Zurück zum Ranking

A resource containing all the tools each ransomware gangs uses

cticybersecuritydetection-engineeringhackingosintransomwarethreat-huntingthreat-intelligencethreatintel
Sterne-Wachstum
Sterne
1.4k
Forks
155
Wochenwachstum
Issues
0
1k
Aug. 2024März 2025Nov. 2025Juli 2026
README

Ransomware Tool Matrix

  • This repository contains a list of which tools each ransomware gang or extortionist gang uses
  • As defenders, we should exploit the fact that many of the tools used by these cybercriminals are often reused
  • We can threat hunt, deploy detections, and block these tools to eliminate the ability of adversaries to launch intrusions
  • This project will be updated as additional intelligence on ransomware gang TTPs is made available
  • Feel free to watch my presentation on this project at BSides London in December 2024.

[!TIP] This Ransomware Tool Matrix has several use cases, which are as follows:

  • As a list of leads for threat hunting inside the environments available to you
  • As a list of leads to look for during incident response engagements
  • As a checklist of tools to identify patterns of behaviour between certain ransomware affiliates
  • As an adversary emulation resource for threat intelligence-led purple team engagements

Ransomware Tool Matrix

Threat Intel Sources

Additional Resources

Types of Ransomware Adversaries

[!TIP] This repo also contains multiple types of Ransomware adversaries, this includes the ransomware gangs themselves, affiliates, and initial access brokers

  • Ransomware Gangs: In this repo, a tool is associated with a ransomware gang, meaning that the tool was observed in an intrusion which resulted in the deployment of that ransomware family
  • Affiliates: A threat group in this repo with an asterisk at the end (e.g. Scattered Spider*), means it is a ransomware affiliate, which has access to one or more ransomware families
  • Initial Access Brokers: A threat group in this repo with an asterisk at the start (e.g. *Prophet Spider), means it is an Initial Access Broker (IAB), which sells access to one or more ransomware gangs
  • State-sponsored: A threat group in this repo with a plus sign at the end (e.g. DarkBit+), means it is a suspected state-sponosored adversary using ransomware, such as those from Iran, DPRK, Russia, or China

Challenges

[!IMPORTANT] Using the Ransomware Tool Matrix comes with its own challenges. While it is undoubtedly useful to have a list of tools commonly used by ransomware gangs to hunt, detect, and block, there are some risks.

  • Many of the tools referenced in this repository may be currently used by your IT team or even your Cybersecurity team.
  • When hunting for these tools, you may uncover many installations of them inside your environment.
  • Deciphering whether a tool is being used legitimately, by an employee, with permission is difficult in a large or global environment.
  • If you create a detection rule, you may generate a large amount of alerts, which may get ignore or turned off without investigating them.
  • If you block these tools without investigating for legitimate usage, you may cause disruption to legitimate business operations and potentially impose costs on your own organisation.

How To Contribute

  • Please see the following guidelines to contribute to this repo.

Integrations

License

  • This project is licensed under the Creative Commons Attribution 4.0 International License (CC BY 4.0).
  • You are free to share and adapt the material for any purpose, including commercial use, provided appropriate attribution is given and any modifications are indicated.
  • For the full license text, see the LICENSE file or visit: https://creativecommons.org/licenses/by/4.0/