Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ThreatActors-TTPs — Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving to other types of threats. | Kitploit
Tools/GitHubGitHub/crocodyli/threatactors-ttps
OSINT (Open Source Intelligence)Vulnerability AnalysisMalware AnalysisDigital ForensicsThreat IntelligenceLearning & EducationIncident ResponseCurated Resources
GitHubcrocodyli/threatactors-ttps

ThreatActors-TTPs

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving to other types of threats.

View Repository
4086037 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
dajsdhasjkdhas

THREAT ACTORS AND RANSOMWARES - TTPs

This repository was created with the aim of assisting companies and independent researchers in studying the Tactics, Techniques, and Procedures (TTPs), based on the MITRE ATT&CK framework, adopted by active or inactive Ransomware operators/groups and other Threat Actors.

This content includes TTP mapping, the history of activities, and the record of exploited CVEs (Common Vulnerabilities and Exposures). Furthermore, I am including data on commands, tools, and useful locations for researching artifacts in the DFIR/CTI field.

The primary focus is to offer a summary of each actor's trajectory, providing essential information that can be utilized by security organizations and individual researchers.

COLLABORATION AND DATA SHARING

This project relies on contributions from various researchers in the community. The data collected here is also intended to serve as a resource for other security projects, such as RANSOMWARE.LIVE (accessible at: https://www.ransomware.live/), fostering a wider collaboration ecosystem.


REPOSITORY STRUCTURE

FOLDERDESCRIPTION
Actor's NameDetailed profile containing: , of the group, and a list of exploited (where applicable).

Contact: https://twitter.com/crocodylii

The goal is to map all possible strategies adopted by Ransomware operators, and contributions are highly welcome!

Download Tool
TTPs (MITRE ATT&CK)
History/Trajectory
CVEs
CommandsRepository designed to insert commands captured based on DFIR and CTI activities of Threat Actors, Ransomware groups, and affiliates.
Payload locationsRepository designed to inform locations commonly used for the execution of ransomware and other threats.