04:12. Someone in Accounts opened an invoice attachment. The payload is already running, and it is spreading across your file share while you read this sentence. Nothing here waits for you. Find the process, kill it, cut its road, get your data back.
A safe, fictional simulation — nothing on your machine is touched. The mechanics mirror how real ransomware behaves: unsigned binaries in AppData, SMB worming, shadow-copy deletion and backup vaults targeted first.
The estate panel is live. Click any machine to select it, then use Isolate to drop it off the network or Restore to rebuild it from backup.
Processes run in the right-hand table. One of them does not belong — wrong name, wrong directory, wrong command line. Hit kill on it. Kill the wrong one and your users go offline.
isolate FS-SHARE-01, kill 7731, share off, restore WS-ACCT-02, status. Type help for the full list.