Threat intel analyst tracking adversaries where they operate β from intrusion tooling and MITRE ATT&CK TTPs to ransom notes and negotiation chats.
I break things to understand how they work. Sometimes they talk back.
Repository of a threat intel analyst who tries to help the world be a better place...
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β THREAT ACTORS Β· RANSOMWARE Β· MITRE ATT&CK Β· DFIR β
β IoCs Β· CVEs Β· Behavioral CTI Β· Extortion Lifecycle β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
|
Threat Actors Profiles, history & trajectory |
Ransomware Groups, affiliates & extortion |
MITRE ATT&CK TTP mapping & kill chain |
DFIR / CTI Commands, artifacts & IoCs |
ποΈ ThreatActors-TTPs
Open-source knowledge base mapping Tactics, Techniques & Procedures of ransomware operators and threat actors β aligned with MITRE ATT&CK, including group history, exploited CVEs, commands, tools, and artifact locations.
Used by projects like RANSOMWARE.LIVE and the wider CTI community.
π¬ RansomDialect
Behavioral CTI profiles of ransomware negotiation chats β how each threat actor talks, pressures, and closes deals. 25 actor profiles derived from Ransomchats, cross-referenced with ThreatLabz, RTM, and ThreatActors-TTPs.
T-7d β T-1h T+0 T+N
RTM + crocodyli β ThreatLabz β RansomDialect
(intrusion/hunt) (ransom note) (negotiation chat)
π§π· BR-Forum-CSIRTs
Analytics, tools, and automation from CSIRT Forum presentations (2023β2024). Insights on malware operations, IoCs, TTPs, and sandboxing β bridging the Brazilian security community with practical CTI resources.
Contributions are always welcome β whether it's a new TTP mapping, a CVE reference, or a negotiation profile.
| Project | How to contribute |
|---|---|
| ThreatActors-TTPs | Open an issue or PR with actor profiles, TTPs, or CVE data |
| RansomDialect | Help expand behavioral profiles and cross-references |
| BR-Forum-CSIRTs | Share tools and techniques from the community |
