# 🐉 Cyber & Dragons: The Ransomus Campaign
## 🎲 Tabletop Exercise (TTX) D&D Style Facilitator & Campaign Master Guide

> [!TIP]
> 🚀 **Interactive D&D Game Portal**: Launch [`index.html`](../index.html) and click the **"🎲 D&D Campaign Deck"** button in the top navigation bar to run this exercise with real-time sound effects, D20 dice roller, animated spells, and boss HP tracking!

---

## 📌 Campaign Overview

Welcome, Dungeon Master (Facilitator)! This guide transforms standard cybersecurity Incident Response (IR) tabletop exercises into an immersive **Dungeons & Dragons (D&D) style fantasy tabletop roleplaying campaign**. 

Players assume the roles of an elite **Cyber Adventuring Party** battling **Ransomus the Encryptor**—a dark threat spirit attempting to siphon customer archives and freeze corporate systems with ransomware crystals.

- **Target Audience**: SOC L1, L2, L3, Incident Communicator, SOC Manager, Business/Asset Owner, Network/System Team, CTI Team, CIO, CISO, and Executive Leadership.
- **Duration**: 2 to 3 Hours.
- **System Mechanics**: D20 System (Natural 20 = Critical Hit, 10–19 = Success, 1–9 = Failure/Corruption), Boss HP Bar (10,000 HP), Skill Checks, RACI Spells, and Initiative Order.
- **Goal**: Gamify SOP adherence, test RACI containment authority enforcement, enforce SLA response velocity, and build team alignment.

---

## ⚔️ The 11 Character Class Roles & RACI Spells

Each participant receives a Character Card with specific RACI abilities, stats, and containment spells:

| Hero Class / Role | Class Title | Primary Skill & Ability | RACI Containment Spell / Power |
| :--- | :--- | :--- | :--- |
| 🛡️ **SOC L1 Sentinel** | Shift Duty Paladin | **Perception (DC 14)**: Continuous alert monitoring & FP vs TP triage. | *Predefined Containment Aura*: Execute low/med playbook actions; escalate to L2 <15 min. |
| 🏹 **SOC L2 Investigator** | Forensic Ranger | **Investigation (DC 15)**: Log analysis, timeline tracking, scope mapping. | *High-Severity Binding*: Recommend & execute high-sev host isolation per matrix. |
| 🧙‍♂️ **Archmage SOC L3** | Senior Forensics Wizard | **Arcana / Forensics (DC 16)**: Deep malware reverse-engineering & RCA. | *Major Containment Counter-Spell*: Share full operational authority during SEV1. |
| 🎺 **War Room Bard** | Incident Communicator | **Performance / Comms (DC 13)**: Own WAR Room & executive SLA alerts. | *SLA Horn of Emergency*: Sound executive alerts <15 min (*NO containment authority*). |
| 👑 **Grand Commander** | SOC Manager | **Leadership (DC 16)**: Operational authority, Major Incident declaration. | *Domain Shield of Governance*: Declare Major Incident, engage BCP/DR, approve containment. |
| 🏰 **Guild Asset Overseer** | Business / Asset Owner | **Insight (DC 14)**: Business impact assessment & application context. | *Production Access Seal*: Approve production system containment; validate recovery. |
| ⚒️ **Dwarven Technomancer** | Network & System Team | **Athletics / Engineering (DC 15)**: Firewall blocks, AD locks, reimaging. | *Wall of Stone & Firewall*: Execute network isolation, IP bans, & AD account locks. |
| 🔮 **Shadow Oracle** | CTI Threat Intel | **Scrying (DC 14)**: Threat actor attribution & C2 campaign correlation. | *Scrying Orb of Intelligence*: Enrich IOCs & track adversary infrastructure. |
| 📜 **Lord Chancellor CIO** | Core Systems Authority | **History / Authority (DC 17)**: Core infrastructure governance & BCP sign-off. | *Decree of System Restoration*: Grant mandatory final recovery sign-off for SEV1/SEV2. |
| ⚜️ **Grand Inquisitor CISO** | Cyber Governance Paladin | **Religion / Compliance (DC 17)**: Regulatory oversight & risk alignment. | *Aegis of Regulatory Compliance*: Strategic cyber oversight & mandatory recovery sign-off. |
| 🏛️ **High Council** | Executive Management | **Diplomacy / Risk (DC 18)**: Executive risk governance & public disclosure. | *Council Sanction*: Approve strategic business & regulatory decisions. |

---

## 🎲 Core Game Mechanics for the Dungeon Master (DM)

1. **Boss Health Pool**: Ransomus starts with **10,000 HP**. Each successful encounter roll depletes Boss HP.
2. **Initiative Order**: Turn proceeds sequentially through Encounters I to VI.
3. **Skill Checks & D20 Rolls**:
   - Player rolls a **D20 die** (or clicks the interactive D20 die in `index.html`).
   - **Natural 20 (Critical Hit)**: 1.5× Damage (e.g., 2,250 HP damage), epic success, instantly unlocks bonus threat intel.
   - **10 to 19 (Success)**: Normal Damage (1,000–2,000 HP), successful RACI defense, SLA met.
   - **1 to 9 (Failure)**: 0 Damage to Boss. Ransomus retaliates with a **Corruption Spike** (penalty warning or SLA breach).
4. **DM Storytelling Rule**: Read the **Dungeon Master Script** aloud for each encounter before prompting players to respond with their role handbooks!

---

## 🎬 The 6 Quest Encounters (Start-to-Finish Script)

---

### 📜 Encounter I: The Mimic's Scroll (Phishing Vector)
- **Phase**: Detection & Shift Triage
- **Simulated Time**: 09:15 AM (Day 1 - Offsite)
- **Active Hero**: **SOC L1 Sentinel**
- **Boss Damage**: 1,500 HP
- **Visual Asset**: `assets/telegram_phishing.jpg` & `assets/fake_pdf_error.jpg`

#### 🗣️ Dungeon Master Script (Read Aloud):
> *"Hark, brave adventurers! A remote loan officer working outside the castle walls receives a sealed parchment named `Customer_Documents_2026.zip` over the Telegram messaging network. Believing it to be a legitimate loan applicant, the officer opens `Signed_Agreement.pdf`—a dark executable in disguise! A cursed Adobe error (`0x80070005`) flashes across his screen. The officer ignores the warning and continues working. Behind the error, a silent Trojan spirit awakens and beacons back to the dark domain!"*

#### 🎯 Party Objective & Challenge:
- **SOC L1 Sentinel** must cast **Perception Check (DC 14)**.
- **DM Question to Player**: *"SOC L1 Sentinel! The EDR scroll flags an unusual process tree (`explorer.exe` launching a Trojan DLL). What are your mandatory SOP steps, and what is your SLA escalation deadline?"*
- **Required Player Answer**: Validate True Positive, enrich asset/user context (`LOAN-LAPTOP-042`, `j.smith`), open ITSM ticket, and escalate to **SOC L2 Investigator** within **15 minutes** (or directly to **Grand Commander SOC Manager** if L2 is absent).

---

### 🌐 Encounter II: Infiltration of Loan-Keep LAN (Lateral Recon)
- **Phase**: Investigation & Scope Mapping
- **Simulated Time**: 02:00 PM (Day 1 - Corporate HQ)
- **Active Hero**: **SOC L2 Investigator** & **Shadow Oracle (CTI)**
- **Boss Damage**: 1,800 HP
- **Visual Asset**: `assets/cyber_war_room_map.jpg`

#### 🗣️ Dungeon Master Script (Read Aloud):
> *"The loan officer returns to HQ and plugs `LOAN-LAPTOP-042` directly into the corporate LAN! Like shadow tendrils, the malware spirit crawls across the internal realm. It enumerates Active Directory domain controllers (`AD-DC01`), abuses existing Kerberos tokens under account `j.smith`, and discovers the ancient vault of customer file shares (`\\FS01\LoanShares`)!"*

#### 🎯 Party Objective & Challenge:
- **SOC L2 Investigator** & **Shadow Oracle** must cast **Investigation & Scrying Check (DC 15)**.
- **DM Question to Player**: *"SOC L2 Investigator! The dark spirit is probing Kerberos tickets and scoping file shares. How do you confirm the severity level, and what intelligence does Shadow Oracle gather?"*
- **Required Player Answer**: SOC L2 leads forensic log investigation, correlates host/user scope, confirms high severity, and drafts technical alert. CTI Shadow Oracle enriches C2 IP indicators and campaign attribution.

---

### 📤 Encounter III: The Mass Exfiltration Ritual (5GB Data Drain)
- **Phase**: Threat Intelligence & SIEM Correlation
- **Simulated Time**: 02:25 PM (Day 1)
- **Active Hero**: **Shadow Oracle (CTI)** & **Dwarven Technomancer**
- **Boss Damage**: 2,000 HP
- **Visual Asset**: `assets/siem_dashboard.jpg`

#### 🗣️ Dungeon Master Script (Read Aloud):
> *"Dark magic surges! An dark portal opens to external realm `185.123.45.6:443`. Ransomus begins siphoning 5GB of sensitive customer loan archives over encrypted channels! The IBM QRadar SIEM crystal glows bright red, triggering dual alarms: Outbound Data Exfiltration Spike + Abnormal SMB Read Burst!"*

#### 🎯 Party Objective & Challenge:
- **Shadow Oracle** & **Dwarven Technomancer** must cast **Arcana & Engineering Check (DC 16)**.
- **DM Question to Player**: *"Dwarven Technomancer & Shadow Oracle! 5GB of customer archives are draining into the abyss! What immediate technical containment spell do you prepare?"*
- **Required Player Answer**: Shadow Oracle confirms C2 malicious reputation (`185.123.45.6`). Dwarven Technomancer prepares firewall perimeter blocks and account session terminations.

---

### 🔒 Encounter IV: Curse of Encryptus (Ransomlock)
- **Phase**: Active Crisis & Major Incident Declaration
- **Simulated Time**: 02:32 PM (Day 1)
- **Active Heroes**: **Archmage SOC L3** & **Grand Commander (SOC Mgr)**
- **Boss Damage**: 2,200 HP
- **Visual Asset**: `assets/edr_ransomware_alert.jpg` & `assets/ransomware_note.jpg`

#### 🗣️ Dungeon Master Script (Read Aloud):
> *"Ransomus strikes with full fury! Dark encryption crystals freeze workstation files and shared vaults (`\\FS01\LoanShares`) with `.lock` extensions! Alex's Dell laptop freezes, displaying a blood-red ransom note: '5 BITCOIN DEMANDED WITHIN 72 HOURS OR ALL KEYS DESTROYED!' CrowdStrike EDR roars with a CRITICAL SEV-1 ALERT!"*

#### 🎯 Party Objective & Challenge:
- **Grand Commander** & **Archmage L3** must cast **Saving Throw against Total Encryption (DC 17)**.
- **DM Question to Player**: *"Grand Commander! The core file share is freezing and a 5 BTC ransom demand is posted! Do you declare a Major Incident, and who has containment authority?"*
- **Required Player Answer**: Grand Commander declares SEV-1 Major Incident, activates BCP/DR protocol, and approves major containment. Archmage L3 performs deep forensic analysis.

---

### 🛡️ Encounter V: War Room Summit & Elemental Barrier (Containment)
- **Phase**: Incident Command & WAR Room Operations
- **Simulated Time**: 02:45 PM (Day 1)
- **Active Heroes**: **War Room Bard**, **Dwarven Technomancer**, **Guild Asset Overseer**
- **Boss Damage**: 1,500 HP
- **Visual Asset**: `assets/war_room_dashboard.jpg`

#### 🗣️ Dungeon Master Script (Read Aloud):
> *"The alarm bells ring! War Room Bard blows the SLA Horn of Emergency, gathering all 11 heroes into the Incident Command WAR Room! Executive notifications shoot across the realm to Lord Chancellor CIO and Grand Inquisitor CISO within 15 minutes. Dwarven Technomancers slam the firewall gates shut!"*

#### 🎯 Party Objective & Challenge:
- **War Room Bard**, **Dwarven Technomancer**, & **Guild Asset Overseer** must cast **Containment Barrier (DC 15)**.
- **DM Question to Player**: *"War Room Bard & Guild Asset Overseer! Does the Bard have containment execution authority? And what application isolation does Guild Asset Overseer approve?"*
- **Required Player Answer**: War Room Bard owns comms and WAR Room management but has **NO containment authority**. Guild Asset Overseer approves setting `\\FS01\LoanShares` to Read-Only mode to preserve business data. Dwarven Technomancer blocks C2 IP `185.123.45.6` and locks AD account `j.smith`.

---

### ✨ Encounter VI: Divine Purge & Clean Restoration (Eradication & Recovery)
- **Phase**: Eradication, Backup Recovery & Business Sign-Off
- **Simulated Time**: Days 2–3
- **Active Heroes**: **Lord Chancellor CIO**, **Grand Inquisitor CISO**, **Guild Asset Overseer**
- **Boss Damage**: 1,000 HP (FINISHING BLOW!)
- **Visual Asset**: `assets/backup_recovery_portal.jpg`

#### 🗣️ Dungeon Master Script (Read Aloud):
> *"VICTORY IS WITHIN REACH! The infected laptop is cleansed and reimaged with gold armor. Technomancers cast Holy Restoration, pulling a 98% clean immutable snapshot from the backup vaults! Guild Asset Overseer inspects the restored archives and confirms operational integrity. Lord Chancellor CIO and Grand Inquisitor CISO raise their staves to grant final blessing!"*

#### 🎯 Party Objective & Challenge:
- **Lord Chancellor CIO** & **Grand Inquisitor CISO** cast **Divine Recovery Blessing (DC 17)**.
- **DM Question to Player**: *"CIO & CISO! What mandatory sign-off is required before systems return to production, and who tracks post-incident action items?"*
- **Required Player Answer**: Joint formal recovery approval from both CIO and CISO is mandatory for SEV1 return-to-production. Grand Commander (SOC Mgr) tracks overdue PIR action items with 30/60/90 day SLA enforcement.

---

## 📊 Evaluation Rubric & Victory Rewards (Loot)

| Benchmark Metric | SLA Target | D&D Achievement Unlocked |
| :--- | :--- | :--- |
| **L1 Alert Escalation** | < 15 Minutes | 🏆 *Shield of Swift Perception* (Prevented early lateral spread) |
| **Host & Network Containment** | < 30 Minutes | ⚔️ *Blade of Containment* (Severed C2 portal 185.123.45.6) |
| **Executive WAR Room Alert** | < 15 Minutes | 🎺 *Horn of Executive Alignment* (Notified CIO & CISO within SLA) |
| **Immutable Backup Restore** | < 4 Hours | 🔮 *Orb of Clean Recovery* (Restored 98% clean snapshot) |
| **Joint Recovery Sign-Off** | < 24 Hours | 👑 *Crown of Governance Sign-Off* (Approved return to production) |

---

## 📑 Post-Campaign Debriefing Checklist (PIR)

- [ ] **Review D20 Roll Logs**: Evaluate where skill checks succeeded or failed.
- [ ] **RACI Alignment Check**: Confirm no role exceeded or defaulted on their containment authority.
- [ ] **Action Item Assignment**: Assign 30/60/90 day SLA deadlines for PIR security enhancements.
- [ ] **Campaign Archive**: Save results and launch the interactive portal via [`index.html`](../index.html).
