Ransomware Kill Chain Investigator (RKCI)
Reduce MTTD/MTTR for ransomware by automatically ingesting Microsoft Defender incidents, enriching users/devices/IOCs (via Entra/Intune/Threat Intelligence), correlating the ATT&CK kill chain, and guiding response with a clear, human-readable plan.
“Agent-as-Process”: RKCI orchestrates global skills + local KQL hunts, and calls one GPT skill only to render the executive brief.
IncidentId (optional), LookbackHours=72, IncludeHunts="yes", TopN=50, MinSeverity="High".
A polished Markdown brief with: Executive Summary → Kill Chain (ATT&CK) → Affected Assets → IOCs & Threat Intel table → Recommended Actions → Timeline.
Controlled Folder Access blocks (RKCI_HuntCFA)
Ransomware utilities: vssadmin / wbadmin / bcdedit / cipher (RKCI_HuntRansomOps)
Mass rename/modify bursts (RKCI_HuntMassRename)
Ransom note creation/modification (RKCI_HuntRansomNotes)
Encoded/obfuscated PowerShell (RKCI_HuntPsEncoded)
Lateral movement patterns: PsExec / WMI / Schtasks / SC / AT (RKCI_HuntLateralMovement)
Merge only relevant hits; dedupe by (DeviceName, Process/IOC, time bin).
Results are capped (TopN) to prevent noise; the brief favors high-signal findings.
Least-privilege access for Microsoft Defender XDR, Microsoft Entra ID, Microsoft Threat Intelligence (DTI), and Microsoft Intune.
Advanced Hunting access in Defender (DeviceEvents, DeviceProcessEvents, DeviceFileEvents).
Security Copilot license + extension enabled in Visual Studio Code.
Skillset project named RansomwareKillChainInvestigator (required for namespaces).
In the Security Copilot Agents gallery, locate Ransomware Kill Chain Investigator (RKCI) and enable it.
Consent to required plugins: M365 (Defender XDR), Entra, ThreatIntelligence.DTI, Intune (recommended).
Confirm required skillsets: M365, Entra, Intune, ThreatIntelligence.DTI, and local RansomwareKillChainInvestigator.
On-demand: provide a Defender IncidentId.
Optional parameters: LookbackHours (default 72), IncludeHunts (default yes), TopN (default 50), MinSeverity (default High).
Analyzes full incidents: timeline, alerts, entities (users, devices, IOCs, files).
Enriches each entity with identity, device posture, and threat-intel context; runs targeted hunts; produces a single Markdown brief.
Gaps are explicitly called out when data is unavailable.
Ready to accelerate ransomware investigations and response?
Contact us to enable RKCI and generate a single executive-ready kill-chain narrative with guided actions.
Defender-only hunts + evidence-driven enrichment + Markdown executive brief.