Staged exfiltration for days, then a partial encryption trigger and a leak-threat note — backups may be tampered, scope still unknown
A extremely-hard Cybersecurity scenario on Multi-Stage Ransomware (Double Extortion).
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.
catalog id · ransomware-double-extortion-exfil-first
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Double-extortion containment ordering
- Backup-integrity-aware recovery decisioning
- Data Encrypted for Impact · ImpactT1486 · TA0040MappedHigh confidence
Trains response to the encryption stage of a double-extortion incident.
- Exfiltration Over Web Service · ExfiltrationT1567 · TA0010MappedHigh confidence
Trains scoping of staged exfiltration that preceded encryption.
- File AnalysisD3-FAMappedHigh confidence
Trains evidence handling for encrypted files and the ransom note.
- Network Traffic AnalysisD3-NTAMappedMedium confidence
Trains egress analysis that reveals the pre-encryption exfil.
- Recovery Planning · RecoverRC.RP · RCMappedHigh confidence
Trains restore-from-verified-backup decisioning under tamper risk.
- Mitigation · RespondRS.MI · RSMappedHigh confidence
Trains containment of ongoing encryption plus exfil.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains the evidence-before-restore ordering this incident centers on.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains scoping of exactly what was exfiltrated for notification.
- System Backups2.OMappedHigh confidence
Trains the immutable-backup baseline that makes safe recovery possible.
- Incident Response Plans2.PMappedHigh confidence
Trains the IR-plan baseline for double-extortion handling.
- Data RecoveryControl 11MappedHigh confidence
Trains integrity-verified recovery from a possibly-tampered backup set.
- Data ProtectionControl 3MappedHigh confidence
Trains the data-protection lens on the confirmed exfiltration.