Detect & Respond to Ransomware Behavior
advanced 50 min 4 tasksSubscription
Red: run a benign ransomware simulation that mass-renames/encrypts files and deletes the shadow copies. Blue: detect the burst of file changes and the anti-recovery command, then contain the host.
This lab is available with a Purple Edge subscription. Sign in to view the full overview and start the lab.
Part of these paths
Unlock this lab
Launch the lab in your browser. Real Kali, Ubuntu and Windows targets, guided step by step. No setup, no VM downloads.
Updated 2026-06-15