Impact exercise

Ransomware testing

Grade how defenses respond to encrypt, ransom note, VSS inhibit, and backup wipe — then Blow up or Recover on an authorized lab path.

Technique coverage

ATT&CK Impact stages

Each stage maps to MITRE technique IDs so results read like the rest of the purple teaming catalog — pass when the defense blocks the probe, fail when it succeeds live.

  • Encrypt / decrypt sandbox canaries under Temp
  • Ransom note and inhibit recovery (VSS) checks
  • Optional backup wipe and operator Blow up / Recover

Lab controls

Reversible by design

Default paths stay in reversible sandbox mode. Aggressive allowlisted encrypt is available when operators acknowledge the risk — Controlled Folder Access and similar controls can still block Impact.

  • Auto-decrypt leftovers on Recover
  • Acked allowlist for aggressive lab encrypt
  • Active window and host agent gate every run

Build Your Own Narrative

After phishing and purple teaming

Unlock ransomware as the final Impact chapter in a narrative campaign once purple teaming stages complete. See Build Your Own Narrative.

  • Shared project timeline with phishing and APT packs
  • Unlock notifies operators; Play stays deliberate
  • People-risk opener available via phishing testing on the same timeline

Run ransomware testing only on authorized lab hosts and paths. See the ParitySH license.