incident-response-trainer
Mock scenarios · Rule-based grading
CatalogOverviewSnapshot
← Back to catalog
CybersecurityhardRansomware (Early Stage)Critical asset
Scenario

FILE-SRV-04 encrypting shares, ransom note dropped, lateral SMB scans starting

A hard Cybersecurity scenario on Ransomware (Early Stage).

Practice this scenario

Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.

Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.

catalog id · ransomware-early-stage-fileserver

Training alignment

What this scenario practices, mapped to recognized frameworks.

Educational mapping only. Not a compliance attestation.

What this trains
  • Early-stage ransomware containment
  • Backup-driven recovery decisioning
MITRE ATT&CKmitre-attack
  • Data Encrypted for Impact · ImpactT1486 · TA0040
    MappedHigh confidence

    Trains early-stage ransomware recognition and containment.

  • Remote Services · Lateral MovementT1021 · TA0008
    PartialMedium confidence

    Trains defensive reasoning about lateral spread risk on file shares.

MITRE D3FENDmitre-d3fend
  • File AnalysisD3-FA
    MappedHigh confidence

    Trains file-analysis evidence handling for suspicious renames.

  • Process Activity AnalysisD3-PAU
    MappedHigh confidence

    Trains process-activity review on the source host.

NIST CSF 2.0nist-csf-2
  • Mitigation · RespondRS.MI · RS
    MappedHigh confidence

    Trains the mitigation reasoning the scenario centers on.

  • Recovery Planning · RecoverRC.RP · RC
    MappedHigh confidence

    Trains recovery decision making before encryption completes.

NIST SP 800-61r3nist-sp-800-61r3
  • IR lifecycle phaseContainment, Eradication & Recovery
    MappedHigh confidence

    Trains the IR phase the scenario centers on.

CISA Cybersecurity Performance Goalscisa-cpg
  • System Backups2.O
    MappedHigh confidence

    Trains the backup-readiness baseline the scenario depends on.

  • Incident Response Plans2.P
    MappedHigh confidence

    Trains the IR-plan baseline.

CIS Controls v8cis-controls
  • Data RecoveryControl 11
    MappedHigh confidence

    Trains the recovery control the scenario exercises.

  • Malware DefensesControl 10
    MappedHigh confidence

    Trains the endpoint-defense response.