lending databases are locked. Who holds final authority to sign off on BCP disaster recovery invocation when core core systems are compromised?"

    ๐Ÿ›๏ธ Chapter 5: The Incident Command WAR Room & Multi-Team Containment

    Incident Command WAR RoomIncident Command WAR Room

    ๐Ÿ“– The Narrative

    At 02:45 PM, the SOC Manager formally declared a SEV-1 Major Incident.

    The Incident Communicator immediately launched the central Incident Command WAR Room, bringing together all 11 role stakeholders: SOC Analysts, Forensics, IT Infrastructure, Threat Intel, Asset Owners, CIO, CISO, and Executive Leadership.

    4 parallel containment streams were initiated:

    1. Network Containment: Block IP 185.123.45.6 at the perimeter firewall and isolate LOAN-LAPTOP-042.

    2. Identity Lockdown: Disable AD account j.smith, reset Kerberos krbtgt tickets, and terminate active SMB sessions.

    3. Application Guard: Place \\FS01\LoanShares into Read-Only Mode while forensic volatile memory capture was executed.

    4. Executive Briefings: Issue 30-minute status updates to CISO, CIO, and legal counsel.


    ๐ŸŒ€ Dramatic Plot Twist 5: The Secondary Persistence Backdoor

    TWIST: During network containment, Network Ops notices HTTPS traffic to a SECOND unknown IP (198.51.100.42) originating from a totally different server (WEB-APP-02)! The attacker installed a web shell 3 days prior as a secondary fallback persistence mechanism!

    โ“ Hot-Seat Character Interrogation Questions (Chapter 5)

    Character RoleHot-Seat Twist Question for the Player
    IR CommunicatorIR Communicator

    Incident Communicator
    "The CISO demands an instant update while Network Ops discovers a secondary web shell backdoor. Does the Incident Communicator have authority to execute containment actions? How do you manage stakeholder comms?"
    Network SystemNetwork System

    Network & System Team
    "SOC L2 requests severing WEB-APP-02 from the internet. This will take the customer online portal offline. How quickly can your team execute this isolation?"
    Business OwnerBusiness Owner

    Business / Asset Owner
    "With WEB-APP-02 and FS01 offline, what manual paper fallback procedures does your business unit initiate to maintain loan processing?"

    ๐Ÿงน Chapter 6: The Immutable Restoration & Executive Return-to-Production

    Backup Restoration PortalBackup Restoration Portal

    ๐Ÿ“– The Narrative

    By Day 2 at 08:00 AM, eradication activities were fully underway.

    The Network & System Team reimaging LOAN-LAPTOP-042 with an approved gold image, purged the web shell on WEB-APP-02, patched CVE-2026-1102 on AD-DC01, and verified EDR sensor health across all endpoints.

    Engineers accessed the immutable offline backup vault and located an uncorrupted snapshot taken at 02:00 AM on Day 1 (prior to infection). Restoration reached 98% completion by 02:00 PM.

    At 04:00 PM, the Business Asset Owner validated data integrity across restored shares. Finally, in a joint executive session, the CIO and CISO granted formal recovery authorization to return systems to production.


    ๐ŸŒ€ Dramatic Plot Twist 6: The 2-Hour Backup Gap & Missing Deals

    TWIST: Data validation reveals that loan contracts created between 07:00 AM and 09:00 AM on Day 1 were not captured in the 02:00 AM snapshot. 14 high-value loan agreements must be manually re-entered from paper receipts!

    โ“ Hot-Seat Character Interrogation Questions (Chapter 6)

    Character RoleHot-Seat Twist Question for the Player
    Business OwnerBusiness Owner

    Business / Asset Owner
    "14 loan contracts are missing from the restored snapshot. How do you validate manual re-entry accuracy before confirming operational recovery to the CIO/CISO?"
    CIOCIO

    CIO
    "Under governance SOPs, what mandatory sign-off criteria must be satisfied before you and the CISO authorize returning core systems to production?"
    CISOCISO

    CISO
    "Post-Incident Review (PIR) identifies 5 overdue remediation items. How does the CISO enforce accountability and tracking for overdue action items?"

    ๐Ÿ“Š Summary of Character RACI Powers & Story Arc

    flowchart LR subgraph Phase1["Phase 1: Phishing & Triage"] A["๐Ÿ‘จโ€๐Ÿ’ผ Alex opens Telegram zip"] --> B["๐Ÿ›ก๏ธ SOC L1 Triage & Ticket"] end subgraph Phase2["Phase 2: LAN Recon & Scope"] B --> C["๐Ÿน SOC L2 Investigation"] C --> D["๐Ÿ”ฎ CTI Threat Intel Enrichment"] end subgraph Phase3["Phase 3: Exfiltration & SIEM"] D --> E["๐Ÿ“Š QRadar SIEM Offense #48291"] E --> F["โš’๏ธ Net Ops Block C2 IP"] end subgraph Phase4["Phase 4: Encryption & WAR Room"] F --> G["๐Ÿ”’ CrowdStrike SEV-1 Alert"] G --> H["๐Ÿ‘‘ SOC Manager Declares SEV-1"] H --> I["๐ŸŽบ War Room Bard Management"] end subgraph Phase5["Phase 5: Recovery & Sign-Off"] I --> J["๐Ÿฐ Asset Owner Validation"] J --> K["๐Ÿ“œ CIO & โšœ๏ธ CISO Final Approval"] end classDef triage fill:#1A233A,stroke:#00F2FE,color:#FFF; classDef crisis fill:#3A1A23,stroke:#FF3B30,color:#FFF; classDef recovery fill:#1A3A23,stroke:#00E676,color:#FFF; class Phase1,Phase2 triage; class Phase3,Phase4 crisis; class Phase5 recovery;

    ๐ŸŽ“ Facilitator Epilogue & Key Takeaways

    1. RACI Enforcement: Containment authority must strictly align with pre-approved matrix boundaries to eliminate operational bottlenecks.

    2. Communication Velocity: Incident Communicators own stakeholder notification and WAR Room management, ensuring technical teams remain focused on containment.

    3. Immutable Snapshots: Offline, air-gapped backups are the single critical line of defense against ransomware extortion.

    4. Joint Executive Blessing: Production restoration requires formal sign-off from both business and security leadership (CIO & CISO).

    ๐Ÿš€ Run the Interactive Deck: Open index.html to present full-screen slides or launch the D&D campaign mode!

    ๐Ÿ‰ Cyber & Dragons: The Ransomus Campaign

    ๐ŸŽฒ Tabletop Exercise (TTX) D&D Style Facilitator & Campaign Master Guide

    Tip: ๐Ÿš€ Interactive D&D Game Portal: Launch index.html and click the "๐ŸŽฒ D&D Campaign Deck" button in the top navigation bar to run this exercise with real-time sound effects, D20 dice roller, animated spells, and boss HP tracking!

    ๐Ÿ“Œ Campaign Overview

    Welcome, Dungeon Master (Facilitator)! This guide transforms standard cybersecurity Incident Response (IR) tabletop exercises into an immersive Dungeons & Dragons (D&D) style fantasy tabletop roleplaying campaign.

    Players assume the roles of an elite Cyber Adventuring Party battling Ransomus the Encryptorโ€”a dark threat spirit attempting to siphon customer archives and freeze corporate systems with ransomware crystals.

  • Target Audience: SOC L1, L2, L3, Incident Communicator, SOC Manager, Business/Asset Owner, Network/System Team, CTI Team, CIO, CISO, and Executive Leadership.
  • Duration: 2 to 3 Hours.
  • System Mechanics: D20 System (Natural 20 = Critical Hit, 10โ€“19 = Success, 1โ€“9 = Failure/Corruption), Boss HP Bar (10,000 HP), Skill Checks, RACI Spells, and Initiative Order.
  • Goal: Gamify SOP adherence, test RACI containment authority enforcement, enforce SLA response velocity, and build team alignment.

  • โš”๏ธ The 11 Character Class Roles & RACI Spells

    Each participant receives a Character Card with specific RACI abilities, stats, and containment spells:

    Hero Class / RoleClass TitlePrimary Skill & AbilityRACI Containment Spell / Power
    ๐Ÿ›ก๏ธ SOC L1 SentinelShift Duty PaladinPerception (DC 14): Continuous alert monitoring & FP vs TP triage.Predefined Containment Aura: Execute low/med playbook actions; escalate to L2 <15 min.
    ๐Ÿน SOC L2 InvestigatorForensic RangerInvestigation (DC 15): Log analysis, timeline tracking, scope mapping.High-Severity Binding: Recommend & execute high-sev host isolation per matrix.
    ๐Ÿง™โ€โ™‚๏ธ Archmage SOC L3Senior Forensics WizardArcana / Forensics (DC 16): Deep malware reverse-engineering & RCA.Major Containment Counter-Spell: Share full operational authority during SEV1.
    ๐ŸŽบ War Room BardIncident CommunicatorPerformance / Comms (DC 13): Own WAR Room & executive SLA alerts.SLA Horn of Emergency: Sound executive alerts <15 min (NO containment authority).
    ๐Ÿ‘‘ Grand CommanderSOC ManagerLeadership (DC 16): Operational authority, Major Incident declaration.Domain Shield of Governance: Declare Major Incident, engage BCP/DR, approve containment.
    ๐Ÿฐ Guild Asset OverseerBusiness / Asset OwnerInsight (DC 14): Business impact assessment & application context.Production Access Seal: Approve production system containment; validate recovery.
    โš’๏ธ Dwarven TechnomancerNetwork & System TeamAthletics / Engineering (DC 15): Firewall blocks, AD locks, reimaging.Wall of Stone & Firewall: Execute network isolation, IP bans, & AD account locks.
    ๐Ÿ”ฎ Shadow OracleCTI Threat IntelScrying (DC 14): Threat actor attribution & C2 campaign correlation.Scrying Orb of Intelligence: Enrich IOCs & track adversary infrastructure.
    ๐Ÿ“œ Lord Chancellor CIOCore Systems AuthorityHistory / Authority (DC 17): Core infrastructure governance & BCP sign-off.Decree of System Restoration: Grant mandatory final recovery sign-off for SEV1/SEV2.
    โšœ๏ธ Grand Inquisitor CISOCyber Governance PaladinReligion / Compliance (DC 17): Regulatory oversight & risk alignment.Aegis of Regulatory Compliance: Strategic cyber oversight & mandatory recovery sign-off.
    ๐Ÿ›๏ธ High CouncilExecutive ManagementDiplomacy / Risk (DC 18): Executive risk governance & public disclosure.Council Sanction: Approve strategic business & regulatory decisions.

    ๐ŸŽฒ Core Game Mechanics for the Dungeon Master (DM)

    1. Boss Health Pool: Ransomus starts with 10,000 HP. Each successful encounter roll depletes Boss HP.

    2. Initiative Order: Turn proceeds sequentially through Encounters I to VI.

    3. Skill Checks & D20 Rolls:

  • Player rolls a D20 die (or clicks the interactive D20 die in index.html).
  • Natural 20 (Critical Hit): 1.5ร— Damage (e.g., 2,250 HP damage), epic success, instantly unlocks bonus threat intel.
  • 10 to 19 (Success): Normal Damage (1,000โ€“2,000 HP), successful RACI defense, SLA met.
  • 1 to 9 (Failure): 0 Damage to Boss. Ransomus retaliates with a Corruption Spike (penalty warning or SLA breach).
  • 4. DM Storytelling Rule: Read the Dungeon Master Script aloud for each encounter before prompting players to respond with their role handbooks!


    ๐ŸŽฌ The 6 Quest Encounters (Start-to-Finish Script)


    ๐Ÿ“œ Encounter I: The Mimic's Scroll (Phishing Vector)

  • Phase: Detection & Shift Triage
  • Simulated Time: 09:15 AM (Day 1 - Offsite)
  • Active Hero: SOC L1 Sentinel
  • Boss Damage: 1,500 HP
  • Visual Asset: assets/telegram_phishing.jpg & assets/fake_pdf_error.jpg
  • ๐Ÿ—ฃ๏ธ Dungeon Master Script (Read Aloud):

    "Hark, brave adventurers! A remote loan officer working outside the castle walls receives a sealed parchment named Customer_Documents_2026.zip over the Telegram messaging network. Believing it to be a legitimate loan applicant, the officer opens Signed_Agreement.pdfโ€”a dark executable in disguise! A cursed Adobe error (0x80070005) flashes across his screen. The officer ignores the warning and continues working. Behind the error, a silent Trojan spirit awakens and beacons back to the dark domain!"

    ๐ŸŽฏ Party Objective & Challenge:

  • SOC L1 Sentinel must cast Perception Check (DC 14).
  • DM Question to Player: "SOC L1 Sentinel! The EDR scroll flags an unusual process tree (explorer.exe launching a Trojan DLL). What are your mandatory SOP steps, and what is your SLA escalation deadline?"
  • Required Player Answer: Validate True Positive, enrich asset/user context (LOAN-LAPTOP-042, j.smith), open ITSM ticket, and escalate to SOC L2 Investigator within 15 minutes (or directly to Grand Commander SOC Manager if L2 is absent).

  • ๐ŸŒ Encounter II: Infiltration of Loan-Keep LAN (Lateral Recon)

  • Phase: Investigation & Scope Mapping
  • Simulated Time: 02:00 PM (Day 1 - Corporate HQ)
  • Active Hero: SOC L2 Investigator & Shadow Oracle (CTI)
  • Boss Damage: 1,800 HP
  • Visual Asset: assets/cyber_war_room_map.jpg
  • ๐Ÿ—ฃ๏ธ Dungeon Master Script (Read Aloud):

    "The loan officer returns to HQ and plugs LOAN-LAPTOP-042 directly into the corporate LAN! Like shadow tendrils, the malware spirit crawls across the internal realm. It enumerates Active Directory domain controllers (AD-DC01), abuses existing Kerberos tokens under account j.smith, and discovers the ancient vault of customer file shares (\\FS01\LoanShares)!"

    ๐ŸŽฏ Party Objective & Challenge:

  • SOC L2 Investigator & Shadow Oracle must cast Investigation & Scrying Check (DC 15).
  • DM Question to Player: "SOC L2 Investigator! The dark spirit is probing Kerberos tickets and scoping file shares. How do you confirm the severity level, and what intelligence does Shadow Oracle gather?"
  • Required Player Answer: SOC L2 leads forensic log investigation, correlates host/user scope, confirms high severity, and drafts technical alert. CTI Shadow Oracle enriches C2 IP indicators and campaign attribution.

  • ๐Ÿ“ค Encounter III: The Mass Exfiltration Ritual (5GB Data Drain)

  • Phase: Threat Intelligence & SIEM Correlation
  • Simulated Time: 02:25 PM (Day 1)
  • Active Hero: Shadow Oracle (CTI) & Dwarven Technomancer
  • Boss Damage: 2,000 HP
  • Visual Asset: assets/siem_dashboard.jpg
  • ๐Ÿ—ฃ๏ธ Dungeon Master Script (Read Aloud):

    "Dark magic surges! An dark portal opens to external realm 185.123.45.6:443. Ransomus begins siphoning 5GB of sensitive customer loan archives over encrypted channels! The IBM QRadar SIEM crystal glows bright red, triggering dual alarms: Outbound Data Exfiltration Spike + Abnormal SMB Read Burst!"

    ๐ŸŽฏ Party Objective & Challenge:

  • Shadow Oracle & Dwarven Technomancer must cast Arcana & Engineering Check (DC 16).
  • DM Question to Player: "Dwarven Technomancer & Shadow Oracle! 5GB of customer archives are draining into the abyss! What immediate technical containment spell do you prepare?"
  • Required Player Answer: Shadow Oracle confirms C2 malicious reputation (185.123.45.6). Dwarven Technomancer prepares firewall perimeter blocks and account session terminations.

  • ๐Ÿ”’ Encounter IV: Curse of Encryptus (Ransomlock)

  • Phase: Active Crisis & Major Incident Declaration
  • Simulated Time: 02:32 PM (Day 1)
  • Active Heroes: Archmage SOC L3 & Grand Commander (SOC Mgr)
  • Boss Damage: 2,200 HP
  • Visual Asset: assets/edr_ransomware_alert.jpg & assets/ransomware_note.jpg
  • ๐Ÿ—ฃ๏ธ Dungeon Master Script (Read Aloud):

    "Ransomus strikes with full fury! Dark encryption crystals freeze workstation files and shared vaults (\\FS01\LoanShares) with .lock extensions! Alex's Dell laptop freezes, displaying a blood-red ransom note: '5 BITCOIN DEMANDED WITHIN 72 HOURS OR ALL KEYS DESTROYED!' CrowdStrike EDR roars with a CRITICAL SEV-1 ALERT!"

    ๐ŸŽฏ Party Objective & Challenge:

  • Grand Commander & Archmage L3 must cast Saving Throw against Total Encryption (DC 17).
  • DM Question to Player: "Grand Commander! The core file share is freezing and a 5 BTC ransom demand is posted! Do you declare a Major Incident, and who has containment authority?"
  • Required Player Answer: Grand Commander declares SEV-1 Major Incident, activates BCP/DR protocol, and approves major containment. Archmage L3 performs deep forensic analysis.

  • ๐Ÿ›ก๏ธ Encounter V: War Room Summit & Elemental Barrier (Containment)

  • Phase: Incident Command & WAR Room Operations
  • Simulated Time: 02:45 PM (Day 1)
  • Active Heroes: War Room Bard, Dwarven Technomancer, Guild Asset Overseer
  • Boss Damage: 1,500 HP
  • Visual Asset: assets/war_room_dashboard.jpg
  • ๐Ÿ—ฃ๏ธ Dungeon Master Script (Read Aloud):

    "The alarm bells ring! War Room Bard blows the SLA Horn of Emergency, gathering all 11 heroes into the Incident Command WAR Room! Executive notifications shoot across the realm to Lord Chancellor CIO and Grand Inquisitor CISO within 15 minutes. Dwarven Technomancers slam the firewall gates shut!"

    ๐ŸŽฏ Party Objective & Challenge:

  • War Room Bard, Dwarven Technomancer, & Guild Asset Overseer must cast Containment Barrier (DC 15).
  • DM Question to Player: "War Room Bard & Guild Asset Overseer! Does the Bard have containment execution authority? And what application isolation does Guild Asset Overseer approve?"
  • Required Player Answer: War Room Bard owns comms and WAR Room management but has NO containment authority. Guild Asset Overseer approves setting \\FS01\LoanShares to Read-Only mode to preserve business data. Dwarven Technomancer blocks C2 IP 185.123.45.6 and locks AD account j.smith.

  • โœจ Encounter VI: Divine Purge & Clean Restoration (Eradication & Recovery)

  • Phase: Eradication, Backup Recovery & Business Sign-Off
  • Simulated Time: Days 2โ€“3
  • Active Heroes: Lord Chancellor CIO, Grand Inquisitor CISO, Guild Asset Overseer
  • Boss Damage: 1,000 HP (FINISHING BLOW!)
  • Visual Asset: assets/backup_recovery_portal.jpg
  • ๐Ÿ—ฃ๏ธ Dungeon Master Script (Read Aloud):

    "VICTORY IS WITHIN REACH! The infected laptop is cleansed and reimaged with gold armor. Technomancers cast Holy Restoration, pulling a 98% clean immutable snapshot from the backup vaults! Guild Asset Overseer inspects the restored archives and confirms operational integrity. Lord Chancellor CIO and Grand Inquisitor CISO raise their staves to grant final blessing!"

    ๐ŸŽฏ Party Objective & Challenge:

  • Lord Chancellor CIO & Grand Inquisitor CISO cast Divine Recovery Blessing (DC 17).
  • DM Question to Player: "CIO & CISO! What mandatory sign-off is required before systems return to production, and who tracks post-incident action items?"
  • Required Player Answer: Joint formal recovery approval from both CIO and CISO is mandatory for SEV1 return-to-production. Grand Commander (SOC Mgr) tracks overdue PIR action items with 30/60/90 day SLA enforcement.

  • ๐Ÿ“Š Evaluation Rubric & Victory Rewards (Loot)

    Benchmark MetricSLA TargetD&D Achievement Unlocked
    L1 Alert Escalation< 15 Minutes๐Ÿ† Shield of Swift Perception (Prevented early lateral spread)
    Host & Network Containment< 30 Minutesโš”๏ธ Blade of Containment (Severed C2 portal 185.123.45.6)
    Executive WAR Room Alert< 15 Minutes๐ŸŽบ Horn of Executive Alignment (Notified CIO & CISO within SLA)
    Immutable Backup Restore< 4 Hours๐Ÿ”ฎ Orb of Clean Recovery (Restored 98% clean snapshot)
    Joint Recovery Sign-Off< 24 Hours๐Ÿ‘‘ Crown of Governance Sign-Off (Approved return to production)

    ๐Ÿ“‘ Post-Campaign Debriefing Checklist (PIR)

    Review D20 Roll Logs: Evaluate where skill checks succeeded or failed.
    RACI Alignment Check: Confirm no role exceeded or defaulted on their containment authority.
    Action Item Assignment: Assign 30/60/90 day SLA deadlines for PIR security enhancements.
    Campaign Archive: Save results and launch the interactive portal via index.html .

    ๐Ÿ“Š Executive Briefing Presentation Deck (.pptx)

    Executive Presentation: Complete 16:9 widescreen PowerPoint deck generated automatically using build_presentation.py. Ready for boardrooms, projectors, and offline team briefings.

    ๐Ÿ“‘ Slide Deck Table of Contents

      Slide 1: Executive Title & TTX Scenario Briefing (ADMFI Microfinance)
        Slide 2: Operational Reality & Off-Site Risk Context
          Slide 3: 11-Role RACI Authority & Containment Matrix
            Slide 4: End-to-End Threat Kill-Chain & Architecture
              Slide 5: Inject 1 โ€” Telegram Social Engineering & Fake PDF Error
                Slide 6: Inject 2 โ€” Corporate LAN Reconnection & Kerberos Recon
                  Slide 7: Inject 3 โ€” 5.2GB Customer Data Exfiltration & SIEM Correlation
                    Slide 8: Inject 4 โ€” Ransomware Detonation ($50,000 Extortion Demand)
                      Slide 9: Plot Twists (Telegram BEC Hijack, VSS Wiper, Dark Web Leak)
                        Slide 10: Inject 5 โ€” Major Incident WAR Room & 4-Pillar Containment
                          Slide 11: Inject 6 โ€” Forensic Eradication & Immutable Snapshot Recovery
                            Slide 12: Post-Incident Review (PIR), KPI Rubric & Continuous Improvement
    Incident Command Structure

    ๐Ÿ‘ฅ 11 Incident Response Roles & RACI Matrix

    Clear role delineation ensures rapid incident triage, prevents unauthorized operational disruption, and enforces formal containment authorities across SOC, IT Infrastructure, Business, and Executive leadership.

    Full Command Structure IR Team Avengers

    ๐Ÿ›ก๏ธ Incident Response Team & Authority Hierarchy

    Technical responders (L1/L2) investigate and execute low/medium containment. High-severity and production containment requires SOC Manager and Business Owner approval. System return-to-production requires mandatory CIO & CISO sign-off.

    IR Team Group
    SOC L1 (Shift Duty / Tier 1)
    SOC L1 (Shift Duty / Tier 1)
    Shift Triage & Alert Validation
    Low/Med Playbook Predefined
    ๐Ÿ“Œ Core Mandatory Scope
    Continuously monitors EDR, SIEM, and firewall alerts. Performs initial triage to determine True vs False Positives, enriches incident context, creates ITSM tickets, and escalates credible threats to SOC L2 in <15 minutes.
    ๐ŸŽฎ TTX Scenario Specific Duty
    Triage offsite user report of Adobe error 0x80070005, detect Trojan DLL execution under explorer.exe, create SEV-1 ticket, and escalate within 15-minute SLA.
    ๐Ÿ“ Duty Checklist
    ๐Ÿ›ก๏ธ Shift Duty Paladin Open Handbook (.md)
    SOC L2 Analyst (Lead Investigator)
    SOC L2 Analyst (Lead Investigator)
    Lead Investigation & Forensics
    High Severity (per matrix)
    ๐Ÿ“Œ Core Mandatory Scope
    Leads technical investigation, validates scope and blast radius, confirms severity level, correlates threat intelligence, reconstructs forensic timelines from event logs, and executes high-severity host containment.
    ๐ŸŽฎ TTX Scenario Specific Duty
    Analyze 5.2GB data egress to C2 185.220.101.45, isolate host LOAN-LAPTOP-042, track Kerberos ticket abuse on domain controller, and assist in eradication.
    ๐Ÿ“ Duty Checklist
    ๐Ÿน Forensic Ranger Open Handbook (.md)
    SOC Lead / L3 (Senior Forensics)
    SOC Lead / L3 (Senior Forensics)
    Deep Forensics & Root Cause Analysis
    Major Containment Authorized
    ๐Ÿ“Œ Core Mandatory Scope
    Senior technical authority. Guides complex reverse engineering, leads enterprise-wide threat hunting, assists scoping and RCA, and shares operational containment authority during SEV-1 crises.
    ๐ŸŽฎ TTX Scenario Specific Duty
    Reverse engineer Trojan payload, extract hardcoded C2 domains, identify wiper script targeting Volume Shadow Copies (VSS), and guide malware eradication.
    ๐Ÿ“ Duty Checklist
    ๐Ÿง™โ€โ™‚๏ธ Forensics Archmage Open Handbook (.md)
    Incident Communicator (WAR Room)
    Incident Communicator (WAR Room)
    WAR Room & Stakeholder Comms
    โŒ NO Containment Authority
    ๐Ÿ“Œ Core Mandatory Scope
    Owns all incident communications. Establishes and moderates the Incident Command WAR Room bridge, notifies executives per SLA (<15 min), prepares 30-60 min situation reports, and coordinates regulatory reporting.
    ๐ŸŽฎ TTX Scenario Specific Duty
    Launch MS Teams / Zoom WAR Room bridge, notify CIO/CISO, issue 30-minute status updates, manage external breach inquiries, and draft After-Action Report (AAR).
    ๐Ÿ“ Duty Checklist
    ๐ŸŽบ War Room Bard Open Handbook (.md)
    SOC Manager (Incident Commander)
    SOC Manager (Incident Commander)
    Overall Operational Authority
    Full Operational Approval
    ๐Ÿ“Œ Core Mandatory Scope
    Overall operational commander during incidents. Approves major containment actions, formally declares SEV-1 Major Incidents, activates BCP/DR processes, and coordinates executive escalations.
    ๐ŸŽฎ TTX Scenario Specific Duty
    Declare SEV-1 Major Incident, approve network-wide file share isolation, engage BCP/DR Disaster Recovery team, and lead post-incident executive briefings.
    ๐Ÿ“ Duty Checklist
    ๐Ÿ‘‘ Grand Commander Open Handbook (.md)
    Business / Asset Owner (Head of Loans)
    Business / Asset Owner (Head of Loans)
    Business Context & Application Recovery
    Production System Approval
    ๐Ÿ“Œ Core Mandatory Scope
    Represents business operations and loan asset systems. Evaluates financial/operational impact, approves containment on production file shares (e.g. Read-Only mode), and validates business data recovery before service restoration.
    ๐ŸŽฎ TTX Scenario Specific Duty
    Assess impact on customer loan pipeline, approve temporary read-only lock on \\ADMFI-FS01\Loan_Share$, and verify customer document integrity from clean backup snapshots.
    ๐Ÿ“ Duty Checklist
    ๐Ÿฐ Guild Asset Overseer Open Handbook (.md)
    Network & System Infrastructure Team
    Network & System Infrastructure Team
    Infrastructure Execution & Active Directory
    Technical Execution
    ๐Ÿ“Œ Core Mandatory Scope
    Executes infrastructure containment requested by SOC: firewall C2 IP bans, Active Directory account locks, Kerberos token revocation, VLAN isolations, server snapshot restoration, and endpoint reimaging.
    ๐ŸŽฎ TTX Scenario Specific Duty
    Block C2 IP 185.220.101.45 at perimeter firewall, revoke AD account sok.dara, lock loan share permissions, and reimage infected laptop LOAN-LAPTOP-042.
    ๐Ÿ“ Duty Checklist
    โš’๏ธ Dwarven Technomancer Open Handbook (.md)
    CTI Team (Cyber Threat Intelligence)
    CTI Team (Cyber Threat Intelligence)
    Adversary Attribution & Threat Hunting
    Intelligence Support
    ๐Ÿ“Œ Core Mandatory Scope
    Enriches IOCs with adversary context, tracks threat actor campaign patterns (Ransomus group), monitors dark web leak sites and extortion channels, and provides threat briefing intelligence to leadership.
    ๐ŸŽฎ TTX Scenario Specific Duty
    Correlate Trojan hash with known Telegram phishing campaigns, monitor dark web extortion portal for ADMFI customer leaks, and assist legal with attribution intelligence.
    ๐Ÿ“ Duty Checklist
    ๐Ÿ”ฎ Shadow Oracle Open Handbook (.md)
    CIO (Chief Information Officer)
    CIO (Chief Information Officer)
    Core IT Infrastructure & BCP Authority
    Final Recovery Sign-Off
    ๐Ÿ“Œ Core Mandatory Scope
    Ultimate executive authority over core IT systems and infrastructure. Receives mandatory SEV-1 notifications, authorizes enterprise disaster recovery activations, and provides final sign-off for system return-to-production.
    ๐ŸŽฎ TTX Scenario Specific Duty
    Authorize BCP/DR failover procedures, approve emergency infrastructure budget, and grant mandatory final recovery sign-off for returning file shares to live service.
    ๐Ÿ“ Duty Checklist
    ๐Ÿ“œ Lord Chancellor CIO Open Handbook (.md)
    CISO (Chief Information Security Officer)
    CISO (Chief Information Security Officer)
    Cybersecurity Governance & Compliance
    Strategic & Recovery Sign-Off
    ๐Ÿ“Œ Core Mandatory Scope
    Leads strategic cybersecurity response and governance. Ensures regulatory alignment, briefs the Executive Board, manages mandatory incident reporting to the National Bank of Cambodia (NBC) and CamCERT, and co-signs recovery.
    ๐ŸŽฎ TTX Scenario Specific Duty
    Brief Executive Board and Board Risk Committee, direct statutory breach notifications to NBC and CamCERT within 24 hours, and co-sign final incident closure.
    ๐Ÿ“ Duty Checklist
    โšœ๏ธ Grand Inquisitor CISO Open Handbook (.md)
    Executive Management & Board
    Executive Management & Board
    Strategic Business Risk & Public Affairs
    Strategic & Regulatory
    ๐Ÿ“Œ Core Mandatory Scope
    CEO, Board Risk Committee, Head of Legal, and Head of Communications. Evaluates strategic enterprise risk, approves high-impact business decisions (zero ransom policy), and governs public disclosures.
    ๐ŸŽฎ TTX Scenario Specific Duty
    Enforce strict organizational policy against paying ransom ($50,000 USD), authorize customer notifications if data is leaked, and govern press communications.
    ๐Ÿ“ Duty Checklist
    ๐Ÿ›๏ธ High Council Open Handbook (.md)
    Post-Incident Review & Reporting

    ๐Ÿ“Š After-Action Review (AAR) & SLA Evaluation Suite

    Evaluate exercise performance across key SLA milestones, track containment efficiency, review decision branch history, and export official debrief reports in 1 click.

    SLA Scorecard Evaluation
    P1 ยท SOC L1 Detection & Validation (<15m)PENDING
    P2 ยท EDR Host Isolation & Revocation (<30m)PENDING
    P3 ยท Major Incident WAR Room Declaration (<30m)PENDING
    P4 ยท NBC & CamCERT Regulatory Notification (<24h)PENDING
    Overall Containment & Grade
    0%
    Containment Achieved
    PENDING
    Overall SLA Grade
    Live Generated After-Action Report (AAR) Preview Markdown Format
    TTX Environment Configuration

    โš™๏ธ Scenario Customizer & Audio/Visual Preferences

    Customize scenario parameters (Target Organization, C2 IP, Ransom Amount, Domain), test audio/visual alarms, and manage simulation states.

    Scenario Parameters
    Audio & Visual Preferences
    Sound Effects (SFX)
    CRT Scanlines Overlay
    Emergency Alarm Test
    Language Toggle
    Session Reset & State

    Reset all SLA scores, decision branch outcomes, countdown timers, and combat logs to start a fresh exercise drill.

    LIVE DEFENSE & CRISIS CONTROL DOCK
    Click to Minimize (Q / Esc) โœ•
    โšก Quick SOC Containment Actions
    โฑ๏ธ Quick Discussion Timers
    ๐ŸŽฒ Quick Cyber Dice & Alarm
    ๐Ÿ›ก๏ธ EXERCISE COMMAND & FACILITATOR MASTER CONTROL CENTER

    Live Cyber TTX Master Panel

    Containment: 0%
    Grade: PENDING
    Click any stage to instantly jump & update display:
    Control branch paths across all 9 critical scenario decision points:
    20
    โš”๏ธ D20 Cyber Saving Throw Engine
    Roll to determine success of urgent RACI actions (DC 10 Normal, Nat 20 Critical Hit, <10 Saving Throw Failure).
    [System] Cyber defense combat engine active. Click d20 or trigger actions below.
    ๐Ÿ›ก๏ธ Synchronized Cyber Containment Workstreams
    Step through or auto-play all 10 chronological attack alerts:
    Speed:
    ๐Ÿ’€ Ransomware 72-Hour Extortion Clock
    71:59:45
    โฑ๏ธ Incident SLA Window Controls
    15:00
    ๐Ÿ’ฌ Discussion Session Timer
    --:--
    Evaluate participant performance against critical SLAs & RACI requirements:
    P1 ยท SOC L1 Detection & Validation (<15m)PENDING
    Triage phishing alert, analyze fake Adobe PDF trojan, create SEV-1 ticket, and escalate to L2.
    P2 ยท Host Isolation & Containment (<30m)PENDING
    Execute CrowdStrike EDR isolation on LOAN-LAPTOP-042 and revoke sok.dara Active Directory identity.
    P3 ยท Incident Command WAR Room (<30m)PENDING
    Formally declare Major Incident SEV-1, establish bridge, and deliver executive phone briefing to CIO & CISO.
    P4 ยท Regulatory Compliance Notice (<24h)PENDING
    Draft and submit preliminary regulatory incident disclosure to National Bank of Cambodia (NBC) & CamCERT.
    Select active participant persona to view specialized RACI handbook and trigger role-specific decisions:
    Detonate surprise live events during the drill to test team agility and crisis communications:
    ๐Ÿ“ž CEO Phone CallSEV-1
    CEO calls War Room demanding immediate media release draft within 10 minutes.
    ๐Ÿ“ฐ Social Media LeakHIGH
    Journalist tweets screenshot of stolen customer loan agreement posted on dark web.
    ๐Ÿ’ป Siem Reap Branch OutageWARN
    Branch staff report complete inability to open customer loan dossiers.
    ๐Ÿ›ก๏ธ CamCERT Alert BulletinINTEL
    CamCERT broadcasts national threat advisory on Ransomus active campaigns.
    โœ๏ธ Custom Live Inject Broadcaster
    ๐Ÿ”Š Synthesized Sound FX Studio
    ๐Ÿ“บ Visual Immersion Effects
    Customize the victim organization, compromised asset, regulatory authority, and ransom amount:
    โšก Quick Industry Presets
    Real-time generated After-Action Report (AAR) based on drill performance:
    ๐Ÿ“‹ Notification message