Loan Operations Ransomware & Data Exfiltration Tabletop Exercise
An end-to-end tactical simulation of an off-site loan officer targeted by social engineering via Telegram. The exercise walks through initial payload execution, internal network reconnection, C2 exfiltration of 5.2GB customer data, active file encryption, and multi-tier SOC & Crisis Command response aligned with formal RACI authority matrices.
- Triage Velocity: Validate SOC L1 triage accuracy & escalation to L2 in <15 minutes.
- 4-Pillar Containment: Execute synchronized host isolation, AD revocation, firewall C2 blocks, and storage share locks.
- Crisis Command: Establish Incident WAR Room bridge within <30 minutes and maintain 30-min executive cadence.
- Business Recovery: Verify clean immutable backup snapshot integrity and obtain CIO/Business sign-off.
- Regulatory Compliance: Comply with mandatory National Bank of Cambodia (NBC) and CamCERT statutory breach reporting within 24 hours.
Strict containment boundaries distinguish technical responders from operational command and executive authority:
- SOC L1/L2 Technical: Triage & Playbook Execution (<15m SLA, endpoint isolation).
- SOC Lead / L3: Senior forensics, threat hunting, and RCA co-authority.
- SOC Manager: Overall operational command, SEV-1 declaration, and containment authorization.
- Incident Communicator: WAR Room moderation & executive notices (NO containment authority).
- CIO & CISO: Final production recovery sign-off, Board briefing, and regulatory governance.
10โ19: 1,500 DMG (Pass)
1โ9: 0 DMG (Corruption)
๐ Comprehensive TTX Guides, SOPs & Documentation
Access all facilitator guides, readiness checklists, player briefing handouts, branching decision matrices, localized scenario variants, and executive presentation materials.
๐ Ransomware Tabletop Exercise (TTX) - Facilitator Guide
๐ Exercise Overview
๐ฅ Role Assignment & Authority Matrix Summary
| Role Title | Focus / Scope | Mandatory Core Responsibilities (SOP Aligned) | Containment Authority |
|---|---|---|---|
| SOC L1 (Tier 1 / Shift Duty) | Shift Triage | Monitor alerts continuously, validate FP vs TP, enrich context (asset, user, IP, impact), create ITSM ticket, escalate to L2 < 15 min, execute playbook containment for low/med severity, escalate directly to SOC Manager if L2 unavailable. | Low/Med Playbook Predefined |
| SOC L2 (Tier 2 Analyst) | Lead Investigation | Lead investigation, validate legitimacy & scope, confirm severity level, threat intel correlation, forensic log analysis & timeline reconstruction, assess business impact, recommend containment, execute high-severity containment per authority matrix, lead eradication, draft technical reports. | High Severity (per matrix) |
| SOC Lead / L3 | Senior Forensics | Support complex investigations, guide deep forensic analysis, authorize major containment actions, assist scoping & root cause analysis (RCA), escalation support for L2 uncertainty, share full authority with SOC Manager during SEV1. | Major Containment Authorized |
| Incident Communicator | Comms & WAR Room | Own all incident communications, create & manage WAR Room, coordinate stakeholders, notify executives per SLA, prepare & distribute Interim/Final reports, manage recovery comms, track action items. | โ NO Containment Authority |
| SOC Manager | Operational Authority | Overall operational authority during incidents, approve major containment actions, declare Major Incidents, engage BCP/DR process, coordinate executive escalation, oversee execution & reporting, ensure overdue action escalation. | Full Operational Approval |
| Business / Asset Owner | Business Context | Provide business/application context, participate in impact assessment, approve containment affecting production systems/apps, execute remediation & recovery, validate restoration & business recovery before closure. | Production System Approval |
| Network & System Team | Infrastructure Ops | Execute network and system containment requested by SOC, perform firewall blocks, account changes, or system actions when SOC lacks permission, support eradication & recovery, coordinate with SOC. | Technical Execution |
| CTI Team | Threat Intelligence | Provide IOC enrichment & campaign intelligence, support attribution analysis, track industry-wide threats & campaigns, assist threat intelligence correlation during investigations. | Intelligence Support |
| CIO | Core System Authority | Final authority during crises impacting core systems, approve recovery for SEV1 and SEV2 incidents, receive executive notifications, participate in BCP/DR discussions. | Final Recovery Sign-Off |
| CISO | Cyber Governance | Strategic oversight of cybersecurity response, regulatory & risk alignment, mandatory SEV1/SEV2 notification, approve recovery for SEV1 & SEV2, review reports & recommendations. | Strategic & Recovery Sign-Off |
| Executive Management | Board & Governance | CIO/CRO/CISO/Cyber Head/Heads of Division provide business & risk oversight, approve strategic decisions, make regulatory decisions, participate in high-severity governance. | Strategic & Regulatory |
๐ฌ Exercise Injects & Facilitator Script
๐ Inject 1: Unsanctioned Communication & Malicious Payload Arrival
Customer_Documents_2026.zip via Telegram from what appears to be an urgent customer loan applicant.
Telegram PhishingSigned_Agreement.pdf (disguised .exe). An Adobe Reader error pop-up appears: "Unable to render document format (0x80070005)". The user ignores the error and closes the app.
Fake PDF Error๐ Inject 2: LAN Reconnection & Reconnaissance
LOAN-LAPTOP-042) into the corporate LAN.\\ADMFI-FS01\Loan_Share$). It abuses existing Kerberos tokens under account sok.dara.๐ Inject 3: Data Exfiltration & SIEM Anomalies
185.220.101.45 (C2 domain: mal-c2.admfi-verify.com).
SIEM Dashboard๐ Inject 4: Active Encryption & HelpDesk Crisis
LOAN-LAPTOP-042 and \\ADMFI-FS01\Loan_Share$ are encrypted with .ADMFI_LOCKED extensions.
EDR Alert
Ransomware NoteLOAN-LAPTOP-042) freezes and displays a ransom note demanding $50,000 USD (USDT/Bitcoin) within 72 hours.๐ Inject 5: Major Incident WAR Room & Multi-Team Containment
War Room Dashboard185.220.101.45), AD account lockouts (sok.dara), and host isolation requested by SOC.\\ADMFI-FS01\Loan_Share$ Read-Only mode).๐ Inject 6: Eradication, Recovery & Business Sign-Off
๐ Plot Twists & When to Trigger Them
Plot Twists are optional facilitator escalations to be injected dynamically based on SOC team performance. Use them to challenge a team responding well, or to pivot the scenario trajectory.
| # | Plot Twist | Trigger Condition | Best Injection Point |
|---|---|---|---|
| ๐ 1 | Telegram BEC Hijack: Attacker uses stolen session cookies to log into Head of Loans Telegram account (@vuthy_loan_head) and broadcasts a malicious fake VPN link to 45 loan officers. | SOC has successfully isolated Sok Dara's laptop. | Between Inject 2 and 3. |
| ๐ 2 | Shadow Copy & Backup NAS Wipe: Malware runs vssadmin delete shadows /all /quiet and attempts to authenticate to \\ADMFI-BKP01 using cached Domain Admin credentials. | Team starts discussing backup restoration. | After Inject 4, when recovery planning begins. |
| ๐ 3 | Public Customer Data Leak: Threat actor posts 50 customer ID cards and land titles on a public Telegram channel with a 24-hour ultimatum to dump all 3,500 records. | Ransom demand discussion begins. | After Inject 5, to escalate Legal/CISO/CIO governance pressure. |
๐ TTX Evaluation & KPI Scoring Rubric
| Metric / KPI | Target SLA | Evaluation Criteria |
|---|---|---|
| L1 Alert Validation | < 15 Mins | Did L1 determine TP and escalate to L2 within 15 mins (or SOC Mgr if L2 unavailable)? |
| L2/L3 Containment Authority | < 30 Mins | Did L2 lead investigation and Network/System team execute firewall/AD actions per authority matrix? |
| Executive Notification | < 15 Mins | Did Incident Communicator notify CISO, CIO, and Cyber Head per SLA? |
| WAR Room Setup | < 30 Mins | Was central WAR Room established with key role stakeholders represented? |
| Business Recovery Confirmation | Pre-Closure | Did Asset Owner validate restoration and CIO/CISO approve SEV1 recovery before closure? |
| Overdue Action Tracking | Post-PIR | Did SOC Manager and Communicator establish tracking escalation for overdue PIR actions? |
๐ TTX Readiness & Required Materials Checklist
๐ก๏ธ Pre-Exercise Setup, Communication Channels & Resource Checklist
1. ๐ข Communication Channels & Contact Lists
| Category | Channel / Tool | Purpose & Details | Status / Action Item |
|---|---|---|---|
| Primary Exercise Chat | MS Teams / Slack Channel: #TTX-Ransomware-2026 | Real-time text communications during exercise injects. | โฌ Ready |
| Out-of-Band (OOB) Comms | Dedicated Telegram / Signal Group | Simulated emergency comms when primary IT networks are "down". | โฌ Ready |
| Incident WAR Room | MS Teams / Zoom Bridge: TTX Incident Command | Virtual bridge activated during Phase 3 Crisis Escalation. | โฌ Ready |
| Executive Contact Roster | Printed / PDF Escalation Roster | Phone numbers for CISO, CIO, SOC Lead, Legal, PR & BCP Officer. | โฌ Ready |
| Regulatory Contacts | Pre-drafted Contact Sheet | Contact emails/phones for National Bank of Cambodia (NBC) & CamCERT. | โฌ Ready |
2. ๐ Scenario Documents & Role Handbooks
facilitator_guide.md (Facilitator script, inject timing & discussion prompts).ransom_ttx.md & khmer_ransomware_scenario.md .soc_ttx_briefing_slides.md (Slide presentation for team briefing).roles/ ):SOC_L1_Analyst.md)SOC_L2_Analyst.md)SOC_Lead_L3.md)IR_Communicator.md)SOC_Manager.md)Business_Asset_Owner.md)Network_System_Team.md)CTI_Team.md)CIO.md)CISO.md)Executive_Management.md)3. ๐ฅ๏ธ Hardware, Visual Assets & Room Infrastructure
[ MAIN PRESENTATION SCREEN ]
(Runs index.html Portal & Mockups)
โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โผ โผ โผ
[ Facilitator Desk ] [ SOC Operations Desk ] [ Executive Command Desk ]
- Facilitator Guide - Laptops & SOP Playbooks - Executive Escalation Sheet
- Master Inject Clock - ITSM / SIEM Mockup Access - Legal & NBC Notification Forms
- Scribe / Minute Notebook - EDR Isolation Controls - BCP Decision Matrixindex.html for full-screen slide presentations.assets/ ):telegram_phishing.jpg (Telegram payload screenshot)fake_pdf_error.jpg (Adobe error window)edr_ransomware_alert.jpg (CrowdStrike alert console)ransomware_note.jpg (Victim lock screen)siem_dashboard.jpg (QRadar correlation dashboard)war_room_dashboard.jpg (Incident Command board)4. ๐ Administrative, Scribing & Evaluation Materials
5. ๐ Pre-TTX Kickoff Checklist (T-Minus 30 Minutes)
1. [ ] Confirm all participants are logged into the primary chat channel (#TTX-Ransomware-2026).
2. [ ] Test video/audio bridge if conducting a hybrid or virtual exercise.
3. ] Verify main presentation screen is displaying [index.html .
4. [ ] Distribute role handbooks to designated participants.
5. ] Deliver the SOC Team Briefing Slides ([soc_ttx_briefing_slides.md ) to set exercise ground rules and objectives.
6. [ ] Release Inject 1 and start the exercise master clock!
marp: true
theme: default
paginate: true
header: "๐ก๏ธ SOC Briefing | Ransomware Tabletop Exercise (TTX)"
footer: "Confidential - Cybersecurity Operations Center"
๐ก๏ธ SOC Team Briefing: Ransomware Tabletop Exercise (TTX)
๐ฏ Executive & Operational Orientation Slide Deck
Presenter: SOC Lead / Facilitator
Target Audience: SOC L1, SOC L2, SOC Lead/L3, SOC Manager, IR Communicator, CTI Team
Exercise Context: Off-site Phishing, C2 Beaconing, SMB Exfiltration & Ransomware Outbreak
Date: August 2026
๐ 1. Why Are We Running This TTX?
Background & Operational Reality
Customer_Documents_2026.zip), triggering fake error messages while establishing covert background persistence.Loan_Share$).๐ฏ Core Purpose: To test, evaluate, and refine our SOC Incident Response SOPs, detection capabilities, team escalation SLAs, and crisis communication in a simulated, zero-risk environment.
๐ฏ 2. Core Exercise Objectives
| # | Objective | Success Criteria / SLA Target |
|---|---|---|
| 1 | โฑ๏ธ Validate SLA Speed | SOC L1 โ L2 escalation in <15 mins; Executive notification in <15 mins for SEV-1. |
| 2 | ๐ Test Containment Playbooks | Rapid execution of EDR host isolation, AD session revocation, C2 IP blocking, and file share restrictions. |
| 3 | ๐ฌ Practice Crisis Comms | Incident WAR Room creation within 30 mins; stakeholder status updates every 30โ60 mins. |
| 4 | ๐ Scoping & Threat Hunting | Accurate mapping of initial access vector, lateral movement attempts, and compromised assets. |
| 5 | ๐ Identify Gaps & Improve | Uncover friction points between SOC, IT Infrastructure, Legal, and Business teams. |
๐ 3. Scenario At A Glance: "ADMFI Ransomware Incident"
[ Telegram Phishing ] โโ> [ Fake PDF Error ] โโ> [ Silent C2 Connection ]
โ
[ Shared Folder Encryption ] <โโ [ Data Exfiltration ] <โโ [ LAN Reconnection ]
โ
โโโ> ๐จ CrowdStrike EDR Critical Alert (Host Isolated)
โโโ> ๐ QRadar SIEM Event Correlation (Anomalous SMB Access)
โโโ> ๐ Ransom Note Displayed ($50,000 USD Demand)Customer_Documents_2026.zip containing Loan_Agreement.pdf.exe via Telegram..ADMFI_LOCKED extension across local workstation and shared drive (\\ADMFI-FS01\Loan_Share$).๐ญ 4. SOC Roles & Expectations Matrix
| Role | Key Focus | Primary Responsibilities During TTX |
|---|---|---|
| SOC L1 Analyst | Initial Triage | Monitor SIEM/EDR, validate alerts, enrich context, open ITSM ticket, escalate to L2 <15m. |
| SOC L2 Analyst | Lead Investigation | Scope blast radius, create forensic timeline, execute host isolation, block IOCs. |
| SOC Lead / L3 | Deep Forensics | Reverse engineer malware sample, lead enterprise threat hunting, assist complex containment. |
| SOC Manager | Incident Command | Declare SEV-1 Major Incident, authorize production containment, engage CISO/CIO & BCP. |
| IR Communicator | Comms & WAR Room | Setup MS Teams WAR Room <30m, issue interim updates every 30-60m, draft AAR. |
| CTI Analyst | Threat Intel | Enrich IOCs, correlate threat actor TTPs, search external campaign intelligence. |
๐จโ๐ป 5. Deep Dive: SOC L1 & SOC L2 Execution Responsibilities
๐น SOC L1 Analyst (Tier 1 Duty)
1. Acknowledge & Validate: Confirm EDR alert (CrowdStrike) & SIEM correlation (QRadar) are True Positive.
2. Enrich Context: Gather Endpoint Name, IP address, User Account (sok.dara), Hash, and Alert Severity.
3. Log & Escalate: Create ITSM Ticket (#INC-2026-0814) with provisional SEV-1 rating and transfer to L2 in <15 minutes.
๐น SOC L2 Analyst (Tier 2 Incident Lead)
1. Forensic Timeline: Reconstruct timeline from Telegram download โ C2 beacon โ LAN connection โ SMB enumeration.
2. Execute Containment: Isolate infected endpoint in EDR console immediately.
3. Enforce Restrictions: Request AD account lock, active token revocation, C2 domain/IP firewall block, and SMB write restriction.
๐ 6. Deep Dive: SOC L3, SOC Manager & IR Communicator
๐ฌ SOC Lead / L3 Analyst
Loan_Agreement.pdf.exe.e3b0c442...).๐ SOC Manager (Incident Commander)
๐ฌ Incident Communicator
๐ 7. Exercise Ground Rules & Mindset
1. Speak Up & Participate: Explain your actions step-by-step: "I am checking X log file, issuing Y command, and notifying Z role."
2. Focus on SOP Alignment: Reference our official playbooks (Ransomware SOP & Account Compromise SOP).
3. Challenge Assumptions: If a procedure is unclear, redundant, or missing authorization, raise it during the inject discussion.
4. No Real Production Impact: All actions discussed are hypotheticalโno live systems will be disrupted.
๐ 8. SOC Response Workflow Summary
๐ 9. Post-TTX Deliverables & Next Steps
1. ๐ After-Action Report (AAR): Documenting key observations, SLA compliance, and technical findings.
2. ๐ ๏ธ SOP & Playbook Updates: Refining containment matrix, containment delegation authority, and communication templates.
3. ๐ฏ Detection Engineering Tuning: Adding custom EDR prevention rules and SIEM correlation alerts for double-extension files (.pdf.exe).
4. ๐ Action Item Tracking: Assigning clear ownership and deadlines for all identified gaps.
โ Questions & Readiness Check
Are all SOC team members clear on their roles and objectives? Let's begin Inject 1!
๐ณ "What If... / Then If..." Branching Injects & Decision Tree Guide
๐ก๏ธ Tabletop Exercise (TTX) Dynamic Decision Paths & Scenario Outcomes
๐งญ Decision Tree Overview
๐ Phase 1: Off-site Telegram Payload Receipt
๐น Branch 1A: EDR Auto-Quarantine (Best Case)
Customer_Agreement_2026.pdf.exe immediately upon extraction?1. Malware execution fails; no persistence or C2 beacon is established.
2. EDR generates Alert #1042 (Medium Severity).
3. SOC L1 Action: Quarantines hash enterprise-wide and notifies Loan Department to issue warning about Telegram account @chanthy_loan_applicant.
4. Exercise Outcome: Incident contained at Phase 1. Proceed to Threat Hunting verification.
๐น Branch 1B: Silent Persistence & Background C2 (Default Path)
0x80070005 and malware establishes silent registry run key persistence under standard user context? 1. Malware connects covertly to C2 IP 185.220.101.45:443.
2. Malware goes dormant, polling C2 every 60 seconds waiting for corporate domain ADMFI.LOCAL signal.
3. SOC L1 Action: No alert generated yet (stealth payload). Proceed to Phase 2 LAN Reconnection.
๐น Branch 1C: Telegram Session & Credential Hijack (Plot Twist Variant)
1. Attacker steals active session tokens for Senior Loan Officer Sok Dara.
2. Attacker logs into Sok Dara's Telegram account and sends malicious payload .zip files to 30 other loan officers!
3. SOC L2 Action: Must execute immediate credential revocation, active session teardown, and internal broadcast warning.
๐ Phase 2: Corporate LAN Reconnection & SMB Scanning
๐น Branch 2A: Host Isolation <5 Minutes (Ideal SOC Response)
\\ADMFI-FS01\Loan_Share$ and executes EDR host isolation within 5 minutes?1. Ransomware execution on Shared Drive is aborted mid-process.
2. Only 5 local files on Sok Dara's laptop are encrypted; corporate file server remains 100% clean.
3. Impact: Minor workstation re-image required. Incident resolved within 2 hours.
๐น Branch 2B: Delayed Containment >30 Minutes (High Impact - Default)
1. Ransomware encrypts 12,000 files across 4 shared folders (Loan_Share$, HR_Share$, Finance_Share$) in 4 minutes.
2. File extension changes to .ADMFI_LOCKED.
3. EDR triggers CRITICAL SEV-1 alert; SOC Manager declares Major Incident & activates WAR Room.
๐น Branch 2C: Pass-The-Ticket Domain Admin Escalation (Catastrophic Path)
1. Attacker deploys ransomware Domain-wide via Active Directory Group Policy Objects (GPO).
2. 45 workstations and 6 servers across Phnom Penh & Siem Reap branches freeze simultaneously.
3. CIO Action: Authorizes total isolation of corporate network and mandates full BCP/DR activation.
๐ Phase 3: Ransom Demand & Backup Restoration
๐น Branch 3A: Immutable Backup Clean Restoration (Recovery Success)
Loan_Share$ immutable storage snapshots taken at 12:00 PM are uncompromised?1. CIO & CISO approve clean data restoration.
2. IT re-images laptop, wipes infected shared folders, and restores from immutable snapshot in 4 hours.
3. Ransom Outcome: Zero ransom paid. Operations restored cleanly.
๐น Branch 3B: Shadow Copy & Secondary Backup Wipe (Plot Twist 2)
vssadmin delete shadows /all /quiet and wipes connected network backup NAS drives?1. Local volume shadow copies and hot NAS backups are destroyed.
2. IT must fallback to off-site tape / cold cloud backup (RTO increases to 24-48 hours).
3. Executive Action: BCP Committee convenes to manage manual paper-based loan processing workarounds.
๐น Branch 3C: Ransom Negotiation Dilemma
1. CISO & Legal advise that paying violates NBC cybersecurity compliance guidelines and OFAC sanctions.
2. Attacker provides test decryption key, but key fails on 40% of large database files (corrupt decryption).
3. Outcome: Financial loss without guaranteed data recovery.
๐ Phase 4: Double Extortion & Public Data Leak
๐น Branch 4A: Telegram Public Customer Data Leak (Plot Twist 3)
1. Media and social media pick up the leak within 2 hours.
2. Legal & CISO Action: Mandatory notification to National Bank of Cambodia (NBC) and CamCERT within 24 hours.
3. PR Action: Release official press statement reassuring customers and setting up dedicated customer inquiry hotline.
๐น Branch 4B: CTI Takedown & Managed Disclosure
1. Public exposure is contained to dark web leak site only (admfi-leaks.onion).
2. PR holds press statement while Legal fulfills NBC regulatory briefing requirements privately.
๐ Summary Decision Matrix for Facilitators
| Scenario Phase | Branch Choice | Trigger Condition | Operational Consequence | Recommended Discussion Prompt |
|---|---|---|---|---|
| Phase 1 | 1A / 1B / 1C | SOC EDR Policy Enforcement | Clean Quarantine vs. Silent C2 vs. Telegram BEC | How do we secure Telegram off-site workflows? |
| Phase 2 | 2A / 2B / 2C | SOC Isolation Speed (<5m vs >30m) | Local PC Only vs. Shared Drive Lock vs. Domain Wipe | Does SOC L2 have pre-approved isolation authority? |
| Phase 3 | 3A / 3B / 3C | Backup Air-gap Status | 4-Hour Recovery vs. Disaster Recovery vs. Ransom Loss | How do we verify backup immutability under attack? |
| Phase 4 | 4A / 4B | Public Leak Occurrence | NBC Audit & PR Crisis vs. Private Regulatory Briefing | What is our NBC regulatory notification timeline? |
๐ฐ๐ญ แแแถแแแถแแแแแแแถแแธแแแผ Simulation Ransomware แแแแแแแแ (Khmer-Style Cyber Ransomware TTX Scenario)
ransom_ttx.md | facilitator_guide.md | index.html 1. แแแแแแแแแแถแแธแแแผ (Executive Summary)
แแแแแแแธแฅแแแถแแแถแแแแแแแ แแแ แแปแ แแถแแแถ แแแแแแนแแแแแถแแแธแแแแผแ แทแแแแแแแแแป ADMFI แแแแ แถแแแถแแแถแแธแแแแแแแ แแถแแแแแแแแถแแแทแ แแ แแฝแแขแแทแแทแแแแ แแแแ แแถแแทแแถแแแ (Off-site) แแ แ แถแแแถแ แแแแแฝแแแแแแแแ แแผแ แแถแแแแแถแแแแผแแ แแแแแแแทแแแแแทแแถแแฅแแแถแแแ แแแแแปแแถ แแแแแแแธแฅแแแถแแแผแแแแแแแแแแแแแพแแแแถแแ Telegram แแพแแแแธแแถแแแแ แแแแพ-แแแฝแ แฏแแแถแแแแแพแแปแแแแแ แธ แขแแแแแแแแถแแแแแแ แแผแแแแแแแแแแแถแแถ แแทแแแแแแแแแแแแทแแแแทแแธแแแแธ (แแแแแแแนแ/แแแแแแแแ)แ
แแแแปแแขแแกแปแแแแแแแแพแแถแ แแแ แแปแ แแถแแแถ แแถแแแแฝแแแถแ Telegram แแธแขแแทแแทแแแแแแธแแแแถแแแแแแแแแพแแแแถแแแแแแแ "แแแแแแแธ แแนแ แ
แถแแแแธ" แแแแแถแแแแแพ file แแแแแ แฏแแแถแ_แแแแพแแปแ_แฅแแแถแ_แขแ แขแฆ.zipแ แแแปแแแแ แแ
แแแแปแ zip file แแแแแถแ file แแแแแแแแผแแแแแแ (Malware Exe) แแแแแแแแแแแแแแแถ file PDF แแแแแ แแแแแแแแ_แแแแ
แธ_แขแแทแแทแแ.pdf.exeแ
แแ แแแแแแ แแถแแแถ แ แปแ แแพแ file แแแ แแแแแแทแแธแแถแแแแแ แถแแแแแถแแ Error แแแแแแแแแถแแแถ "แแทแแขแถแ แแพแแฏแแแถแ PDF แแถแแแ แแแแแถแแฏแแแถแแแผแ (Corrupted File)"แ แแแแแทแแแถแขแแทแแทแแแแแแพ file แแผแ แแแ แแถแแแถ แแแแถแแแแแ แ แพแแแแแแแแแพแแถแแแแแแแถแ แแแปแแแแแแ แแธแแแแแแแแแ แแแแแแแถแแ แถแแแแแแพแ run แแแแแแแถแแแ แแแแแแ แผแแแแแแแแแ laptop แแแแแแแ แแถแแแถ แแทแแแแแถแแแแแแถแแแแแแแแ แแถแแ attacker Command & Control (C2) Serverแ
แแปแแแแแแกแพแ แแแ แแถแแแถ แแถแแแแแกแแแแแแถแแแแถแแทแแถแแแแแแแแถแ ADMFI (Head Office) แ แพแแแถแแแแแแแแแแแแแถแ LAN แ
แผแแแ
แแแแปแแแแแแถแแแแแแแแแปแ (Corporate Network 10.20.0.0/16)แ แแแแถแแแแแ แแแแแ Ransomware แแถแแแนแแแถ laptop แแถแแแแแถแแแ
แผแแแแแแถแแแแถแแถแ แ แพแแแถแแถแแ
1. แแแแแแแ Shared Drives แแแแแแถแแแแแแถแแฅแแแถแ (\\ADMFI-FS01\Loan_Share$)
2. แแแแถแแแทแแแแท (Abuse Authenticated Token) แแแแแแแ แแถแแแถ แแพแแแแธแแฝแ แแทแแแแแแแขแแทแแทแแ (Data Exfiltration) แแแแพแแ C2 Server
3. แ
แถแแแแแแพแ Encrypt (แแแแแแแผแแ
แแ) แแพแแถแแแฏแแแถแแแถแแแขแแแแ
แแพ Laptop แแทแ Shared Folder แแแแแแแแปแแฅแแแถแ แแแแแแแผแ extension แแ
แแถ .ADMFI_LOCKED
4. แแแแ แถแ Ransom Note แแถแแแแแถแแแ แแแฝแ $50,000 USD แแถ Bitcoin/USDTแ
2. แแฝแขแแแ แแทแ แแแแปแแแถแแแถแแแแแปแแแแแถแแธแแแผ (Key Persona & Roles)
| แแแแแ / แแฝแแถแแธ | แแถแแถแขแแแแแแแ | แแถแแแทแ แแ แแแแปแแแแแถแแธแแแผ |
|---|---|---|
| แแแ แแปแ แแถแแแถ | Senior Loan Officer | แแแแแแแแแแแแแผแ (Initial Victim) แแแแแถแแแพแ file แแแแแแแถแ Telegram แแแแแแแพแแถแ off-site |
| แแแแแแแธ แแนแ แ แถแแแแธ (Fake) | Threat Actor / Phisher | แแแแธ Telegram แแแแแแแแแถแแแแแแแแพ payload แแแแแ Ransomware |
| แแแ แแแ แ แถแแแแธ | SOC L1 Analyst | แขแแแแแแฝแแแถแ Alert แแแแผแแแธ EDR/SIEM แแทแแแถแขแแแแแแแแพแ ITSM Incident Ticket |
| แแแ แแแ แแปแแแแธ | SOC L2 Analyst | แขแแแแแนแแแถแแแถแแแแพแแขแแแแแแแ แแ แแแแแ แแแแพ Forensic Timeline แแทแ Isolate Host |
| แแแ แ แแถแ แแปแแ | SOC Lead / L3 | แขแแแแแทแแถแแแแแแแแแแแ แแแแ (Malware Reverse Engineering) แแทแแแฝแแแแแแแ containment |
| แแแแแแแธ แแแปแแแแถ | CISO | แขแแแแแแแแแแแแแแปแแแแแถแแแแแ แแปแแแแแทแแถแแแแแแแถแ แแทแแแถแแแถแแแแแผแ แแแถแแถแแแถแแทแแแแแแแปแแถ (NBC) |
| แแแ แ แถแแ แแทแแถแ | CIO | แขแแแแแแแแแ แ แทแแแแแพแแแแแแแแ Core Banking, IT Infrastructure แแทแแแถแแแแแแถแ BCP |
3. แแแ แผแแแแแถแแแถแแแแแ แถแ (Attack Progression Flowchart)
4. แแแแพแแแถแแแแแพแแแแขแถแแแแ SOP (Incident Response SOP Flowchart)
5. แแแแแถแแแ แแทแ แ แแแแฝแแแแแแถแแแแทแแถแแแแถ (TTX Discussion Injects)
๐น Inject 1: แแแแ แถแแแแแแแแแถแแแแแพแแแแถแแ Telegram แแแแปแแแแแแทแแแแแทแแถแแฅแแแถแ (Off-site Work Risks)
1. แแพแแแแผแแแแแแแแแแแแ แแแถแแแถ แ แแแแแแถแแขแแปแแแแถแ แฌ แ แถแแแถแแแแถแแแถแแแ file แแธ Telegram แ แผแแแแแปแ Laptop แแแแปแแ แแปแ?
2. แแแแแทแแแพแขแแทแแทแแแแแแพ file .zip แฌ .rar แแพแแแแแแแแแแปแแแแแทแแถแแขแปแธแแแ แฌ Endpoint Defender แแฝแแแแแแแพแแถแแแแแแแแถแแแแแแแแแแแแแแแแแแทแแแแฌแแ?
๐น Inject 2: แแถแแแแแแแแถแแแแแ Ransomware แ แถแแแแแแพแ encrypt file แแพ Shared Drive
\\ADMFI-FS01\Loan_Share$ แแแแผแแแแแแแแแแแแถ .ADMFI_LOCKED แแแแปแแแแแฟแ แฅแ files/แแทแแถแแธแ1. แแพ SOC L1/L2 แแถแแแทแแแแทแขแแแถแ แแแแแแแแแแปแแแถแ Isolate Laptop แแแแแแแ แแถแแแถ แแแแแทแแแถแ แแแแแ แถแแแถแแแแแแแแแแธ Business Owner แแแแฌแแ?
2. แแพแแแแผแแแแแพแแผแ แแแแแ แแพแแแแธแแถแแแถแ Shared Drives แแแแแแแแ (แแผแ แแถ HR, Finance, Core Banking Backups) แแทแแฒแแแแแถแแแแแแแแ?
๐น Inject 3: แแถแแแแแแแแแแแแทแแแแแท แแทแ แแถแแแแแแทแ แแ แ แแแถแแ/แแแแแแแแแแแแท (NBC Compliance & Data Leak)
1. แแพแแแถแแถแ ADMFI แแถแแแแแแถแแแ "แแทแแแแแแแแถแแแแแ (No-Ransom Policy)" แแแแฌแแ?
2. แแพแแถแแแแแแถแแ แแแถแแ แแทแ CISO แแแแผแแแถแแแถแแแแแผแ แแแถแแถแแแถแแทแแแแแแแปแแถ (NBC) แแทแ CamCERT แแแแปแแแแแแแแแแปแแแแถแแแแแแแแแแถแแแแธแแนแแแถแแถแแแทแแแแแแแแแ แแแแถแ?
3. แแพแแแแผแแแแแพแแแแแนแแแถแแแแแแแถแ (Public Relations) แแแถแแแผแ แแแแแ แแแแแทแแแพแแแแแแถแแแแแแแ แแแแถแแแพแแแแแถแแแแแแ Facebook/Telegram?
6. แแผแ แแถแแแแ แแ แแแแแแแแแถแแแถแแแแแ แถแ (Technical IOCs Table)
| แแแแแแ (Type) | แแแแแแถแแแ แแ แแแแแ (Indicator / Value) | แแถแแแทแแแแแถ (Description) |
|---|---|---|
| File Name | แฏแแแถแ_แแแแพแแปแ_แฅแแแถแ_แขแ แขแฆ.zip | Archive file แแแแแแฝแแแถแแแถแ Telegram |
| Payload Executable | แแแแแแแแ_แแแแ
แธ_แขแแทแแทแแ.pdf.exe | Double extension malware executable |
| SHA-256 Hash | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 | Malicious Trojan Loader Hash |
| C2 Domain | mal-c2.admfi-verify.com | Attacker Command and Control Server Domain |
| C2 IP Address | 185.220.101.45 | External Malicious IP (Blocked at Firewall) |
| Encrypted Extension | .ADMFI_LOCKED | File extension after ransomware encryption |
| Ransom Note File | READ_ME_FOR_DECRYPT.txt | Instructions left by attackers on desktop and file shares |
| Attacker Telegram ID | @chanthy_loan_applicant_2026 | Phishing Account used to target Loan Officers |
7. แแถแแถแ RACI Matrix แแแแแถแแ Incident Response (ADMFI Context)
| แแแแถแแแแถแ (Phase) | SOC (L1/L2/L3) | Network & IT Sys | Business Owner (Loan) | CISO / Legal | CIO / ExCo |
|---|---|---|---|---|---|
| แก. Detection & Triage | Accountable / Responsible | Informed | Informed | Informed | Informed |
| แข. Host & User Containment | Responsible | Consulted | Informed | Informed | Informed |
| แฃ. Network & Server Isolation | Consulted | Responsible | Informed | Informed | Informed |
| แค. Crisis Escalation & NBC Comms | Consulted | Informed | Informed | Responsible | Accountable |
| แฅ. Eradication & Backup Recovery | Consulted | Responsible | Consulted | Consulted | Accountable |
| แฆ. Final RCA & Closure | Responsible | Consulted | Consulted | Consulted | Accountable |
๐ก๏ธ TTX Ransomware Exercise Scenario
ttx_story_book.md for chapter prose, dramatic plot twists, character twist questions, and visual assets. ๐ D&D Style Campaign Guide: See dnd_campaign_guide.md for full start-to-finish gamified roleplay scripts and D20 dice mechanics. ๐ PowerPoint Presentation: Download Ransomware_Incident_TTX_Presentation.pptx for executive briefings. ๐ Interactive TTX Portal & Slide Deck: Open index.html in your browser for full-screen slide presentations and interactive injects. ๐ Facilitator Guide: See facilitator_guide.md for step-by-step facilitator scripts and discussion prompts. ๐ญ Role Cards: Explore character roles in roles/ . ๐ธ Visual Screenshots: View high-resolution threat mockups in assets/ . Summary
Loan officers regularly work off-site to meet customers and primarily use Telegram to communicate and exchange loan applications, contracts, identification records, and supporting documents. He receives a compressed archive named Customer_Documents_2026.zip through Telegram from what appears to be a legitimate customer. The archive contains a malicious executable disguised as a PDF document.
The employee extracts the archive and opens the apparent PDF file. A fake document error appears, leading the employee to assume that the customer sent a corrupted document. No administrator credentials are requested, and no software installation window appears. The employee ignores the error and continues working.
Behind the fake error message, malware begins running silently under the employee's standard user account. It establishes user-level persistence, communicates with attacker-controlled command-and-control infrastructure, and waits for access to the corporate environment.
Later, the employee returns to the office and reconnects the infected laptop to the corporate LAN. The malware detects the corporate network and begins several activities in parallel, It discovers accessible Loan Team file shares and abuses the employee's existing authenticated access. It collects sensitive loan and customer documents and attempts to exfiltrate them. It targets available authentication information and attempts to access other systems authorized to the employee. After completing its initial discovery and data-collection activities, the attacker activates the ransomware. The ransomware begins encrypting files stored locally on the Loan Team laptop and documents within accessible Loan Team shared folders.
EDR detects the ransomware behavior and generates a critical alert. At the same time, the SIEM receives and correlates multiple security events from EDR, the firewall, Active Directory, and file servers. These events indicate suspicious external communication, abnormal authentication activity, unusually high file access, and rapid modification of shared documents.
The employee's laptop becomes unresponsive and displays a ransom note. The employee reports the issue to the Help Desk, while the SOC begins reviewing the EDR and SIEM alerts. The SOC validates the ransomware activity, contains the affected endpoint and identity, activates the Incident Response process, assesses the potential impact on Loan Team file shares and customer data, and informs cybersecurity and management stakeholders.
Scenarios Flow
Responding Action
Response Action (SOP Aligned)
What action should do when ransomware happend, ensure SoP is follow.
๐ The Ransomus Protocol: An Interactive Cyber Crisis Storybook
A Narrative Tabletop Exercise Book with Dramatic Plot Twists, Character Interrogations, and Visual Incident Mockups.
Incident Response Command Team๐ Prologue: The Anatomy of a Modern Cyber Attack
It was a rainy Tuesday morning at Loan Corp Headquarters. Loan officers operated on the frontlines of commercial lending, constantly closing high-value mortgage deals and business credit lines. To stay nimble in a hyper-competitive market, loan officers frequently met VIP clients off-site at coffee shops, hotel lobbies, and remote branches.
To expedite documentation exchanges, loan officers relied heavily on corporate Telegram desktop channelsโa convenient, unsanctioned shadow IT channel for sending signed PDF applications, tax records, and identity archives.
Unbeknownst to the team, a sophisticated nation-state threat group known as Ransomus was monitoring these informal channels, waiting for the perfect moment to slip through the castle gates...
๐ธ Chapter 1: The Telegram Phishing Payload & Disguised Execution
Telegram Phishing Vector๐ The Narrative
At 09:15 AM, Alex, a senior commercial loan officer, was working remotely from a downtown coffee shop. A notification popped up on his Telegram app from a verified customer contact profile named "VIP Client - Horizon Real Estate".
Attached was a compressed archive titled Customer_Documents_2026.zip (size: 42 MB). The message read:
"Alex, attached are our signed commercial loan agreements and bank statements for the $12M property acquisition. Please review urgently before noon!"
Eager to close the deal, Alex extracted the archive. Inside was a file with a familiar Adobe PDF icon named Signed_Agreement.pdf.exe. Double-clicking it triggered a brief spinner, followed by a Windows system error dialog:
Fake Adobe PDF ErrorSystem Error: Adobe Acrobat Reader DC - Unable to render document format (0x80070005). File may be corrupted.
Alex assumed the client sent a broken file, closed the error box, sent a quick Telegram message asking for a resend, and moved on to other emails.
Behind the screen, the trap was sprung. The disguised executable silently injected a malicious DLL into svchost.exe, established user-level registry persistence, and initiated encrypted HTTPS beacons to 185.123.45.6:443.
๐ Dramatic Plot Twist 1: The Insider Credentials Leak
TWIST: The Telegram profile that sent the file belonged to an actual high-value client whose personal Telegram account had been hijacked 24 hours earlier! Furthermore, EDR telemetry reveals that the Trojan payload harvested Alex's saved Active Directory credentials and Chrome browser tokens during the error popup!
โ Hot-Seat Character Interrogation Questions (Chapter 1)
| Character Role | Hot-Seat Twist Question for the Player |
|---|---|
SOC L1 Analyst | "An EDR alert fires for LOAN-LAPTOP-042 showing an unrecognized process spawn (explorer.exe -> Signed_Agreement.exe -> svchost.exe). The user reports it as a harmless Adobe glitch. Do you dismiss it as a False Positive or escalate? What is your 15-minute SLA protocol?" |
SOC L2 Analyst | "The malware did not request admin privileges and ran under standard user permissions (j.smith). How do you validate whether this is a commodity Trojan or an targeted APT payload?" |
CTI Team Analyst | "Threat intel links IP 185.123.45.6 to a known ransomware syndicate. What campaign indicators do you immediately feed to L1/L2?" |
๐บ๏ธ Chapter 2: The Corporate LAN Reconnection & Silent Reconnaissance
Global Cyber Threat Map๐ The Narrative
By 02:00 PM, Alex finished his off-site meetings and returned to corporate headquarters. He sat down at his desk and plugged LOAN-LAPTOP-042 directly into an Ethernet jack connected to the corporate LAN.
The moment the laptop obtained an internal IP (10.15.34.120), the dormant malware spirit detected the corporate domain controller (AD-DC01).
Exploiting Alex's existing Kerberos session tokens, the Trojan launched automated network reconnaissance. It mapped accessible network shares, discovered \\FS01\LoanShares, and performed Kerberoasting queries to harvest service account ticket hashes.
๐ Dramatic Plot Twist 2: The Unpatched Domain Controller
TWIST: The attacker utilizes the compromisedj.smithaccount to query Active Directory for Domain Admin service accounts. The SOC discovers thatAD-DC01is missing a critical patch for a known privilege escalation vulnerability (CVE-2026-1102), allowing a standard user account to request elevated Kerberos TGS tickets!
โ Hot-Seat Character Interrogation Questions (Chapter 2)
| Character Role | Hot-Seat Twist Question for the Player |
|---|---|
Network SystemNetwork & System Team | "Active Directory reports 50+ Kerberos TGS requests per second originating from LOAN-LAPTOP-042. Do you instantly isolate the network switch port or wait for SOC Manager approval?" |
Business / Asset Owner | "The network team proposes isolating \\FS01\LoanShares. This will halt 200 loan officers nationwide from closing deals today. Do you authorize this operational freeze?" |
SOC Manager | "L2 requests host isolation for LOAN-LAPTOP-042 and account lockout for j.smith. Who holds mandatory operational authority to approve this action under the RACI matrix?" |
๐ Chapter 3: The 5GB Exfiltration Shadow & SIEM Alarm
IBM QRadar SIEM Dashboard๐ The Narrative
At 02:25 PM, the attacker activated the exfiltration module. Compressed archives containing 5.2 GB of confidential customer loan applications, tax filings, and corporate financial statements were staged in C:\Users\j.smith\AppData\Local\Temp\enc_payload.dll.
The malware opened multi-threaded SSL/TLS outbound streams, pushing the siphoned data to external C2 server 185.123.45.6:443.
At 02:28 PM, the IBM QRadar SIEM console flared red. A CRITICAL SEV-1 Offense #48291 correlated multiple anomalies:
1. Palo Alto Firewall: Outbound HTTPS data spike (5.2 GB to uncategorized IP 185.123.45.6).
2. Active Directory: Abnormal Kerberos TGS ticket request burst under j.smith.
3. File Server FS01: High-volume file read operations on \\FS01\LoanShares.
4. Loan Application System (LOS): Bulk customer record export event.
๐ Dramatic Plot Twist 3: The Media Extortion Threat
TWIST: Simultaneously, the CTI team uncovers a post on a dark web leak site where the Ransomus group claims they have already exfiltrated 5,000 customer PII records and threatens to leak them to financial news media in 2 hours if contact is not made!
โ Hot-Seat Character Interrogation Questions (Chapter 3)
| Character Role | Hot-Seat Twist Question for the Player |
|---|---|
SOC Lead / L3 | "SIEM shows 5.2 GB of data exfiltrated in 3 minutes. How do you determine whether customer PII was included in the exfiltration bundle versus internal system logs?" |
Incident Communicator | "A tech journalist calls your press desk asking if Loan Corp is experiencing a ransomware data breach. How do you respond without violating executive communication SLAs?" |
CISOCISO | "Dark web extortion claims 5,000 customer records were stolen. At what point does regulatory data breach notification (e.g., GDPR / SEC / banking regulators) become mandatory?" |
๐ Chapter 4: The Encryption Catalyst & HelpDesk Midnight Call
CrowdStrike EDR Alert Console๐ The Narrative
At 02:32 PM, having completed data exfiltration, the attacker launched the ransomware payload.
Using multi-threaded AES-256 encryption, the malware began locking local files on LOAN-LAPTOP-042 and rapidly traversed network shares on \\FS01\LoanShares. Thousands of documents, spreadsheets, and database backups were renamed with a .lock extension.
Seconds later, CrowdStrike EDR triggered a CRITICAL SEV-1 ALERT: Ransomware Execution & Mass File Encryption Detected.
Alex's Dell laptop froze completely. The display transformed into a terrifying blood-red lock screen:
Dell Laptop Ransomware Lock ScreenRANSOM LOCK NOTICE: ALL YOUR FILES HAVE BEEN ENCRYPTED BY RANSOMUS! A unique encryption key has locked access. Submit 5.0 BTC (~$325,000 USD) to wallet 1F1tAaz5x1HUXrCNLvtMDqcw6955Hnt9Dk within 72 hours or the key will be permanently destroyed!
๐ Dramatic Plot Twist 4: The Corrupted Shadow Copies
TWIST: When system administrators attempt to trigger local Volume Shadow Copies (VSS) onFS01, they discover the ransomware executedvssadmin delete shadows /all /quietvia a compromised Domain Admin service account prior to encryption!
โ Hot-Seat Character Interrogation Questions (Chapter 4)
| Character Role | Hot-Seat Twist Question for the Player |
|---|---|
SOC Manager | "Local shadow copies on FS01 are wiped and the ransomware note demands 5 BTC. Do you immediately declare a Major SEV-1 Incident and invoke the Business Continuity Plan (BCP)?" |
ExecutiveExecutive Management | "A board member asks if the company should pay the 5 BTC ransom to regain immediate access before market opening. What is executive policy regarding ransom negotiations?" |
CIOCIO | "Core lending databases are locked. Who holds final authority to sign off on BCP disaster recovery invocation when core core systems are compromised?" |
๐๏ธ Chapter 5: The Incident Command WAR Room & Multi-Team Containment
Incident Command WAR Room๐ The Narrative
At 02:45 PM, the SOC Manager formally declared a SEV-1 Major Incident.
The Incident Communicator immediately launched the central Incident Command WAR Room, bringing together all 11 role stakeholders: SOC Analysts, Forensics, IT Infrastructure, Threat Intel, Asset Owners, CIO, CISO, and Executive Leadership.
4 parallel containment streams were initiated:
1. Network Containment: Block IP 185.123.45.6 at the perimeter firewall and isolate LOAN-LAPTOP-042.
2. Identity Lockdown: Disable AD account j.smith, reset Kerberos krbtgt tickets, and terminate active SMB sessions.
3. Application Guard: Place \\FS01\LoanShares into Read-Only Mode while forensic volatile memory capture was executed.
4. Executive Briefings: Issue 30-minute status updates to CISO, CIO, and legal counsel.
๐ Dramatic Plot Twist 5: The Secondary Persistence Backdoor
TWIST: During network containment, Network Ops notices HTTPS traffic to a SECOND unknown IP (198.51.100.42) originating from a totally different server (WEB-APP-02)! The attacker installed a web shell 3 days prior as a secondary fallback persistence mechanism!
โ Hot-Seat Character Interrogation Questions (Chapter 5)
| Character Role | Hot-Seat Twist Question for the Player |
|---|---|
Incident Communicator | "The CISO demands an instant update while Network Ops discovers a secondary web shell backdoor. Does the Incident Communicator have authority to execute containment actions? How do you manage stakeholder comms?" |
Network & System Team | "SOC L2 requests severing WEB-APP-02 from the internet. This will take the customer online portal offline. How quickly can your team execute this isolation?" |
Business / Asset Owner | "With WEB-APP-02 and FS01 offline, what manual paper fallback procedures does your business unit initiate to maintain loan processing?" |
๐งน Chapter 6: The Immutable Restoration & Executive Return-to-Production
Backup Restoration Portal๐ The Narrative
By Day 2 at 08:00 AM, eradication activities were fully underway.
The Network & System Team reimaging LOAN-LAPTOP-042 with an approved gold image, purged the web shell on WEB-APP-02, patched CVE-2026-1102 on AD-DC01, and verified EDR sensor health across all endpoints.
Engineers accessed the immutable offline backup vault and located an uncorrupted snapshot taken at 02:00 AM on Day 1 (prior to infection). Restoration reached 98% completion by 02:00 PM.
At 04:00 PM, the Business Asset Owner validated data integrity across restored shares. Finally, in a joint executive session, the CIO and CISO granted formal recovery authorization to return systems to production.
๐ Dramatic Plot Twist 6: The 2-Hour Backup Gap & Missing Deals
TWIST: Data validation reveals that loan contracts created between 07:00 AM and 09:00 AM on Day 1 were not captured in the 02:00 AM snapshot. 14 high-value loan agreements must be manually re-entered from paper receipts!
โ Hot-Seat Character Interrogation Questions (Chapter 6)
| Character Role | Hot-Seat Twist Question for the Player |
|---|---|
Business / Asset Owner | "14 loan contracts are missing from the restored snapshot. How do you validate manual re-entry accuracy before confirming operational recovery to the CIO/CISO?" |
CIOCIO | "Under governance SOPs, what mandatory sign-off criteria must be satisfied before you and the CISO authorize returning core systems to production?" |
CISOCISO | "Post-Incident Review (PIR) identifies 5 overdue remediation items. How does the CISO enforce accountability and tracking for overdue action items?" |
๐ Summary of Character RACI Powers & Story Arc
๐ Facilitator Epilogue & Key Takeaways
1. RACI Enforcement: Containment authority must strictly align with pre-approved matrix boundaries to eliminate operational bottlenecks.
2. Communication Velocity: Incident Communicators own stakeholder notification and WAR Room management, ensuring technical teams remain focused on containment.
3. Immutable Snapshots: Offline, air-gapped backups are the single critical line of defense against ransomware extortion.
4. Joint Executive Blessing: Production restoration requires formal sign-off from both business and security leadership (CIO & CISO).
๐ Run the Interactive Deck: Open index.html to present full-screen slides or launch the D&D campaign mode! ๐ Cyber & Dragons: The Ransomus Campaign
๐ฒ Tabletop Exercise (TTX) D&D Style Facilitator & Campaign Master Guide
index.html and click the "๐ฒ D&D Campaign Deck" button in the top navigation bar to run this exercise with real-time sound effects, D20 dice roller, animated spells, and boss HP tracking! ๐ Campaign Overview
Welcome, Dungeon Master (Facilitator)! This guide transforms standard cybersecurity Incident Response (IR) tabletop exercises into an immersive Dungeons & Dragons (D&D) style fantasy tabletop roleplaying campaign.
Players assume the roles of an elite Cyber Adventuring Party battling Ransomus the Encryptorโa dark threat spirit attempting to siphon customer archives and freeze corporate systems with ransomware crystals.
โ๏ธ The 11 Character Class Roles & RACI Spells
Each participant receives a Character Card with specific RACI abilities, stats, and containment spells:
| Hero Class / Role | Class Title | Primary Skill & Ability | RACI Containment Spell / Power |
|---|---|---|---|
| ๐ก๏ธ SOC L1 Sentinel | Shift Duty Paladin | Perception (DC 14): Continuous alert monitoring & FP vs TP triage. | Predefined Containment Aura: Execute low/med playbook actions; escalate to L2 <15 min. |
| ๐น SOC L2 Investigator | Forensic Ranger | Investigation (DC 15): Log analysis, timeline tracking, scope mapping. | High-Severity Binding: Recommend & execute high-sev host isolation per matrix. |
| ๐งโโ๏ธ Archmage SOC L3 | Senior Forensics Wizard | Arcana / Forensics (DC 16): Deep malware reverse-engineering & RCA. | Major Containment Counter-Spell: Share full operational authority during SEV1. |
| ๐บ War Room Bard | Incident Communicator | Performance / Comms (DC 13): Own WAR Room & executive SLA alerts. | SLA Horn of Emergency: Sound executive alerts <15 min (NO containment authority). |
| ๐ Grand Commander | SOC Manager | Leadership (DC 16): Operational authority, Major Incident declaration. | Domain Shield of Governance: Declare Major Incident, engage BCP/DR, approve containment. |
| ๐ฐ Guild Asset Overseer | Business / Asset Owner | Insight (DC 14): Business impact assessment & application context. | Production Access Seal: Approve production system containment; validate recovery. |
| โ๏ธ Dwarven Technomancer | Network & System Team | Athletics / Engineering (DC 15): Firewall blocks, AD locks, reimaging. | Wall of Stone & Firewall: Execute network isolation, IP bans, & AD account locks. |
| ๐ฎ Shadow Oracle | CTI Threat Intel | Scrying (DC 14): Threat actor attribution & C2 campaign correlation. | Scrying Orb of Intelligence: Enrich IOCs & track adversary infrastructure. |
| ๐ Lord Chancellor CIO | Core Systems Authority | History / Authority (DC 17): Core infrastructure governance & BCP sign-off. | Decree of System Restoration: Grant mandatory final recovery sign-off for SEV1/SEV2. |
| โ๏ธ Grand Inquisitor CISO | Cyber Governance Paladin | Religion / Compliance (DC 17): Regulatory oversight & risk alignment. | Aegis of Regulatory Compliance: Strategic cyber oversight & mandatory recovery sign-off. |
| ๐๏ธ High Council | Executive Management | Diplomacy / Risk (DC 18): Executive risk governance & public disclosure. | Council Sanction: Approve strategic business & regulatory decisions. |
๐ฒ Core Game Mechanics for the Dungeon Master (DM)
1. Boss Health Pool: Ransomus starts with 10,000 HP. Each successful encounter roll depletes Boss HP.
2. Initiative Order: Turn proceeds sequentially through Encounters I to VI.
3. Skill Checks & D20 Rolls:
index.html).4. DM Storytelling Rule: Read the Dungeon Master Script aloud for each encounter before prompting players to respond with their role handbooks!
๐ฌ The 6 Quest Encounters (Start-to-Finish Script)
๐ Encounter I: The Mimic's Scroll (Phishing Vector)
assets/telegram_phishing.jpg & assets/fake_pdf_error.jpg๐ฃ๏ธ Dungeon Master Script (Read Aloud):
"Hark, brave adventurers! A remote loan officer working outside the castle walls receives a sealed parchment namedCustomer_Documents_2026.zipover the Telegram messaging network. Believing it to be a legitimate loan applicant, the officer opensSigned_Agreement.pdfโa dark executable in disguise! A cursed Adobe error (0x80070005) flashes across his screen. The officer ignores the warning and continues working. Behind the error, a silent Trojan spirit awakens and beacons back to the dark domain!"
๐ฏ Party Objective & Challenge:
explorer.exe launching a Trojan DLL). What are your mandatory SOP steps, and what is your SLA escalation deadline?"LOAN-LAPTOP-042, j.smith), open ITSM ticket, and escalate to SOC L2 Investigator within 15 minutes (or directly to Grand Commander SOC Manager if L2 is absent).๐ Encounter II: Infiltration of Loan-Keep LAN (Lateral Recon)
assets/cyber_war_room_map.jpg๐ฃ๏ธ Dungeon Master Script (Read Aloud):
"The loan officer returns to HQ and plugsLOAN-LAPTOP-042directly into the corporate LAN! Like shadow tendrils, the malware spirit crawls across the internal realm. It enumerates Active Directory domain controllers (AD-DC01), abuses existing Kerberos tokens under accountj.smith, and discovers the ancient vault of customer file shares (\\FS01\LoanShares)!"
๐ฏ Party Objective & Challenge:
๐ค Encounter III: The Mass Exfiltration Ritual (5GB Data Drain)
assets/siem_dashboard.jpg๐ฃ๏ธ Dungeon Master Script (Read Aloud):
"Dark magic surges! An dark portal opens to external realm 185.123.45.6:443. Ransomus begins siphoning 5GB of sensitive customer loan archives over encrypted channels! The IBM QRadar SIEM crystal glows bright red, triggering dual alarms: Outbound Data Exfiltration Spike + Abnormal SMB Read Burst!"
๐ฏ Party Objective & Challenge:
185.123.45.6). Dwarven Technomancer prepares firewall perimeter blocks and account session terminations.๐ Encounter IV: Curse of Encryptus (Ransomlock)
assets/edr_ransomware_alert.jpg & assets/ransomware_note.jpg๐ฃ๏ธ Dungeon Master Script (Read Aloud):
"Ransomus strikes with full fury! Dark encryption crystals freeze workstation files and shared vaults (\\FS01\LoanShares) with.lockextensions! Alex's Dell laptop freezes, displaying a blood-red ransom note: '5 BITCOIN DEMANDED WITHIN 72 HOURS OR ALL KEYS DESTROYED!' CrowdStrike EDR roars with a CRITICAL SEV-1 ALERT!"
๐ฏ Party Objective & Challenge:
๐ก๏ธ Encounter V: War Room Summit & Elemental Barrier (Containment)
assets/war_room_dashboard.jpg๐ฃ๏ธ Dungeon Master Script (Read Aloud):
"The alarm bells ring! War Room Bard blows the SLA Horn of Emergency, gathering all 11 heroes into the Incident Command WAR Room! Executive notifications shoot across the realm to Lord Chancellor CIO and Grand Inquisitor CISO within 15 minutes. Dwarven Technomancers slam the firewall gates shut!"
๐ฏ Party Objective & Challenge:
\\FS01\LoanShares to Read-Only mode to preserve business data. Dwarven Technomancer blocks C2 IP 185.123.45.6 and locks AD account j.smith.โจ Encounter VI: Divine Purge & Clean Restoration (Eradication & Recovery)
assets/backup_recovery_portal.jpg๐ฃ๏ธ Dungeon Master Script (Read Aloud):
"VICTORY IS WITHIN REACH! The infected laptop is cleansed and reimaged with gold armor. Technomancers cast Holy Restoration, pulling a 98% clean immutable snapshot from the backup vaults! Guild Asset Overseer inspects the restored archives and confirms operational integrity. Lord Chancellor CIO and Grand Inquisitor CISO raise their staves to grant final blessing!"
๐ฏ Party Objective & Challenge:
๐ Evaluation Rubric & Victory Rewards (Loot)
| Benchmark Metric | SLA Target | D&D Achievement Unlocked |
|---|---|---|
| L1 Alert Escalation | < 15 Minutes | ๐ Shield of Swift Perception (Prevented early lateral spread) |
| Host & Network Containment | < 30 Minutes | โ๏ธ Blade of Containment (Severed C2 portal 185.123.45.6) |
| Executive WAR Room Alert | < 15 Minutes | ๐บ Horn of Executive Alignment (Notified CIO & CISO within SLA) |
| Immutable Backup Restore | < 4 Hours | ๐ฎ Orb of Clean Recovery (Restored 98% clean snapshot) |
| Joint Recovery Sign-Off | < 24 Hours | ๐ Crown of Governance Sign-Off (Approved return to production) |
๐ Post-Campaign Debriefing Checklist (PIR)
index.html .๐ Executive Briefing Presentation Deck (.pptx)
build_presentation.py. Ready for boardrooms, projectors, and offline team briefings.๐ Slide Deck Table of Contents
- Slide 1: Executive Title & TTX Scenario Briefing (ADMFI Microfinance)
- Slide 2: Operational Reality & Off-Site Risk Context
- Slide 3: 11-Role RACI Authority & Containment Matrix
- Slide 4: End-to-End Threat Kill-Chain & Architecture
- Slide 5: Inject 1 โ Telegram Social Engineering & Fake PDF Error
- Slide 6: Inject 2 โ Corporate LAN Reconnection & Kerberos Recon
- Slide 7: Inject 3 โ 5.2GB Customer Data Exfiltration & SIEM Correlation
- Slide 8: Inject 4 โ Ransomware Detonation ($50,000 Extortion Demand)
- Slide 9: Plot Twists (Telegram BEC Hijack, VSS Wiper, Dark Web Leak)
- Slide 10: Inject 5 โ Major Incident WAR Room & 4-Pillar Containment
- Slide 11: Inject 6 โ Forensic Eradication & Immutable Snapshot Recovery
- Slide 12: Post-Incident Review (PIR), KPI Rubric & Continuous Improvement
๐ฅ 11 Incident Response Roles & RACI Matrix
Clear role delineation ensures rapid incident triage, prevents unauthorized operational disruption, and enforces formal containment authorities across SOC, IT Infrastructure, Business, and Executive leadership.
๐ก๏ธ Incident Response Team & Authority Hierarchy
Technical responders (L1/L2) investigate and execute low/medium containment. High-severity and production containment requires SOC Manager and Business Owner approval. System return-to-production requires mandatory CIO & CISO sign-off.
๐ After-Action Review (AAR) & SLA Evaluation Suite
Evaluate exercise performance across key SLA milestones, track containment efficiency, review decision branch history, and export official debrief reports in 1 click.
โ๏ธ Scenario Customizer & Audio/Visual Preferences
Customize scenario parameters (Target Organization, C2 IP, Ransom Amount, Domain), test audio/visual alarms, and manage simulation states.
Reset all SLA scores, decision branch outcomes, countdown timers, and combat logs to start a fresh exercise drill.



