CTI

This page will serve as a curated list of helpful CTI (Cyber Threat Intelligence) resources in relation to Ransomware and Advanced Persistent Threats (APTs).

Ransomware

CTI SourceDescription
#StopRansomware | CISAJoint project between CISA, FBI, NSA, MS-ISAC and JRTF which consists of a one-stop resource with best practices and ways to prevent, protect and/or respond to a ransomware attack.
CovewareLearn more about ransomware trends through Coveware's quarterly ransomware reports.
CrowdStrikeCrowdStrike's global threat landscape. All RaaS (Ransomware as a Service) threat actor groups are listed inside of the eCrime section.
DFIR Ransomware ProjectThe DFIR Ransomware Project helps digital forensic examiners, SOC analysts, and incident responders understand various types of ransomware.
HalcyonHalcyon's power rankings on the latest RaaS (Ransomware as a Service) groups.
MicrosoftMicrosoft's new method of naming RaaS (Ransomware as a Service) threat actor groups. The relevant groups will be noted in the table as financially motivated. (Microsoft Threat Actor Naming Mapping).
Palo Alto Networks Unit 42Palo Alto Networks Unit 42's threat research center on Ransomware.
Ransomware.LiveFree resource for comprehensive information and updates on the ever-evolving landscape of ransomware along with providing the latest insights, analysis, and news related to ransomware attacks, trends, and defense strategies.
Ransomware Tool MatrixA resource containing all the tools each ransomware gangs uses.
RansomwatchRansomwatch trails the extortion sites used by ransomware groups and surfaces an aggregated feed of claims (Github Page).
The DFIR ReportRansomware articles produced by The DFIR Report - Real Intrusions by Real Attackers, The Truth Behind the Intrusion.
Trend MicroTrend Micro's Ransomware Spotlight provides threat intelligence on the most notorious ransomware families used in threat actor campaigns.
WorldWatch Ransomware EcosystemGlobal CERT Orange CyberDefense - World Watch team's ransomware ecosystem map.

Advanced Persistent Threats (APTs)

CTI SourceDescription
CISACISA's naming of nation-state cyber actors.
CrowdStrikeCrowdStrike's global threat landscape. All nation-state groups are listed outside of the eCrime section.
MandiantMandiant's naming of advanced persistent threat (APT) groups.
MicrosoftMicrosoft's new method of naming nation-state threat actor groups. The relevant groups will be noted in the table as Nation-state. (Microsoft Threat Actor Naming Mapping).
Palo Alto Networks Unit 42Palo Alto Networks Unit 42's threat research center on nation-state threat actor groups.
Russian APT Tool MatrixA tool matrix for Russian APTs based on the Ransomware Tool Matrix.