# 📖 The Ransomus Protocol: An Interactive Cyber Crisis Storybook

> *A Narrative Tabletop Exercise Book with Dramatic Plot Twists, Character Interrogations, and Visual Incident Mockups.*

---

![Incident Response Command Team](../assets/IR%20Team_Group.png)

## 📘 Prologue: The Anatomy of a Modern Cyber Attack

It was a rainy Tuesday morning at Loan Corp Headquarters. Loan officers operated on the frontlines of commercial lending, constantly closing high-value mortgage deals and business credit lines. To stay nimble in a hyper-competitive market, loan officers frequently met VIP clients off-site at coffee shops, hotel lobbies, and remote branches. 

To expedite documentation exchanges, loan officers relied heavily on corporate Telegram desktop channels—a convenient, unsanctioned shadow IT channel for sending signed PDF applications, tax records, and identity archives.

Unbeknownst to the team, a sophisticated nation-state threat group known as **Ransomus** was monitoring these informal channels, waiting for the perfect moment to slip through the castle gates...

---

## 📸 Chapter 1: The Telegram Phishing Payload & Disguised Execution

![Telegram Phishing Vector](../assets/telegram_phishing.jpg)

### 📖 The Narrative
At 09:15 AM, Alex, a senior commercial loan officer, was working remotely from a downtown coffee shop. A notification popped up on his Telegram app from a verified customer contact profile named *"VIP Client - Horizon Real Estate"*. 

Attached was a compressed archive titled `Customer_Documents_2026.zip` (size: 42 MB). The message read:
> *"Alex, attached are our signed commercial loan agreements and bank statements for the $12M property acquisition. Please review urgently before noon!"*

Eager to close the deal, Alex extracted the archive. Inside was a file with a familiar Adobe PDF icon named `Signed_Agreement.pdf.exe`. Double-clicking it triggered a brief spinner, followed by a Windows system error dialog:

![Fake Adobe PDF Error](../assets/fake_pdf_error.jpg)

> **System Error**: `Adobe Acrobat Reader DC - Unable to render document format (0x80070005). File may be corrupted.`

Alex assumed the client sent a broken file, closed the error box, sent a quick Telegram message asking for a resend, and moved on to other emails. 

**Behind the screen, the trap was sprung.** The disguised executable silently injected a malicious DLL into `svchost.exe`, established user-level registry persistence, and initiated encrypted HTTPS beacons to `185.123.45.6:443`.

---

### 🌀 Dramatic Plot Twist 1: The Insider Credentials Leak
> **TWIST**: *The Telegram profile that sent the file belonged to an actual high-value client whose personal Telegram account had been hijacked 24 hours earlier! Furthermore, EDR telemetry reveals that the Trojan payload harvested Alex's saved Active Directory credentials and Chrome browser tokens during the error popup!*

---

### ❓ Hot-Seat Character Interrogation Questions (Chapter 1)

| Character Role | Hot-Seat Twist Question for the Player |
| :--- | :--- |
| ![SOC L1](../assets/SOC%20L1%20Avatar.png)<br/>**SOC L1 Analyst** | *"An EDR alert fires for `LOAN-LAPTOP-042` showing an unrecognized process spawn (`explorer.exe` -> `Signed_Agreement.exe` -> `svchost.exe`). The user reports it as a harmless Adobe glitch. Do you dismiss it as a False Positive or escalate? What is your 15-minute SLA protocol?"* |
| ![SOC L2](../assets/SOC%20L2%20Avatar.png)<br/>**SOC L2 Analyst** | *"The malware did not request admin privileges and ran under standard user permissions (`j.smith`). How do you validate whether this is a commodity Trojan or an targeted APT payload?"* |
| ![CTI Team](../assets/SOC%20CTI%20Avatar.png)<br/>**CTI Team Analyst** | *"Threat intel links IP `185.123.45.6` to a known ransomware syndicate. What campaign indicators do you immediately feed to L1/L2?"* |

---

## 🗺️ Chapter 2: The Corporate LAN Reconnection & Silent Reconnaissance

![Global Cyber Threat Map](../assets/cyber_war_room_map.jpg)

### 📖 The Narrative
By 02:00 PM, Alex finished his off-site meetings and returned to corporate headquarters. He sat down at his desk and plugged `LOAN-LAPTOP-042` directly into an Ethernet jack connected to the corporate LAN.

The moment the laptop obtained an internal IP (`10.15.34.120`), the dormant malware spirit detected the corporate domain controller (`AD-DC01`). 

Exploiting Alex's existing Kerberos session tokens, the Trojan launched automated network reconnaissance. It mapped accessible network shares, discovered `\\FS01\LoanShares`, and performed Kerberoasting queries to harvest service account ticket hashes.

---

### 🌀 Dramatic Plot Twist 2: The Unpatched Domain Controller
> **TWIST**: *The attacker utilizes the compromised `j.smith` account to query Active Directory for Domain Admin service accounts. The SOC discovers that `AD-DC01` is missing a critical patch for a known privilege escalation vulnerability (CVE-2026-1102), allowing a standard user account to request elevated Kerberos TGS tickets!*

---

### ❓ Hot-Seat Character Interrogation Questions (Chapter 2)

| Character Role | Hot-Seat Twist Question for the Player |
| :--- | :--- |
| ![Network System](../assets/IR_Team_Group.png)<br/>**Network & System Team** | *"Active Directory reports 50+ Kerberos TGS requests per second originating from `LOAN-LAPTOP-042`. Do you instantly isolate the network switch port or wait for SOC Manager approval?"* |
| ![Business Owner](../assets/Business%20App%20Owner%20Avatar.png)<br/>**Business / Asset Owner** | *"The network team proposes isolating `\\FS01\LoanShares`. This will halt 200 loan officers nationwide from closing deals today. Do you authorize this operational freeze?"* |
| ![SOC Manager](../assets/SOC%20Mgr%20Avatar.png)<br/>**SOC Manager** | *"L2 requests host isolation for `LOAN-LAPTOP-042` and account lockout for `j.smith`. Who holds mandatory operational authority to approve this action under the RACI matrix?"* |

---

## 📊 Chapter 3: The 5GB Exfiltration Shadow & SIEM Alarm

![IBM QRadar SIEM Dashboard](../assets/siem_dashboard.jpg)

### 📖 The Narrative
At 02:25 PM, the attacker activated the exfiltration module. Compressed archives containing 5.2 GB of confidential customer loan applications, tax filings, and corporate financial statements were staged in `C:\Users\j.smith\AppData\Local\Temp\enc_payload.dll`.

The malware opened multi-threaded SSL/TLS outbound streams, pushing the siphoned data to external C2 server `185.123.45.6:443`. 

At 02:28 PM, the **IBM QRadar SIEM** console flared red. A **CRITICAL SEV-1 Offense #48291** correlated multiple anomalies:
1. **Palo Alto Firewall**: Outbound HTTPS data spike (5.2 GB to uncategorized IP `185.123.45.6`).
2. **Active Directory**: Abnormal Kerberos TGS ticket request burst under `j.smith`.
3. **File Server FS01**: High-volume file read operations on `\\FS01\LoanShares`.
4. **Loan Application System (LOS)**: Bulk customer record export event.

---

### 🌀 Dramatic Plot Twist 3: The Media Extortion Threat
> **TWIST**: *Simultaneously, the CTI team uncovers a post on a dark web leak site where the Ransomus group claims they have already exfiltrated 5,000 customer PII records and threatens to leak them to financial news media in 2 hours if contact is not made!*

---

### ❓ Hot-Seat Character Interrogation Questions (Chapter 3)

| Character Role | Hot-Seat Twist Question for the Player |
| :--- | :--- |
| ![SOC Lead](../assets/SOC%20L3%20Avatar.png)<br/>**SOC Lead / L3** | *"SIEM shows 5.2 GB of data exfiltrated in 3 minutes. How do you determine whether customer PII was included in the exfiltration bundle versus internal system logs?"* |
| ![IR Communicator](../assets/SOC%20IR%20Communicator%20Avatar.png)<br/>**Incident Communicator** | *"A tech journalist calls your press desk asking if Loan Corp is experiencing a ransomware data breach. How do you respond without violating executive communication SLAs?"* |
| ![CISO](../assets/CISO%20-%20Mgt.png)<br/>**CISO** | *"Dark web extortion claims 5,000 customer records were stolen. At what point does regulatory data breach notification (e.g., GDPR / SEC / banking regulators) become mandatory?"* |

---

## 🔒 Chapter 4: The Encryption Catalyst & HelpDesk Midnight Call

![CrowdStrike EDR Alert Console](../assets/edr_ransomware_alert.jpg)

### 📖 The Narrative
At 02:32 PM, having completed data exfiltration, the attacker launched the ransomware payload. 

Using multi-threaded AES-256 encryption, the malware began locking local files on `LOAN-LAPTOP-042` and rapidly traversed network shares on `\\FS01\LoanShares`. Thousands of documents, spreadsheets, and database backups were renamed with a `.lock` extension.

Seconds later, CrowdStrike EDR triggered a **CRITICAL SEV-1 ALERT: Ransomware Execution & Mass File Encryption Detected**.

Alex's Dell laptop froze completely. The display transformed into a terrifying blood-red lock screen:

![Dell Laptop Ransomware Lock Screen](../assets/ransomware_note.jpg)

> **RANSOM LOCK NOTICE**: `ALL YOUR FILES HAVE BEEN ENCRYPTED BY RANSOMUS! A unique encryption key has locked access. Submit 5.0 BTC (~$325,000 USD) to wallet 1F1tAaz5x1HUXrCNLvtMDqcw6955Hnt9Dk within 72 hours or the key will be permanently destroyed!`

---

### 🌀 Dramatic Plot Twist 4: The Corrupted Shadow Copies
> **TWIST**: *When system administrators attempt to trigger local Volume Shadow Copies (VSS) on `FS01`, they discover the ransomware executed `vssadmin delete shadows /all /quiet` via a compromised Domain Admin service account prior to encryption!*

---

### ❓ Hot-Seat Character Interrogation Questions (Chapter 4)

| Character Role | Hot-Seat Twist Question for the Player |
| :--- | :--- |
| ![SOC Manager](../assets/SOC%20Mgr%20Avatar.png)<br/>**SOC Manager** | *"Local shadow copies on `FS01` are wiped and the ransomware note demands 5 BTC. Do you immediately declare a Major SEV-1 Incident and invoke the Business Continuity Plan (BCP)?"* |
| ![Executive](../assets/Executive%20-%20Mgr%20Leadership.png)<br/>**Executive Management** | *"A board member asks if the company should pay the 5 BTC ransom to regain immediate access before market opening. What is executive policy regarding ransom negotiations?"* |
| ![CIO](../assets/CIO%20-%20Mgt.png)<br/>**CIO** | *"Core lending databases are locked. Who holds final authority to sign off on BCP disaster recovery invocation when core core systems are compromised?"* |

---

## 🏛️ Chapter 5: The Incident Command WAR Room & Multi-Team Containment

![Incident Command WAR Room](../assets/war_room_dashboard.jpg)

### 📖 The Narrative
At 02:45 PM, the SOC Manager formally declared a **SEV-1 Major Incident**. 

The Incident Communicator immediately launched the central **Incident Command WAR Room**, bringing together all 11 role stakeholders: SOC Analysts, Forensics, IT Infrastructure, Threat Intel, Asset Owners, CIO, CISO, and Executive Leadership.

4 parallel containment streams were initiated:
1. **Network Containment**: Block IP `185.123.45.6` at the perimeter firewall and isolate `LOAN-LAPTOP-042`.
2. **Identity Lockdown**: Disable AD account `j.smith`, reset Kerberos krbtgt tickets, and terminate active SMB sessions.
3. **Application Guard**: Place `\\FS01\LoanShares` into **Read-Only Mode** while forensic volatile memory capture was executed.
4. **Executive Briefings**: Issue 30-minute status updates to CISO, CIO, and legal counsel.

---

### 🌀 Dramatic Plot Twist 5: The Secondary Persistence Backdoor
> **TWIST**: *During network containment, Network Ops notices HTTPS traffic to a SECOND unknown IP (`198.51.100.42`) originating from a totally different server (`WEB-APP-02`)! The attacker installed a web shell 3 days prior as a secondary fallback persistence mechanism!*

---

### ❓ Hot-Seat Character Interrogation Questions (Chapter 5)

| Character Role | Hot-Seat Twist Question for the Player |
| :--- | :--- |
| ![IR Communicator](../assets/SOC%20IR%20Communicator%20Avatar.png)<br/>**Incident Communicator** | *"The CISO demands an instant update while Network Ops discovers a secondary web shell backdoor. Does the Incident Communicator have authority to execute containment actions? How do you manage stakeholder comms?"* |
| ![Network System](../assets/SOC%20L2%20Avatar.png)<br/>**Network & System Team** | *"SOC L2 requests severing `WEB-APP-02` from the internet. This will take the customer online portal offline. How quickly can your team execute this isolation?"* |
| ![Business Owner](../assets/Business%20App%20Owner%20Avatar.png)<br/>**Business / Asset Owner** | *"With `WEB-APP-02` and `FS01` offline, what manual paper fallback procedures does your business unit initiate to maintain loan processing?"* |

---

## 🧹 Chapter 6: The Immutable Restoration & Executive Return-to-Production

![Backup Restoration Portal](../assets/backup_recovery_portal.jpg)

### 📖 The Narrative
By Day 2 at 08:00 AM, eradication activities were fully underway. 

The Network & System Team reimaging `LOAN-LAPTOP-042` with an approved gold image, purged the web shell on `WEB-APP-02`, patched CVE-2026-1102 on `AD-DC01`, and verified EDR sensor health across all endpoints.

Engineers accessed the immutable offline backup vault and located an uncorrupted snapshot taken at 02:00 AM on Day 1 (prior to infection). Restoration reached **98% completion** by 02:00 PM.

At 04:00 PM, the Business Asset Owner validated data integrity across restored shares. Finally, in a joint executive session, the **CIO and CISO** granted formal recovery authorization to return systems to production.

---

### 🌀 Dramatic Plot Twist 6: The 2-Hour Backup Gap & Missing Deals
> **TWIST**: *Data validation reveals that loan contracts created between 07:00 AM and 09:00 AM on Day 1 were not captured in the 02:00 AM snapshot. 14 high-value loan agreements must be manually re-entered from paper receipts!*

---

### ❓ Hot-Seat Character Interrogation Questions (Chapter 6)

| Character Role | Hot-Seat Twist Question for the Player |
| :--- | :--- |
| ![Business Owner](../assets/Business%20App%20Owner%20Avatar.png)<br/>**Business / Asset Owner** | *"14 loan contracts are missing from the restored snapshot. How do you validate manual re-entry accuracy before confirming operational recovery to the CIO/CISO?"* |
| ![CIO](../assets/CIO%20-%20Mgt.png)<br/>**CIO** | *"Under governance SOPs, what mandatory sign-off criteria must be satisfied before you and the CISO authorize returning core systems to production?"* |
| ![CISO](../assets/CISO%20-%20Mgt.png)<br/>**CISO** | *"Post-Incident Review (PIR) identifies 5 overdue remediation items. How does the CISO enforce accountability and tracking for overdue action items?"* |

---

## 📊 Summary of Character RACI Powers & Story Arc

```mermaid
flowchart LR
    subgraph Phase1["Phase 1: Phishing & Triage"]
        A["👨‍💼 Alex opens Telegram zip"] --> B["🛡️ SOC L1 Triage & Ticket"]
    end

    subgraph Phase2["Phase 2: LAN Recon & Scope"]
        B --> C["🏹 SOC L2 Investigation"]
        C --> D["🔮 CTI Threat Intel Enrichment"]
    end

    subgraph Phase3["Phase 3: Exfiltration & SIEM"]
        D --> E["📊 QRadar SIEM Offense #48291"]
        E --> F["⚒️ Net Ops Block C2 IP"]
    end

    subgraph Phase4["Phase 4: Encryption & WAR Room"]
        F --> G["🔒 CrowdStrike SEV-1 Alert"]
        G --> H["👑 SOC Manager Declares SEV-1"]
        H --> I["🎺 War Room Bard Management"]
    end

    subgraph Phase5["Phase 5: Recovery & Sign-Off"]
        I --> J["🏰 Asset Owner Validation"]
        J --> K["📜 CIO & ⚜️ CISO Final Approval"]
    end

    classDef triage fill:#1A233A,stroke:#00F2FE,color:#FFF;
    classDef crisis fill:#3A1A23,stroke:#FF3B30,color:#FFF;
    classDef recovery fill:#1A3A23,stroke:#00E676,color:#FFF;

    class Phase1,Phase2 triage;
    class Phase3,Phase4 crisis;
    class Phase5 recovery;
```

---

## 🎓 Facilitator Epilogue & Key Takeaways

1. **RACI Enforcement**: Containment authority must strictly align with pre-approved matrix boundaries to eliminate operational bottlenecks.
2. **Communication Velocity**: Incident Communicators own stakeholder notification and WAR Room management, ensuring technical teams remain focused on containment.
3. **Immutable Snapshots**: Offline, air-gapped backups are the single critical line of defense against ransomware extortion.
4. **Joint Executive Blessing**: Production restoration requires formal sign-off from both business and security leadership (CIO & CISO).

> 🚀 **Run the Interactive Deck**: Open [`index.html`](../index.html) to present full-screen slides or launch the D&D campaign mode!
