---
marp: true
theme: default
paginate: true
header: "🛡️ SOC Briefing | Ransomware Tabletop Exercise (TTX)"
footer: "Confidential - Cybersecurity Operations Center"
---

# 🛡️ SOC Team Briefing: Ransomware Tabletop Exercise (TTX)
### 🎯 Executive & Operational Orientation Slide Deck

**Presenter**: SOC Lead / Facilitator  
**Target Audience**: SOC L1, SOC L2, SOC Lead/L3, SOC Manager, IR Communicator, CTI Team  
**Exercise Context**: Off-site Phishing, C2 Beaconing, SMB Exfiltration & Ransomware Outbreak  
**Date**: August 2026  

---

# 📌 1. Why Are We Running This TTX?

### Background & Operational Reality
- **Off-site Workforce Vulnerability**: Loan officers and remote staff rely heavily on messaging platforms (e.g., Telegram) for customer interactions.
- **Silent Malware Execution**: Attackers disguise malicious executables inside archives (`Customer_Documents_2026.zip`), triggering fake error messages while establishing covert background persistence.
- **LAN Reconnection Hazard**: Upon returning to the office network, malware abuses existing user authentication to target corporate file shares (`Loan_Share$`).

> 🎯 **Core Purpose**: To test, evaluate, and refine our SOC Incident Response SOPs, detection capabilities, team escalation SLAs, and crisis communication in a simulated, zero-risk environment.

---

# 🎯 2. Core Exercise Objectives

| # | Objective | Success Criteria / SLA Target |
| :-: | :--- | :--- |
| **1** | **⏱️ Validate SLA Speed** | SOC L1 → L2 escalation in **<15 mins**; Executive notification in **<15 mins** for SEV-1. |
| **2** | **🚒 Test Containment Playbooks** | Rapid execution of EDR host isolation, AD session revocation, C2 IP blocking, and file share restrictions. |
| **3** | **💬 Practice Crisis Comms** | Incident WAR Room creation within **30 mins**; stakeholder status updates every **30–60 mins**. |
| **4** | **🔍 Scoping & Threat Hunting** | Accurate mapping of initial access vector, lateral movement attempts, and compromised assets. |
| **5** | **📝 Identify Gaps & Improve** | Uncover friction points between SOC, IT Infrastructure, Legal, and Business teams. |

---

# 📖 3. Scenario At A Glance: "ADMFI Ransomware Incident"

```
[ Telegram Phishing ] ──> [ Fake PDF Error ] ──> [ Silent C2 Connection ]
                                                            │
[ Shared Folder Encryption ] <── [ Data Exfiltration ] <── [ LAN Reconnection ]
            │
            ├──> 🚨 CrowdStrike EDR Critical Alert (Host Isolated)
            ├──> 📊 QRadar SIEM Event Correlation (Anomalous SMB Access)
            └──> 💀 Ransom Note Displayed ($50,000 USD Demand)
```

- **Victim User**: Sok Dara (Senior Loan Officer)
- **Initial Vector**: Received `Customer_Documents_2026.zip` containing `Loan_Agreement.pdf.exe` via Telegram.
- **Impact**: Files encrypted with `.ADMFI_LOCKED` extension across local workstation and shared drive (`\\ADMFI-FS01\Loan_Share$`).

---

# 🎭 4. SOC Roles & Expectations Matrix

| Role | Key Focus | Primary Responsibilities During TTX |
| :--- | :--- | :--- |
| **SOC L1 Analyst** | Initial Triage | Monitor SIEM/EDR, validate alerts, enrich context, open ITSM ticket, escalate to L2 <15m. |
| **SOC L2 Analyst** | Lead Investigation | Scope blast radius, create forensic timeline, execute host isolation, block IOCs. |
| **SOC Lead / L3** | Deep Forensics | Reverse engineer malware sample, lead enterprise threat hunting, assist complex containment. |
| **SOC Manager** | Incident Command | Declare SEV-1 Major Incident, authorize production containment, engage CISO/CIO & BCP. |
| **IR Communicator** | Comms & WAR Room | Setup MS Teams WAR Room <30m, issue interim updates every 30-60m, draft AAR. |
| **CTI Analyst** | Threat Intel | Enrich IOCs, correlate threat actor TTPs, search external campaign intelligence. |

---

# 👨‍💻 5. Deep Dive: SOC L1 & SOC L2 Execution Responsibilities

### 🔹 SOC L1 Analyst (Tier 1 Duty)
1. **Acknowledge & Validate**: Confirm EDR alert (CrowdStrike) & SIEM correlation (QRadar) are True Positive.
2. **Enrich Context**: Gather Endpoint Name, IP address, User Account (`sok.dara`), Hash, and Alert Severity.
3. **Log & Escalate**: Create ITSM Ticket (`#INC-2026-0814`) with provisional **SEV-1** rating and transfer to L2 in **<15 minutes**.

### 🔹 SOC L2 Analyst (Tier 2 Incident Lead)
1. **Forensic Timeline**: Reconstruct timeline from Telegram download → C2 beacon → LAN connection → SMB enumeration.
2. **Execute Containment**: Isolate infected endpoint in EDR console immediately.
3. **Enforce Restrictions**: Request AD account lock, active token revocation, C2 domain/IP firewall block, and SMB write restriction.

---

# 👔 6. Deep Dive: SOC L3, SOC Manager & IR Communicator

### 🔬 SOC Lead / L3 Analyst
- Perform memory/file artifact analysis on `Loan_Agreement.pdf.exe`.
- Conduct threat hunt across all corporate endpoints for IOC hashes (`e3b0c442...`).

### 👔 SOC Manager (Incident Commander)
- Formally declare **SEV-1 Major Incident**.
- Notify CISO & CIO by phone within **15 minutes**.
- Authorize high-impact containment actions (e.g., disconnecting file server segments).

### 💬 Incident Communicator
- Establish **WAR Room** within **30 minutes** of SEV-1 declaration.
- Maintain Incident Action Log and publish periodic executive briefings every 30–60 minutes.

---

# 📜 7. Exercise Ground Rules & Mindset

> [!TIP]
> 🟢 **Safe Learning Environment**: This TTX is an evaluation of *processes and playbooks*, NOT an individual performance audit.

1. **Speak Up & Participate**: Explain your actions step-by-step: *"I am checking X log file, issuing Y command, and notifying Z role."*
2. **Focus on SOP Alignment**: Reference our official playbooks (Ransomware SOP & Account Compromise SOP).
3. **Challenge Assumptions**: If a procedure is unclear, redundant, or missing authorization, raise it during the inject discussion.
4. **No Real Production Impact**: All actions discussed are hypothetical—no live systems will be disrupted.

---

# 🔄 8. SOC Response Workflow Summary

```mermaid
flowchart LR
    A["🚨 Alert / Report"] --> B["👨‍💻 L1 Triage & Ticket<br/>⏱️ <15 mins"]
    B --> C["🔍 L2 Investigation<br/>& EDR Host Isolation"]
    C --> D["📢 SOC Mgr SEV-1<br/>WAR Room Comms"]
    D --> E["🧹 Eradication,<br/>Re-image & Restore"]
    E --> F["📋 72-Hour Monitor<br/>& Lessons Learned"]

    classDef detect fill:#E2F0D9,stroke:#548235,color:#375623;
    classDef contain fill:#FFF2CC,stroke:#BF8F00,color:#7F6000;
    classDef crisis fill:#F4CCCC,stroke:#C00000,color:#7F0000;
    classDef recover fill:#D9EAF7,stroke:#2F75B5,color:#17365D;

    class A,B detect;
    class C contain;
    class D crisis;
    class E,F recover;
```

---

# 🏁 9. Post-TTX Deliverables & Next Steps

1. **📄 After-Action Report (AAR)**: Documenting key observations, SLA compliance, and technical findings.
2. **🛠️ SOP & Playbook Updates**: Refining containment matrix, containment delegation authority, and communication templates.
3. **🎯 Detection Engineering Tuning**: Adding custom EDR prevention rules and SIEM correlation alerts for double-extension files (`.pdf.exe`).
4. **📌 Action Item Tracking**: Assigning clear ownership and deadlines for all identified gaps.

---

### ❓ Questions & Readiness Check
*Are all SOC team members clear on their roles and objectives? Let's begin Inject 1!*
