What problem does it solve?
SOC teams often lack formalized, tested procedures for ransomware incidents, leading to slow containment, inconsistent triage decisions, and compliance gaps. This Skill produces a complete ransomware response playbook aligned to NIST SP 800-61 and MITRE ATT&CK so Tier 1-3 analysts follow one standardized process.
Core Features & Use Cases
- Detection Engineering: Ready-to-deploy SIEM queries for Splunk and Elastic Security covering mass file encryption, shadow copy deletion (T1490), and ransom note creation.
- Triage Decision Tree: Branching logic for active encryption, pre-encryption indicators, host count escalation, and double-extortion assessment.
- Containment & Recovery Procedures: EDR isolation commands for CrowdStrike and Microsoft Defender for Endpoint, firewall emergency rules, AD account actions, forensic evidence collection, and backup-based recovery steps.
- Use Case: A SOC manager preparing for a tabletop exercise uses this Skill to generate a ransomware playbook with detection rules, isolation runbooks, and a post-incident review template mapped to NIST CSF controls.
Quick Start
Build a ransomware incident response playbook for our SOC that includes Splunk detection queries, CrowdStrike host isolation steps, and a post-incident review template aligned to NIST SP 800-61.