{"id":14153704,"url":"https://github.com/BushidoUK/Ransomware-Tool-Matrix","last_synced_at":"2025-08-05T23:31:03.385Z","repository":{"id":253332850,"uuid":"841610118","full_name":"BushidoUK/Ransomware-Tool-Matrix","owner":"BushidoUK","description":"A resource containing all the tools each ransomware gangs uses","archived":false,"fork":false,"pushed_at":"2024-10-29T10:09:21.000Z","size":607,"stargazers_count":717,"open_issues_count":0,"forks_count":75,"subscribers_count":21,"default_branch":"main","last_synced_at":"2024-10-29T12:13:14.127Z","etag":null,"topics":["cti","cybersecurity","detection-engineering","hacking","osint","ransomware","threat-hunting","threat-intelligence","threatintel"],"latest_commit_sha":null,"homepage":"https://blog.bushidotoken.net/2024/08/the-ransomware-tool-matrix.html","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/BushidoUK.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-08-12T18:48:51.000Z","updated_at":"2024-10-29T10:09:25.000Z","dependencies_parsed_at":"2024-08-16T02:31:23.904Z","dependency_job_id":"8d2dc410-82b5-46bd-8a43-333a65423bf0","html_url":"https://github.com/BushidoUK/Ransomware-Tool-Matrix","commit_stats":null,"previous_names":["bushidouk/ransomware-tool-matrix"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BushidoUK%2FRansomware-Tool-Matrix","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BushidoUK%2FRansomware-Tool-Matrix/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BushidoUK%2FRansomware-Tool-Matrix/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BushidoUK%2FRansomware-Tool-Matrix/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/BushidoUK","download_url":"https://codeload.github.com/BushidoUK/Ransomware-Tool-Matrix/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":228815251,"owners_count":17976278,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cti","cybersecurity","detection-engineering","hacking","osint","ransomware","threat-hunting","threat-intelligence","threatintel"],"created_at":"2024-08-17T07:00:55.445Z","updated_at":"2025-08-05T23:31:03.369Z","avatar_url":"https://github.com/BushidoUK.png","language":null,"funding_links":[],"categories":["Others","🔭  Observing Ransomware Groups and Attacks","Other Lists"],"sub_categories":["✨  Other","📊 TI TTP/Framework/Model/Trackers"],"readme":"\u003cimg src=\"https://github.com/user-attachments/assets/a87d0c2c-e115-4dba-a128-ae19899d25f2\" width=\"350\" /\u003e\n\n# Ransomware Tool Matrix\n- This repository contains a list of which tools each ransomware gang or extortionist gang uses\n- As defenders, we should exploit the fact that many of the tools used by these cybercriminals are often reused\n- We can threat hunt, deploy detections, and block these tools to eliminate the ability of adversaries to launch intrusions\n- This project will be updated as additional intelligence on ransomware gang TTPs is made available\n- Feel free to watch my presentation on this project at [BSides London](https://www.youtube.com/watch?v=hyoOhAoaX1g) in December 2024.\n\n\u003e [!TIP]\n\u003e  This Ransomware Tool Matrix has several use cases, which are as follows:\n\u003e - As a list of leads for threat hunting inside the environments available to you\n\u003e - As a list of leads to look for during incident response engagements\n\u003e - As a checklist of tools to identify patterns of behaviour between certain ransomware affiliates\n\u003e - As an adversary emulation resource for threat intelligence-led purple team engagements\n\n## Ransomware Tool Matrix\n- [RMM Tools](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/Tools/RMM-Tools.md)\n- [Exfiltration Tools](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/Tools/Exfiltration.md)\n- [Credential Theft Tools](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/Tools/CredentialTheft.md)\n- [Defense Evasion Tools](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/Tools/DefenseEvasion.md)\n- [Networking Tools](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/Tools/Networking.md)\n- [Discovery Tools](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/Tools/DiscoveryEnum.md)\n- [Offensive Security Tools](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/Tools/Offsec.md)\n- [Living-off-the-Land Binaries and Scripts](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/Tools/LOLBAS.md)\n\n## Threat Intel Sources\n- [List of CISA's Threat Groups](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/ThreatIntel/CISAThreatGroups.md)\n- [List of The DFIR Report's Threat Groups](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/ThreatIntel/TheDFIRReportGroups.md)\n- [List of Trend Micro's Threat Groups](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/ThreatIntel/TrendMicroThreatGroups.md)\n- [Common TTPs of the Modern Ransomware Groups by Kaspersky](https://go.kaspersky.com/rs/802-IJN-240/images/Common-TTPs-of-the-modern-ransomware_low-res.pdf)\n- [The Conti Playbook](https://blog.talosintelligence.com/conti-leak-translation/)\n- [The Bassterlord Networking Manual](https://ecirtam.net/autoblogs/autoblogs/wwwecirtamnetlinks_0241ee9d15822b0727e62c15c61de467d47742f3/media/eb33778a.2021-08-3120-20Bassterlord20FishEye20Networking20Manual20X.pdf)\n- [Extra Threat Intel](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/ThreatIntel/ExtraThreatIntel.md)\n\n## Additional Resources\n- [List of Tools used by +10 Ransomware Gangs](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/Tools/MostUsedTools.md)\n- [List of Ransomware Group Profiles](https://github.com/BushidoUK/Ransomware-Tool-Matrix/tree/main/GroupProfiles)\n- [List of All Tools by Type](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/Tools/AllTools.csv)\n- [Ransomware Tool Matrix Threat Hunt Checklist](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/RTM_ThreatHunt_Checklist.csv)\n\n## Types of Ransomware Adversaries\n\u003e [!TIP]\n\u003e This repo also contains multiple types of Ransomware adversaries, this includes the ransomware gangs themselves, affiliates, and initial access brokers\n\u003e - **Ransomware Gangs:** In this repo, a tool is associated with a ransomware gang, meaning that the tool was observed in an intrusion which resulted in the deployment of that ransomware family\n\u003e - **Affiliates:** A threat group in this repo with an asterisk at the end (e.g. Scattered Spider*), means it is a ransomware affiliate, which has access to one or more ransomware families\n\u003e - **Initial Access Brokers:** A threat group in this repo with an asterisk at the start (e.g. *Prophet Spider), means it is an Initial Access Broker (IAB), which sells access to one or more ransomware gangs\n\u003e - **State-sponsored:** A threat group in this repo with a plus sign at the end (e.g. DarkBit+), means it is a suspected state-sponosored adversary using ransomware, such as those from Iran, DPRK, Russia, or China\n\n## Challenges\n\u003e [!IMPORTANT]\n\u003e Using the Ransomware Tool Matrix comes with its own challenges. While it is undoubtedly useful to have a list of tools commonly used by ransomware gangs to hunt, detect, and block, there are some risks.\n\u003e - Many of the tools referenced in this repository may be currently used by your IT team or even your Cybersecurity team.\n\u003e - When hunting for these tools, you may uncover many installations of them inside your environment.\n\u003e - Deciphering whether a tool is being used legitimately, by an employee, with permission is difficult in a large or global environment.\n\u003e - If you create a detection rule, you may generate a large amount of alerts, which may get ignore or turned off without investigating them.\n\u003e - If you block these tools without investigating for legitimate usage, you may cause disruption to legitimate business operations and potentially impose costs on your own organisation.\n\n#### How To Contribute\n- Please see the following [guidelines](https://github.com/BushidoUK/Ransomware-Tool-Matrix/blob/main/HowToContribute.md) to contribute to this repo.\n\n#### Integrations\n- [Ransomware.live](https://x.com/JMousqueton/status/1824434279251665259)\n- [eCrime.ch](https://x.com/ecrime_ch/status/1824469830613021070)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FBushidoUK%2FRansomware-Tool-Matrix","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FBushidoUK%2FRansomware-Tool-Matrix","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FBushidoUK%2FRansomware-Tool-Matrix/lists"}