Claude 24f816b6a3
Consolidate 22 sibling repos into layered organism structure
Place useful parts of the surrounding repos into sica-fondt by layer, per the
body model (Ada = membrane; brain/endocrine/capabilities/knowledge non-Ada):

- brain/        LLM reasoning + providers (dapr, hermes, MoMoA)
- capabilities/ REPRAG sidecars: hermes tools/skills, dapr tools, parallel
                dispatch, A51 channels, and the OSINT cluster
- knowledge/    LORAG corpus: 754 cyber-skills, agency personas, secure-coding,
                MITRE ATT&CK data
- reference/    defensive threat-reference (C3, shhbruh doc) + AdaYaml parser

License handling: AGPL sources (worldosint, advanced_evolution, mercury,
Reticulum) and GPL DeTTECT are SPEC-only clean-room/port descriptions — no
copyleft code copied. MIT/Apache/data parts copied as working trees.

Safety: shhbruh escape/persistence material and C3 covert-C2 kept as reference
only, not wired into the running organism. See CONSOLIDATION.md.

https://claude.ai/code/session_01UehUqEXXJJCsHoA4voCU5c
2026-06-10 06:53:01 +00:00

2.3 KiB

API Reference: Ransomware Leak Site Intelligence

ransomware.live API

Recent Victims

curl https://api.ransomware.live/recentvictims

Group Information

curl https://api.ransomware.live/groups
curl https://api.ransomware.live/group/lockbit3

Response Format

{
  "group_name": "lockbit3",
  "victim": "company-name",
  "website": "company.com",
  "discovered": "2024-03-15T00:00:00Z",
  "country": "US",
  "activity": "Manufacturing"
}

ransomlook.io API

Endpoints

curl https://www.ransomlook.io/api/groups       # List all groups
curl https://www.ransomlook.io/api/group/lockbit # Group details
curl https://www.ransomlook.io/api/recent        # Recent posts

Ransomwatch (GitHub)

Data Repository

git clone https://github.com/joshhighet/ransomwatch
# Data in JSON format: posts.json, groups.json

JSON Schema

{
  "group_name": "string",
  "post_title": "string",
  "discovered": "ISO-8601",
  "post_url": "onion URL",
  "country": "2-letter code",
  "activity": "sector"
}

ID Ransomware

Identification

Upload: encrypted file + ransom note
URL: https://id-ransomware.malwarehunterteam.com/
Returns: ransomware family, decryptor availability

Active Ransomware Groups (2025)

Group Status Primary Target
LockBit 3.0 Active Cross-sector
Cl0p Active MOVEit/file transfer exploitation
Play Active Manufacturing, IT
8Base Active SMBs
Akira Active Healthcare, Education
Black Basta Active Enterprise
Medusa Active Education, Healthcare
RansomHub Active Cross-sector
Rhysida Active Government, Healthcare
BianLian Active Healthcare, Manufacturing

Intelligence Collection Framework

Source Type Update Frequency
ransomware.live Victim listings Real-time
ransomlook.io Group monitoring Daily
ransomwatch Onion site scraping Hourly
NoMoreRansom.org Decryptor availability As released
CISA alerts Government advisories As published

STIX Representation

{
  "type": "threat-actor",
  "name": "LockBit",
  "threat_actor_types": ["crime-syndicate"],
  "roles": ["agent"],
  "goals": ["financial-gain"]
}