Darkmon - Ransomware Victim Response
Triggered when our company surfaces in a Darkmon ransomware mention. Verifies the match, opens a war-room channel via Generic Notify, pages the CISO, and prints next-step guidance for the customer's IR runbook.
- Pack
- Darkmon
- Tasks
- 6
Inputs
- CISOEmail — Mailbox to notify when this playbook fires. Replaces the orphan ${customer_domain} variable so deployments do not silently send to a non-resolving address.
- WarRoomChannel — Slack / Teams channel where SOC discussion of this ransomware victim incident happens. Defaults to