Back to the overview
Agent passport

Ransomware Kill Chain Investigator Agent

adaQuest · Cybersecurity & IT

SaaSNo attestation published

Certification per Microsoft Marketplace.

agentRansomwareCyber Kill Chain
Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 8 captures on record

User ratingNot rated0 reviews on the listing
Runs onSaaSSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

Ransomware Kill Chain Investigator (RKCI) is a security-focused, read-only ransomware investigation agent that helps organizations analyze across Microsoft Defender and Microsoft Sentinel incidents with speed and confidence. It correlates evidence across users, devices, and indicators, maps activity to the ransomware kill chain, and produces an evidence-based investigation report with prioritized response actions.

The agent is designed for SOC analysts, incident responders, and security operations leaders. It supports both direct execution and guided chat for follow-up analysis.

Show the rest of the publisher’s description (30 more lines)

Inputs (what data the agent consumes)

The agent consumes Microsoft security signals such as Microsoft Defender incident data, Microsoft Entra user and sign-in context, Threat Intelligence data for hashes, IPs, and domains, optional Microsoft Intune device posture, and targeted KQL-based hunting results for ransomware behaviors.

If some signals are unavailable due to permissions, tenant configuration, unsupported dependencies, or retention limits, the agent runs in best-effort mode and reports data gaps and confidence impact instead of failing.

Tasks (what the agent performs)

Investigates ransomware-related incidents, correlates evidence into a kill chain view, enriches users, devices, and indicators, validates hashes, domains, and IPs, runs evidence-led hunts, generates prioritized containment, eradication, and recovery guidance, and supports guided analyst interaction through chat.

Outputs (what results the agent generates)

A consolidated ransomware investigation report including:

  • executive summary
  • kill chain correlation
  • affected assets
  • indicator findings
  • prioritized response actions
  • timeline highlights
  • telemetry gap notes.

Estimated SCU consumption

Estimated consumption varies with incident complexity, entity volume, available telemetry, and required enrichment.

Expected consumption per run:

  • Low-evidence or no-confirmation cases: around 0.2 to 0.5 SCUs
  • Standard single-incident investigation: around 1 to 1.6 SCUs
  • Deeper investigations with broader enrichment and hunts: around 1.2 to 1.8 SCUs

Rule of thumb:

  • ~0.3 SCUs when no meaningful ransomware path is confirmed
  • ~1.6 SCUs for a deeper end-to-end ransomware investigation-

Version 3.3.2

Change log

  • Added proactive ransomware hunting in Microsoft Defender XDR, with or without an existing incident.
  • Improved detection, entity enrichment, evidence correlation, and MITRE ATT&CK mapping.
  • Added evidence-based confidence and coverage tracking to reduce unsupported conclusions.
  • Optimized query results and incident processing to prevent context-length errors.
  • Removed the direct Microsoft Sentinel workspace dependency and improved overall execution reliability.

Preview

4 images
Ransomware Kill Chain Investigator Agent preview 1Ransomware Kill Chain Investigator Agent preview 2Ransomware Kill Chain Investigator Agent preview 3Ransomware Kill Chain Investigator Agent preview 4

Agent build and provenance

Sign in to see the provenance.

The evidence, the layer-by-layer tracing, the risk basis, and the cross-marketplace links are open to signed-in accounts.

Sign in

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment · as of 2026-08-29

CompanyadaQuestAutomated
HQUnited States of AmericaAutomated
IndustryTechnologyAutomated
Websitehttps://www.adaquest.com/

Plans and pricing as listed

1 listed
Free Plan Offer - Default
$0.00/month
1-month subscription

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource
License TermsLicense TermsSource

Publisher resources

3 links
adaQuestRansomwareKillChainInvestigatorcatalogartifact.azureedge.netSource
RKCI Web Pagewww.adaquest.comSource
Pricing
Paid
1 plan listed
Delivery
SaaS
https://www.adaquest.com/contact-us-2/
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.