๐งฉ Ransomware
PLANNED๐ Scenario Overview
A sophisticated ransomware attack (PLAY ransomware group) has infiltrated the City of Georgetown's municipal network through a phishing campaign targeting the finance department. The attack encrypts critical servers including tax databases, utility billing systems, permit management, and emergency services dispatch. The ransomware group exfiltrated 2TB of sensitive citizen data before encryption and is now demanding M in Monero. City employees are locked out of email, file shares, and all line-o...
Read full scenario โ๐ฏ Objectives
- Identify all affected systems and determine the scope of the ransomware infection using incident response procedures
- Map the attack lifecycle using MITRE ATT&CK to understand the full kill chain from initial access to impact
- Determine whether to pay the ransom and establish a decision-making framework for ransom negotiations
- Contain the outbreak by isolating affected network segments while maintaining essential city services
- Develop a recovery plan prioritizing critical citizen services (emergency dispatch, water, power)
- Manage public communication and media relations to maintain citizen trust and provide accurate information
- Coordinate with law enforcement (FBI, CISA, Secret Service) for threat intelligence and legal proceedings
- Implement enhanced security controls based on MITRE ATT&CK gaps identified during the exercise
๐ Exercise Modules
Module 1: MODULE 1: Initial Detection & Triage (15 min) โ Assess the alert, determine scope, activate IR team, engage external IR firm
00:00
Module 2: MODULE 2: MITRE ATT&CK Mapping & Analysis (20 min) โ Map full attack chain to MITRE ATT&CK, identify security gaps, prioritize containment
00:00
Module 3: MODULE 3: Containment & Eradication (20 min) โ Isolate network segments, preserve evidence, remove threat actor access, block C2 infrastructure
00:00
Module 4: MODULE 4: Ransom Decision & Stakeholder Communication (20 min) โ Ransom payment decision, legal consultation, public communication strategy
00:00
Module 5: MODULE 5: Recovery & Restoration (15 min) โ Prioritize system recovery, validate backups, restore from clean backups, implement security improvements
00:00
๐ฌ Discussion Questions
๐ References
- MITRE ATT&CK โ Ransomware: https://attack.mitre.org/software/S1066/
- CISA Ransomware Guide: https://www.cisa.gov/stopransomware
- CISA MS-ISAC Ransomware Guide: https://www.cisa.gov/sites/default/files/publications/CISA_MS-ISAC_Ransomware%20Guide_508c.pdf
- NIST SP 800-61 Rev 2 โ Incident Handling Guide: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
- MITRE ATT&CK Enterprise Matrix: https://attack.mitre.org/
- FBI Internet Crime Complaint Center (IC3): https://www.ic3.gov/
- CISA โ Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- NIST Cybersecurity Framework (CSF) 2.0: https://www.nist.gov/cyberframework
- CISA โ Stop Ransomware: https://www.cisa.gov/stopransomware
- Play Ransomware Group Analysis: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a