Cyber Security Labs (Beginner → Advanced)

Lesson 6 of 6

Lab 6 — Practical Exam: Ransomware Incident Response

A full graded scenario: contain a live ransomware outbreak, build the timeline and write the board report.

🔴 Advanced 200 XP

Learn it

In a real incident nobody has all the facts. You act on partial evidence, in the right order, and you write down everything.

The order matters: contain the spread, preserve the evidence, then recover. Wiping the first machine destroys the clues that tell you how many others are infected.

Paying a ransom is a business decision, not a technical fix — and it does not undo the data theft.

Key terms

Containment
Stopping the spread — isolating hosts, disabling accounts, blocking C2 — before eradication.
Double extortion
Stealing data before encrypting it, so victims are pressured even if backups work.
Indicator of Compromise
An artefact such as a file hash, IP, domain or registry key that evidences an intrusion.
3-2-1 backup
Three copies of data, on two media types, with one kept offline or immutable.
Patient zero
The first infected system, which reveals the initial access route.

The scenario

08:12 Monday. You are the incident lead at a college of 1,400 students. Read the facts, then answer the exam below.

  1. 1Fact 1: Reception reports every file on the shared drive is renamed with a .lokx extension and a note titled RESTORE-FILES.txt appears in each folder.
  2. 2Fact 2: The file server's event log shows a domain admin login at 02:41 from workstation LIB-14, which nobody was using.
  3. 3Fact 3: LIB-14's browser history shows a download at 16:52 Friday from a lookalike domain of a printer-driver site.
  4. 4Fact 4: Firewall logs show 41 GB uploaded to an unknown host between 23:10 Sunday and 01:55 Monday.
  5. 5Fact 5: The nightly backup job ran at 01:00 Monday and reports 'success'. The backup server is domain-joined and was reachable by the same admin account.
  6. 6Fact 6: The ransom note demands 30 BTC and threatens to publish student records in 72 hours.
  7. 7Fact 7: The principal asks: 'Can we just pay and be back by lunchtime?'

The timeline you should build

textFri 16:52  LIB-14  trojanised driver downloaded (initial access)
Fri 17:04  LIB-14  beacon to C2 begins (persistence)
Sun 22:30  LIB-14  credential dumping -> domain admin obtained (privilege escalation)
Sun 23:10  FS-01   41 GB exfiltrated (data theft)
Mon 01:00  BKP-01  backup job runs - integrity now UNTRUSTED
Mon 02:41  FS-01   admin login from LIB-14 (lateral movement)
Mon 02:55  FS-01   mass file encryption begins (impact)
Mon 08:12  ---     detection by staff (dwell time: 63 hours)

Dwell time — the gap between initial access and detection — is the single most useful number in the post-incident report.

Sandbox lab

Practise the real technique in a fully simulated environment — no live systems, no real data, nothing leaves your browser.

Packet capture triage console

A frozen, fake capture from a school network. Flag every malicious packet, then check your triage.

Safe simulation
FlagTimeSourceDestinationProto/PortBytesInfo
09:00:0110.0.0.14142.250.187.4TCP/4431,420TLS application data
09:00:0410.0.0.1410.0.0.1UDP/5386DNS query school-portal.local
09:02:0010.0.0.31185.62.190.7TCP/8080312POST /gate.php (heartbeat)
09:04:0010.0.0.31185.62.190.7TCP/8080314POST /gate.php (heartbeat)
09:05:1110.0.0.2210.0.0.14TCP/445980SMB file read report.docx
09:06:0010.0.0.31185.62.190.7TCP/8080313POST /gate.php (heartbeat)
09:06:4110.0.0.910.0.0.2TCP/22640SSH session to admin server
09:07:0210.0.0.7710.0.0.14TCP/2160SYN (no reply)
09:07:0210.0.0.7710.0.0.14TCP/2260SYN (no reply)
09:07:0210.0.0.7710.0.0.14TCP/2360SYN (no reply)
09:08:3010.0.0.14104.18.32.11TCP/4435,210TLS download update.pkg
09:09:1010.0.0.31185.62.190.7TCP/80804,210,000POST /upload (4.2 MB)

Web exploit lab

A pretend vulnerable app running entirely in this page. No real database, no real network requests, no scripts are ever executed.

Safe simulation

SOC mini-lab: AI-assisted incident response

Simulated Security Operations Centre — fictional logs, fictional attacker, zero real systems.

Safe simulation
  1. 1. Triage
  2. 2. Log review
  3. 3. Containment
  4. 4. Report
7 / 27 lab XP26%

07:42 — the AI triage queue has surfaced six alerts with model risk scores. Select every true positive. Remember: a high model score is a signal, not a verdict.

Try it

Put the response actions into the correct order for this incident.

  • 1Disable the compromised domain admin account and force a KRBTGT reset
  • 2Capture memory and disk images of LIB-14 as evidence
  • 3Verify backups on offline media before trusting any restore
  • 4Notify the ICO within 72 hours and inform affected students
  • 5Isolate LIB-14 and FS-01 from the network without powering them off
  • 6Run a post-incident review and fix the initial access route
  • 7Rebuild affected systems from known-good images

Challenge

PRACTICAL EXAM (200 XP). Produce a full incident report for the scenario above. It must contain: (1) a timestamped timeline with the attack phase labelled for each event; (2) the dwell time and how you calculated it; (3) your containment plan in strict order, with a justification for each step's position; (4) a clear recommendation on paying the ransom, with reasoning; (5) the legal/notification obligations and their deadline; (6) five prioritised controls that would have prevented or limited this incident. Be specific — 'improve security' scores zero.

Pick whichever way suits you — every mode earns the same bonus XP.

Write at least 40 more characters to submit.

Mark your own work

Guided walkthrough — 0/9 clues revealed

  1. Clue 1 locked — reveal it only if you get stuck.
  2. Clue 2 locked — reveal it only if you get stuck.
  3. Clue 3 locked — reveal it only if you get stuck.
  4. Clue 4 locked — reveal it only if you get stuck.
  5. Clue 5 locked — reveal it only if you get stuck.
  6. Clue 6 locked — reveal it only if you get stuck.
  7. Clue 7 locked — reveal it only if you get stuck.
  8. Clue 8 locked — reveal it only if you get stuck.
  9. Clue 9 locked — reveal it only if you get stuck.

Each clue costs 10 XP (never below 50 XP). You'd earn 100 XP right now.

Extension: Write the 150-word statement for parents. It must be honest about the data theft without causing panic, and must tell them exactly what to do.

Quiz time

Question 1 of 5Score 0

What was the approximate dwell time in this incident?