Install
$ agentstack add skill-liberty91ltd-cti-skills-lookup-ransomwarelive ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
lookup-ransomwarelive
Queries ransomware.live's PRO API for victim claims, group profiles, IOCs, YARA rules, ransom notes, negotiation chats, and CSIRT contacts. Retrieval only — the invoking skill or agent reasons about the result. Note that leak-site claims are claims, not confirmed breaches (see Source reliability below).
When to invoke
- An investigated domain or organisation should be checked against ransomware leak-site claims
- Profiling a ransomware group — pull description, TTPs, tools, vulnerabilities, leak-site
.onioninfrastructure - Sector- or country-level ransomware briefing (e.g., "all NL victims claimed in 2026")
- Detection engineering for a specific group — fetch its public YARA rules + IOC dump
- Updating the
/ransomware-ecosystemknowledge cell with the current top-N groups by victim count - Incident response: looking up a country's CSIRT/CERT contact list
Do NOT invoke for:
- General malware classification — use
/lookup-virustotal - Confirming whether a specific incident actually occurred — leak-site claims are unverified by default
- Initial-access vector intelligence — that's not on leak sites; chain
/initial-access-brokersinstead
How to invoke
Single Python CLI (stdlib only — no install).
Sanity checks
python3 tools/clis/ransomwarelive.py validate # check the API key
python3 tools/clis/ransomwarelive.py stats # global totals
Victim lookups
# Free-text search across victim names + descriptions
python3 tools/clis/ransomwarelive.py search --q "acme corp"
# Targeted filters (combine freely)
python3 tools/clis/ransomwarelive.py search --country NL --limit 10
python3 tools/clis/ransomwarelive.py search --sector Healthcare --country US
python3 tools/clis/ransomwarelive.py search --group lockbit3 --limit 5
# Last 100 claims globally (newest first)
python3 tools/clis/ransomwarelive.py recent --limit 20
# Single victim detail by ransomware.live id
python3 tools/clis/ransomwarelive.py victim "QksgR3JvdXBAYWtpcmE="
Group intelligence
# All 330+ groups, sorted by victim count
python3 tools/clis/ransomwarelive.py groups --limit 20
# Profile of a specific group — description, TTPs, tools, leak-site URLs, etc.
python3 tools/clis/ransomwarelive.py group-profile lockbit3
# Lighter group detail
python3 tools/clis/ransomwarelive.py group lockbit3
Defensive intel
# IOC dump (md5, ip, etc.) — all groups
python3 tools/clis/ransomwarelive.py iocs
# Per-group IOCs
python3 tools/clis/ransomwarelive.py iocs lockbit3
# YARA rules — all groups, or per group
python3 tools/clis/ransomwarelive.py yara
python3 tools/clis/ransomwarelive.py yara lockbit3 # full rule content
# Ransom note samples
python3 tools/clis/ransomwarelive.py ransomnotes lockbit3
# Negotiation chat logs (if available for that group)
python3 tools/clis/ransomwarelive.py negotiations lockbit3
Context
python3 tools/clis/ransomwarelive.py press # recent press mentions
python3 tools/clis/ransomwarelive.py press --all # full archive
python3 tools/clis/ransomwarelive.py sectors # valid sector filter values
python3 tools/clis/ransomwarelive.py csirt NL # CSIRT contacts for a country
All commands accept --dry-run (preview the request without spending quota) and --insecure (TLS bypass — rarely needed). The CLI exits 2 if RANSOMWARE_LIVE is unset (not in dry-run); report missing key, do not fabricate.
Quota
PRO tier: 3,000 calls/day with burst allowed. Each subcommand is one HTTP call. Use --dry-run if scoping a batch.
Pivots
- From
/domain-investigationor/ip-investigation→search --qto check if the domain's owner has been claimed - From
/ransomware-ecosystemknowledge cell →groups --limit 30for current top-N +group-profilefor each - From
/threat-actor-profiling(ransomware group target) →group-profileis the primary feed; chainiocs,yara,negotiationsfor depth - From
/sigma-writing//yara-writing→yarareturns existing community rules to start from - Country-scoped briefing →
search --country, thencsirtfor IR contact list
Response format
Read commands return:
source: ransomware.live
operation: search | recent | victim | groups | group-profile | iocs | yara | ...
query_time:
data:
For search and recent, data.victims[] is normalised to:
id:
title:
group:
country:
sector:
discovered:
published:
description:
website:
post_url:
permalink:
screenshot:
Source reliability (Admiralty default)
Default for /score-source: B2 (usually reliable, probably true).
Important credibility nuance:
| Field | Credibility | Why | |---|---|---| | Victim name, country, sector, dates, group attribution | 2 (probably true) | Corroborated by the leak-site post itself | | Breach description | 3–4 (possibly true → doubtful) | Written by criminals to coerce payment; routinely overstates volume/sensitivity/ongoing access | | YARA rules, IOC lists | 2 (probably true) | Sourced from public researchers; cross-check before deploying |
A leak-site claim is a claim, not a confirmed breach. Many victims dispute or never publicly acknowledge. Some posts repackage older breaches under a new brand. Always frame downstream products with this caveat.
Operational notes
- Server returns full result sets, not pages.
search --country UShits the API once and returns ~8k victims.--limit Ntrims locally — narrow with filters (--group,--sector,--country) to keep responses small. group_nameis sometimes null in/victims/recentresponses — known API quirk; the value populates correctly insearchandvictimdetail.- The
descriptionfield can contain victim PII or stolen credentials — quote selectively in finished products; don't paste full responses into shared docs. - PRO endpoint is
api-pro.ransomware.live. The free unauthenticated endpoint (api.ransomware.live, 1 req/min) is not supported by this CLI.
Related skills
/ransomware-ecosystem— knowledge cell consuminggroups+group-profiledata/threat-actor-profiling— for ransomware-group profiles, thegroup-profileendpoint is the primary feed/yara-writing,/sigma-writing— start fromyaraoutput/lookup-virustotal,/lookup-otx— chain after pulling group IOCs to verify hashes/domain-investigation— pivots intosearch --qfor victim-status check/initial-access-brokers— complementary; ransomware.live doesn't track IAB activity/score-source,/apply-tlp,/confidence-language— apply rigor before publishing
See also
- Integration setup:
tools/integrations/ransomwarelive.md - Python CLI source:
tools/clis/ransomwarelive.py - API docs: https://api-pro.ransomware.live/docs
- Project: https://www.ransomware.live/
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Liberty91LTD
- Source: Liberty91LTD/cti-skills
- License: MIT
- Homepage: https://liberty91.com/cti-skills
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.