A curated list of ransomware-related resources with a primary focus on research (rather than remediation).
- Ransomware Revealed
- Ransomware: Defending Against Digital Extortion - The O'Reilly book on ransomware
- The Ransomware Hunting Team
- The Ransomware Superhero of Normal, Illinois [ ๐พ archive ]
- Ransomware: Past, Present and Future - Cisco Talos blog post on ransomware, vintage 2016
- Do you want to play a game? Ransomware asks for high score instead of money -- about Rensenware
- Emsisoft Ransomware Decryption Tools
- Free Ransomware Decrypters | Kaspersky
- List of Decryption Tools | Heimdal Security - A long list of decryption tools
- No More Ransom
- Trend Micro Ransomware File Decryptor
- The Windows Club - A list of decryption tools
- CryptoSearch
- RansomNoteCleaner
- RAASNet
- The version above is no more: see CesarAyalaDev/RAASNet
AKA demands.
- Ransomware Notes
- Ransomware known file name ransom notes: ransomware_notes_list.csv
- Translated Conti Leaked Comms
- Ransomware Playbook - Rapid7
- Ransomware playbook (ITSM.00.099) - Canadian Centre for Cyber Security
- Ransomware Template from Counteractive
- Microsoft DART ransomware approach and best practices
- Ransomware Families - A diagram from F-Secure of ransomware families from 2012-2017.
- A timeline of major ransomware events
- The link above is
404
: see the timeline via the Wayback Machine.
- The link above is
- Ransomware Attacks Map - An interactive map of known ransomware incidents in the US
- NJCCIC - From AutoLocky to Zepto
- Ransomware Overview - A Google Sheets document shepherded by
@nyxbone
-- no longer actively updated
- Ransomfeed
- nuke86/ransomFeed on GitHub (a fork of
ransomwatch
)
- nuke86/ransomFeed on GitHub (a fork of
- Ransomlook - Notes and info on 150+ groups
- Ransomware Live
- Ransomwatch Observatory
- โจ notable projects list on
ransomwatch.telemetry.ltd
- joshhighet/ransomwatch on GitHub
- โจ notable projects list on
- Ransomware Tool Matrix - companoin blog post
- Ransomware Vulnerability Matrix
- ransomware_gang.md in
fastfire/deepdarkCTI
on GitHub
- Bleeping Computer's Ransomware Forum
- ID Ransomware
- Ransomware identification for the judicious analyst
- Ransomware Reports
- Yara rules for detecting ransomware
- /r/ransomware
- Ransomware Task Force
- Ransomware known file extensions: ransomware_extensions_list.csv
- EMPHASIS: Economical, Psychological and Societal Impact of Ransomware -- no longer actively updated, still available for reference
- Darkode - A well-produced Radiolab episode that follows a mother-daughter pair in the wake of a ransomware incident
- SANS Ransomware Summit 2022