Purple Team & Ransomware Tabletop
A purple-team ransomware assessment: a real attack scenario run on a live endpoint, scored against what the team and their tools actually detected — then a stakeholder tabletop on the response.
OSec ran a ransomware scenario end to end, mapped each step to MITRE ATT&CK, and recorded what the client’s tooling caught and missed. The verdict: detections existed, but their coverage and timeliness could be materially improved.
Scope. The ability to detect, mitigate, respond to, and recover from a ransomware incident — a simulated attack on a provided laptop, plus a tabletop exercise with stakeholders.
The report, section by section
- Executive summary
- MITRE ATT&CK mapping
- Simulated attack scenario
- What was detected — and what wasn’t
- Tabletop exercise
- Recommendations
How it’s measured
- Every step of the simulated attack is mapped to MITRE ATT&CK techniques and sub-techniques, so gaps are expressed in the same language your blue team already uses.
- Each technique is scored on whether it was detected, and how quickly — turning "are we covered?" into a concrete list of what fired, what stayed silent, and where to tune.
- The tabletop puts the same scenario in front of stakeholders to pressure-test the human side: who owns the decision, when, and what the playbook actually says.
Client names, dates, hosts and other identifying details are redacted throughout. Everything else — findings, severity, method, and the walkthrough — is exactly as delivered.
Read the full redacted report.
PDF not showing? Get a downloadable copy →
Get the PDF, plus all three sample reports.
You’ve read it here. Drop your email and we’ll send this report, plus the other two, as downloadable PDFs.