Sample report · Purple team & ransomware tabletop

Purple Team & Ransomware Tabletop

A purple-team ransomware assessment: a real attack scenario run on a live endpoint, scored against what the team and their tools actually detected — then a stakeholder tabletop on the response.

What happened

OSec ran a ransomware scenario end to end, mapped each step to MITRE ATT&CK, and recorded what the client’s tooling caught and missed. The verdict: detections existed, but their coverage and timeliness could be materially improved.

Scope. The ability to detect, mitigate, respond to, and recover from a ransomware incident — a simulated attack on a provided laptop, plus a tabletop exercise with stakeholders.

What’s inside

The report, section by section

  1. Executive summary
  2. MITRE ATT&CK mapping
  3. Simulated attack scenario
  4. What was detected — and what wasn’t
  5. Tabletop exercise
  6. Recommendations

How it’s measured

  • Every step of the simulated attack is mapped to MITRE ATT&CK techniques and sub-techniques, so gaps are expressed in the same language your blue team already uses.
  • Each technique is scored on whether it was detected, and how quickly — turning "are we covered?" into a concrete list of what fired, what stayed silent, and where to tune.
  • The tabletop puts the same scenario in front of stakeholders to pressure-test the human side: who owns the decision, when, and what the playbook actually says.

Client names, dates, hosts and other identifying details are redacted throughout. Everything else — findings, severity, method, and the walkthrough — is exactly as delivered.

The document

Preview the report. Unlock the whole thing.

Unlock the full report ↓

The opening pages are free to read. Unlock the full 25-page report →

Unlock it

The full report here, plus all three as PDFs.

Drop your work email: the preview above unlocks to the full document, and we’ll send this report plus the other two as downloadable PDFs.

We’ll email the download links to that address.