Skip to content
View crocodyli's full-sized avatar

Block or report crocodyli

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
crocodyli/README.md
Typing SVG

X GitHub followers Profile views


🐊 About

Threat intel analyst tracking adversaries where they operate β€” from intrusion tooling and MITRE ATT&CK TTPs to ransom notes and negotiation chats.

I break things to understand how they work. Sometimes they talk back.

Repository of a threat intel analyst who tries to help the world be a better place...


🎯 Focus Areas

  β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
  β”‚  THREAT ACTORS  Β·  RANSOMWARE  Β·  MITRE ATT&CK  Β·  DFIR    β”‚
  β”‚  IoCs  Β·  CVEs  Β·  Behavioral CTI  Β·  Extortion Lifecycle  β”‚
  β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ•΅οΈ

Threat Actors
Profiles, history & trajectory

πŸ”’

Ransomware
Groups, affiliates & extortion

πŸ›‘οΈ

MITRE ATT&CK
TTP mapping & kill chain

πŸ”

DFIR / CTI
Commands, artifacts & IoCs

πŸ“‚ Featured Repositories

πŸ—‚οΈ ThreatActors-TTPs

Stars Forks

Open-source knowledge base mapping Tactics, Techniques & Procedures of ransomware operators and threat actors β€” aligned with MITRE ATT&CK, including group history, exploited CVEs, commands, tools, and artifact locations.

Used by projects like RANSOMWARE.LIVE and the wider CTI community.


πŸ’¬ RansomDialect

Stars License

Behavioral CTI profiles of ransomware negotiation chats β€” how each threat actor talks, pressures, and closes deals. 25 actor profiles derived from Ransomchats, cross-referenced with ThreatLabz, RTM, and ThreatActors-TTPs.

  T-7d β†’ T-1h          T+0              T+N
  RTM + crocodyli  β†’  ThreatLabz  β†’  RansomDialect
  (intrusion/hunt)    (ransom note)    (negotiation chat)

πŸ‡§πŸ‡· BR-Forum-CSIRTs

Language

Analytics, tools, and automation from CSIRT Forum presentations (2023–2024). Insights on malware operations, IoCs, TTPs, and sandboxing β€” bridging the Brazilian security community with practical CTI resources.


ThreatActors-TTPs RansomDialect

πŸ› οΈ Stack & Frameworks

MITRE ATT&CK Python Threat Intelligence DFIR Ransomware IoCs


πŸ“Š GitHub Stats

GitHub Stats Top Languages
Activity Graph

🀝 Collaboration

Contributions are always welcome β€” whether it's a new TTP mapping, a CVE reference, or a negotiation profile.

Project How to contribute
ThreatActors-TTPs Open an issue or PR with actor profiles, TTPs, or CVE data
RansomDialect Help expand behavioral profiles and cross-references
BR-Forum-CSIRTs Share tools and techniques from the community

πŸ“‘ Connect

X GitHub ThreatActors-TTPs


πŸ“ 127.0.0.1 Β· For research, defense, and threat intelligence only.


Built with curiosity. Maintained with purpose. 🐊

Popular repositories Loading

  1. ThreatActors-TTPs ThreatActors-TTPs Public

    Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving to other types of threats.

    407 60

  2. RansomDialect RansomDialect Public

    Behavioral CTI profiles of ransomware negotiation chats β€” how each threat actor talks, pressures, and closes deals. Based on Ransomchats.

    3

  3. BR-Forum-CSIRTs BR-Forum-CSIRTs Public

    Discover essential features of CSIRT Forum presentations on GitHub. This repository features analytics, tools, and automation techniques discussed in the 2023 and 2024 sessions. Explore in-depth in…

    Python

  4. crocodyli crocodyli Public

  5. MailScope MailScope Public

    CLI tool to audit domain email security β€” SPF, DKIM, DMARC, MTA-STS, MX & DNSSEC. Public DNS only, no external APIs. Visual scorecard included.

    Python