https://store-images.s-microsoft.com/image/apps.6473.8be34d7f-e578-4705-ab93-ea5f7ec9571b.f088a117-f5df-4e9a-97fe-8ff44aba6a87.544a2880-642c-4f5f-a741-f2368381252f

Ransomware Kill Chain Investigator Agent

adaQuest

Ransomware Kill Chain Investigator Agent

adaQuest

Automated ransomware triage with user/device/IOC enrichment and guided response.

The Ransomware Kill Chain Investigator (RKCI) is a purpose-built Security Copilot Agent that automates the investigation and response of Microsoft Defender ransomware incidents. By combining incident ingestion with enrichment from Entra ID, Intune, and Microsoft Threat Intelligence (DTI), RKCI transforms noisy alerts into a single, high-signal narrative.
https://store-images.s-microsoft.com/image/apps.1553.8be34d7f-e578-4705-ab93-ea5f7ec9571b.f088a117-f5df-4e9a-97fe-8ff44aba6a87.17346ee6-bb24-4a3e-8a36-5225bfbd376b
https://store-images.s-microsoft.com/image/apps.1553.8be34d7f-e578-4705-ab93-ea5f7ec9571b.f088a117-f5df-4e9a-97fe-8ff44aba6a87.17346ee6-bb24-4a3e-8a36-5225bfbd376b