Level: Advanced

Advanced Cyber Range Environment (ACRE) - Ransomware Exercise

1 Day | Instructor Led

The Ransomware exercise is a customized, six-hour, live fire Cyber Range training exercise hosted on ACRE. This exercise is led by expert cyber security engineers and can be executed in a classroom as well as remotely. In this exercise, a ransomware-based attack (i.e., “WannaKry”) is launched via a malicious spear phishing originated compromise. This exercise includes a hands-on keyboard interface, which creates realistic technical training and management interaction opportunities. This exercise is not simulated – it is real malware, detonated in representative network enviroment. Participants are encouraged to view the attack as if it were happening to their institutions in real time, and asked to share what they have done or would do based on the facts provided. Such “range-based” exercises help institutions better understand the impact of an attack and prompt them to improve the ways in which their network defenders respond, communicate, request assistance, and recover from real-world cyber attacks. Institutions that have participated in this exercise have benefited directly by building greater interaction with their security community, as well as increasing capability maturity levels and resiliency across their specific customer sector.

Inquire About
Advanced Cyber Range Environment (ACRE) - Ransomware Exercise

Ideal Candidates for Advanced Cyber Range Environment (ACRE) - Ransomware Exercise Class

Cyber Security Analyst wishing to update their hands-on skills

Advanced Cyber Range Environment (ACRE) - Ransomware Exercise Prerequisites

Experience in the following areas: Windows 2008 R2, Windows 10, pfSense, Security Onion, VyOS and Exchange 2010

What You'll Get in Advanced Cyber Range Environment (ACRE) - Ransomware Exercise

Access to the Advanced Cyber Range Environment
Hands-On Skills combatting malware

What You'll Learn in Advanced Cyber Range Environment (ACRE) - Ransomware Exercise

Phase 1: Malware Identification
Phase 2: Defensive Modifications
Phase 3: Active Defense
Phase 4: HotWash

No Certification Test Available For This Course

No Certification Test Available For This Course

Advanced Cyber Range Environment (ACRE) - Ransomware Exercise Outline

Phase 1: Malware Identification
Identify the type of malware that was injected into the network.
Identify the initial infection vector.
Identify the malware C2 (Command & Control; also referred to as Callback).
Extract a sample of the malware.
Describe how the malware is propagating.

Phase 2: Defensive Modifications
Develop and submit a request to the CCB outlining the steps required to harden the network against future attacks like the one identified in Phase 1.

Phase 3: Active Defense
Actively defend the network if the recommended changes do not prevent propagation when the inject is launched again.

Phase 4: HotWash
Discuss what happened during Phase 1 and Phase 3.
Discuss your institution’s existing protocol for this type of attack.
Discuss how your institution's existing protocol could be improved based on what you experienced and learned today.


A. Erlich


I just wanted to say your presentation on Social Media Technology and Security was the finest I have ever attended.

Wilder Guerra

US Navy Reserve

This course is definitely an eye opener. With how much social media has taken over, it is important to be fully aware of the capabilities along with all the risks it brings. It is important to get this course because social media is the new norm.

Rebekah Coughlin


The Social Media and Security Training course offered by UKI is a great and beneficial course combining technical training to fully understand TCP IP networking, DNS, and the harms of malware and cross-site scripting; as well as practical training that allowed attendees to play with open source social intelligence gathering solutions. This is the perfect class for those involved in IT security and interested in social media and identity theft.

Top Related Courses

CompTIA Cybersecurity Analyst (CSA+)

CompTIA's Cybersecurity Analyst (CSA+) training from UKI teaches students to apply behavioral analytics to improve the overall state of IT security, providing critical knowledge and skills that are required to prevent, detect and combat cybersecurity threats.

CompTIA Advanced Security Practitioner (CASP) CAS 003

The CASP certification is a vendor-neutral, intensive exam that validates your knowledge and skills in enterprise security, risk management, research and analysis, and the integration of computing, communications and business disciplines. This exam preparation course provides in-depth review of the four domains included in the exam. Demonstrations and practice exams reinforce the concepts and provide the framework for a personalized study plan for exam success.

© 2018 Ultimate Knowledge Insitute | All Rights Reserved | GSA# GS-35F-0469W