Lesson 6 of 6
Lab 6 — Practical Exam: Ransomware Incident Response
A full graded scenario: contain a live ransomware outbreak, build the timeline and write the board report.
Learn it
In a real incident nobody has all the facts. You act on partial evidence, in the right order, and you write down everything.
The order matters: contain the spread, preserve the evidence, then recover. Wiping the first machine destroys the clues that tell you how many others are infected.
Paying a ransom is a business decision, not a technical fix — and it does not undo the data theft.
Key terms
- Containment
- Stopping the spread — isolating hosts, disabling accounts, blocking C2 — before eradication.
- Double extortion
- Stealing data before encrypting it, so victims are pressured even if backups work.
- Indicator of Compromise
- An artefact such as a file hash, IP, domain or registry key that evidences an intrusion.
- 3-2-1 backup
- Three copies of data, on two media types, with one kept offline or immutable.
- Patient zero
- The first infected system, which reveals the initial access route.
The scenario
08:12 Monday. You are the incident lead at a college of 1,400 students. Read the facts, then answer the exam below.
- 1Fact 1: Reception reports every file on the shared drive is renamed with a .lokx extension and a note titled RESTORE-FILES.txt appears in each folder.
- 2Fact 2: The file server's event log shows a domain admin login at 02:41 from workstation LIB-14, which nobody was using.
- 3Fact 3: LIB-14's browser history shows a download at 16:52 Friday from a lookalike domain of a printer-driver site.
- 4Fact 4: Firewall logs show 41 GB uploaded to an unknown host between 23:10 Sunday and 01:55 Monday.
- 5Fact 5: The nightly backup job ran at 01:00 Monday and reports 'success'. The backup server is domain-joined and was reachable by the same admin account.
- 6Fact 6: The ransom note demands 30 BTC and threatens to publish student records in 72 hours.
- 7Fact 7: The principal asks: 'Can we just pay and be back by lunchtime?'
The timeline you should build
textFri 16:52 LIB-14 trojanised driver downloaded (initial access)
Fri 17:04 LIB-14 beacon to C2 begins (persistence)
Sun 22:30 LIB-14 credential dumping -> domain admin obtained (privilege escalation)
Sun 23:10 FS-01 41 GB exfiltrated (data theft)
Mon 01:00 BKP-01 backup job runs - integrity now UNTRUSTED
Mon 02:41 FS-01 admin login from LIB-14 (lateral movement)
Mon 02:55 FS-01 mass file encryption begins (impact)
Mon 08:12 --- detection by staff (dwell time: 63 hours)Dwell time — the gap between initial access and detection — is the single most useful number in the post-incident report.
Sandbox lab
Practise the real technique in a fully simulated environment — no live systems, no real data, nothing leaves your browser.
Packet capture triage console
A frozen, fake capture from a school network. Flag every malicious packet, then check your triage.
| Flag | Time | Source | Destination | Proto/Port | Bytes | Info |
|---|---|---|---|---|---|---|
| 09:00:01 | 10.0.0.14 | 142.250.187.4 | TCP/443 | 1,420 | TLS application data | |
| 09:00:04 | 10.0.0.14 | 10.0.0.1 | UDP/53 | 86 | DNS query school-portal.local | |
| 09:02:00 | 10.0.0.31 | 185.62.190.7 | TCP/8080 | 312 | POST /gate.php (heartbeat) | |
| 09:04:00 | 10.0.0.31 | 185.62.190.7 | TCP/8080 | 314 | POST /gate.php (heartbeat) | |
| 09:05:11 | 10.0.0.22 | 10.0.0.14 | TCP/445 | 980 | SMB file read report.docx | |
| 09:06:00 | 10.0.0.31 | 185.62.190.7 | TCP/8080 | 313 | POST /gate.php (heartbeat) | |
| 09:06:41 | 10.0.0.9 | 10.0.0.2 | TCP/22 | 640 | SSH session to admin server | |
| 09:07:02 | 10.0.0.77 | 10.0.0.14 | TCP/21 | 60 | SYN (no reply) | |
| 09:07:02 | 10.0.0.77 | 10.0.0.14 | TCP/22 | 60 | SYN (no reply) | |
| 09:07:02 | 10.0.0.77 | 10.0.0.14 | TCP/23 | 60 | SYN (no reply) | |
| 09:08:30 | 10.0.0.14 | 104.18.32.11 | TCP/443 | 5,210 | TLS download update.pkg | |
| 09:09:10 | 10.0.0.31 | 185.62.190.7 | TCP/8080 | 4,210,000 | POST /upload (4.2 MB) |
Web exploit lab
A pretend vulnerable app running entirely in this page. No real database, no real network requests, no scripts are ever executed.
SOC mini-lab: AI-assisted incident response
Simulated Security Operations Centre — fictional logs, fictional attacker, zero real systems.
- 1. Triage
- 2. Log review
- 3. Containment
- 4. Report
07:42 — the AI triage queue has surfaced six alerts with model risk scores. Select every true positive. Remember: a high model score is a signal, not a verdict.
Try it
Put the response actions into the correct order for this incident.
- 1Disable the compromised domain admin account and force a KRBTGT reset
- 2Capture memory and disk images of LIB-14 as evidence
- 3Verify backups on offline media before trusting any restore
- 4Notify the ICO within 72 hours and inform affected students
- 5Isolate LIB-14 and FS-01 from the network without powering them off
- 6Run a post-incident review and fix the initial access route
- 7Rebuild affected systems from known-good images
Challenge
PRACTICAL EXAM (200 XP). Produce a full incident report for the scenario above. It must contain: (1) a timestamped timeline with the attack phase labelled for each event; (2) the dwell time and how you calculated it; (3) your containment plan in strict order, with a justification for each step's position; (4) a clear recommendation on paying the ransom, with reasoning; (5) the legal/notification obligations and their deadline; (6) five prioritised controls that would have prevented or limited this incident. Be specific — 'improve security' scores zero.
Pick whichever way suits you — every mode earns the same bonus XP.
Write at least 40 more characters to submit.
Mark your own work
Guided walkthrough — 0/9 clues revealed
- Clue 1 locked — reveal it only if you get stuck.
- Clue 2 locked — reveal it only if you get stuck.
- Clue 3 locked — reveal it only if you get stuck.
- Clue 4 locked — reveal it only if you get stuck.
- Clue 5 locked — reveal it only if you get stuck.
- Clue 6 locked — reveal it only if you get stuck.
- Clue 7 locked — reveal it only if you get stuck.
- Clue 8 locked — reveal it only if you get stuck.
- Clue 9 locked — reveal it only if you get stuck.
Each clue costs 10 XP (never below 50 XP). You'd earn 100 XP right now.
Extension: Write the 150-word statement for parents. It must be honest about the data theft without causing panic, and must tell them exactly what to do.