# BushidoUK/Ransomware-Tool-Matrix

A resource containing all the tools each ransomware gangs uses

Repository: https://github.com/BushidoUK/Ransomware-Tool-Matrix
Canonical: https://ross.abutalabs.com/products/ransomware-tool-matrix
Homepage: https://blog.bushidotoken.net/2024/08/the-ransomware-tool-matrix.html
License: NOASSERTION
License Family: other
Topics: cti, cybersecurity, detection-engineering, hacking, osint, ransomware, threat-hunting, threat-intelligence, threatintel
Last push: 2026-07-25T17:45:22+00:00

## Health v2 (maintenance only)
Score: 65/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 94, release rhythm 35, longevity 53
- inputs: {"age_days": 751, "days_push": 39, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1434, forks 156 (observed 2026-08-28T04:04:43.366521+00:00)

## What it is
A curated knowledge base mapping the tools used by ransomware and extortion gangs, organized by category (RMM, exfiltration, credential theft, LOLBAS, etc.) and sourced from CISA advisories, The DFIR Report, and other OSINT. It is a reference resource for defenders doing threat hunting, detection engineering, and incident response.

## Use cases
- find which tools a ransomware gang uses for threat hunting
- build detections for ransomware affiliate tooling
- checklist of attacker tools during incident response
- adversary emulation scenarios for purple team exercises
- identify behavioral patterns between ransomware groups
- block tools commonly abused by ransomware operators

## When to choose
- you need an up-to-date, categorized reference of ransomware gang tooling
- you are a defender building threat hunts or detection rules
- you are planning threat-intel-led purple team engagements

## When to avoid
- you need executable software rather than a reference document
- you need automated IOC feeds or API access
- you need offensive tooling itself

## Facets
- artifact type: dataset
- maturity: active
- function: security, osint, vulnerability-scanning
- domain: security, osint
- platform: cross-platform
- tags: ransomware, threat-hunting, detection-engineering, cti, incident-response, purple-team, adversary-emulation, awesome-list, threat-intelligence

## Member repositories
- BushidoUK/Ransomware-Tool-Matrix (main) score 65

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:43.366521+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:36:53.460260+00:00, confidence not recorded.
  - readme: https://github.com/BushidoUK/Ransomware-Tool-Matrix (fetched 2026-08-28T04:04:43.366521+00:00, sha 6ce06f5ce9a6)
  - homepage: https://blog.bushidotoken.net/2024/08/the-ransomware-tool-matrix.html (fetched 2026-08-29T11:48:13.771621+00:00, sha 43113a01a83a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
