Trace a multi-subnet ransomware incident from phishing macro to shadow-copy destruction, then choose containment that preserves evidence
At 06:00 the SOC at the fictional Solstice Retail Group is flooded with mass file-rename alerts and ransom notes spreading across three network segments. Trace patient-zero back to a phishing macro, reconstruct the WMI/SMB propagation and shadow-copy destruction, and choose containment that preserves evidence instead of paying the ransom.