Technique coverage
ATT&CK Impact stages
Each stage maps to MITRE technique IDs so results read like the rest of the purple teaming catalog — pass when the defense blocks the probe, fail when it succeeds live.
- Encrypt / decrypt sandbox canaries under Temp
- Ransom note and inhibit recovery (VSS) checks
- Optional backup wipe and operator Blow up / Recover
Lab controls
Reversible by design
Default paths stay in reversible sandbox mode. Aggressive allowlisted encrypt is available when operators acknowledge the risk — Controlled Folder Access and similar controls can still block Impact.
- Auto-decrypt leftovers on Recover
- Acked allowlist for aggressive lab encrypt
- Active window and host agent gate every run
Build Your Own Narrative
After phishing and purple teaming
Unlock ransomware as the final Impact chapter in a narrative campaign once purple teaming stages complete. See Build Your Own Narrative.
- Shared project timeline with phishing and APT packs
- Unlock notifies operators; Play stays deliberate
- People-risk opener available via phishing testing on the same timeline