Ransomware Kill Chain Investigator (RKCI)

Ransomware Kill Chain Investigator (RKCI)

Reduce MTTD/MTTR for ransomware by automatically ingesting Microsoft Defender incidents, enriching users/devices/IOCs (via Entra/Intune/Threat Intelligence), correlating the ATT&CK kill chain, and guiding response with a clear, human-readable plan.

Customer benefit

  • Faster triage: stitch alerts into a single narrative across ATT&CK phases.
  • Higher confidence: identity/device posture and threat-intel context on every entity and IOC.
  • Operational scale: repeatable guided response, less analyst toil, consistent quality.

Products in scope

  • Microsoft Defender XDR (MDE/MDI/MDO)
  • Microsoft Entra ID
  • Microsoft Intune
  • Microsoft Threat Intelligence (DTI)

Functional design (high level)

Operating model

“Agent-as-Process”: RKCI orchestrates global skills + local KQL hunts, and calls one GPT skill only to render the executive brief.

Defaults

IncidentId (optional), LookbackHours=72, IncludeHunts="yes", TopN=50, MinSeverity="High".

Output

A polished Markdown brief with: Executive Summary → Kill Chain (ATT&CK) → Affected Assets → IOCs & Threat Intel table → Recommended Actions → Timeline.

Manual trigger
On-demand
72h
Default lookback
LookbackHours
Optional schedule
DefaultPollPeriodSeconds=1800 (30 minutes)
Final output
Markdown

Targeted hunts (Defender Advanced Hunting)

Executed when IncludeHunts="yes"

Controlled Folder Access blocks (RKCI_HuntCFA)

Ransomware utilities: vssadmin / wbadmin / bcdedit / cipher (RKCI_HuntRansomOps)

Mass rename/modify bursts (RKCI_HuntMassRename)

Ransom note creation/modification (RKCI_HuntRansomNotes)

Encoded/obfuscated PowerShell (RKCI_HuntPsEncoded)

Lateral movement patterns: PsExec / WMI / Schtasks / SC / AT (RKCI_HuntLateralMovement)

Hunt handling

Merge only relevant hits; dedupe by (DeviceName, Process/IOC, time bin).

Results are capped (TopN) to prevent noise; the brief favors high-signal findings.

Enablement & how to run

Prerequisites

Least-privilege access for Microsoft Defender XDR, Microsoft Entra ID, Microsoft Threat Intelligence (DTI), and Microsoft Intune.

Advanced Hunting access in Defender (DeviceEvents, DeviceProcessEvents, DeviceFileEvents).

Security Copilot license + extension enabled in Visual Studio Code.

Skillset project named RansomwareKillChainInvestigator (required for namespaces).

Enable the agent

In the Security Copilot Agents gallery, locate Ransomware Kill Chain Investigator (RKCI) and enable it.

Consent to required plugins: M365 (Defender XDR), Entra, ThreatIntelligence.DTI, Intune (recommended).

Confirm required skillsets: M365, Entra, Intune, ThreatIntelligence.DTI, and local RansomwareKillChainInvestigator.

How to run

On-demand: provide a Defender IncidentId.

Optional parameters: LookbackHours (default 72), IncludeHunts (default yes), TopN (default 50), MinSeverity (default High).

What to expect

Analyzes full incidents: timeline, alerts, entities (users, devices, IOCs, files).

Enriches each entity with identity, device posture, and threat-intel context; runs targeted hunts; produces a single Markdown brief.

Gaps are explicitly called out when data is unavailable.

Ready to accelerate ransomware investigations and response?
Contact us to enable RKCI and generate a single executive-ready kill-chain narrative with guided actions. Defender-only hunts + evidence-driven enrichment + Markdown executive brief.

Request contact