Liberty91

Ransomware.live module.

Last updated 10 Aug 20263 min read

Ransomware.live aggregates the victim claims that ransomware groups publish on their own leak sites. The module polls that data and turns each claim into an Event in your feed, titled <group> claims <victim>, which then flows into the Threat Event layer exactly like news coverage, FalconFeeds posts, or Group-IB reporting. It is a source of reporting rather than an enrichment provider, so it adds occurrences to your feed rather than context to your indicators.

There is no API key to find. Liberty91 holds the licence, so the only decision you make is whether the feed is on.

What a victim claim is, and what it is not

A leak-site post is the attacker's own assertion that they compromised a named organization. It is unverified by definition. Groups have every incentive to exaggerate, and they have been known to recycle an old breach, name a company they only reached through a supplier, or get the name wrong outright. Nothing about a claim appearing in your feed means the breach happened as described.

Liberty91 grades ransomware.live at Admiralty reliability B, usually reliable. Read that carefully: the grade says the aggregator faithfully reports what the leak site published, not that the claim is true. Reliability belongs to the source and credibility belongs to the occurrence, which is exactly the distinction Source reliability, credibility, and confidence draws. A claim carried only by a leak-site post therefore arrives well-sourced and poorly-corroborated at the same time, and the platform shows both. Alerts generated from these claims carry the words UNVERIFIED leak-site CLAIM. for the same reason.

Treat a claim as a prompt to go and check, and let corroboration from other reporting do the rest.

Turning the feed on or off

  1. Go to Modules, open the Collection Modules section, and click the Ransomware.live tile.
  2. Use the Feed enabled switch. Its description reads "Receive ransomware.live victim claims as Threat Events for your billing account."
  3. Click Update.

The feed is on by default for every billing account, so there is nothing to do unless you want it off. The module page shows Victim claims ingested as a running total and Last polled as the time of the most recent collection run, which together tell you whether the feed is healthy.

Where the claims show up

Claims travel the same paths as every other piece of reporting:

  • The Recent Threats dashboard, chronologically, as new Events arrive.
  • The Threat Event layer, deduplicated against other reporting about the same incident. Where a news outlet later covers the same breach, the claim and the coverage read as one occurrence with two sources rather than two items.
  • Search, so you can pull claims alongside everything else you are tracking.
  • Alert rules, which match leak-site claims the same way they match any other reporting. See Set up automatic alerting.

Getting alerted when a claim names you or a supplier

Alongside ordinary alert rules there is a dedicated setting that watches victim domains rather than search criteria. It fires the moment a claim names a domain belonging to one of your suppliers, your tracked assets, an organization you follow, or your own billing account. It is configured separately, in billing account settings, and it needs an Owner or Admin. Configure ransomware domain alerts walks through the toggles, the destinations, and the matching limits.

Frequently asked questions

Do I need an API key for Ransomware.live?

No. Liberty91 holds the licence, so the only choice you make is whether the feed is on. It is on by default for every billing account.

Does a victim claim mean the company was definitely breached?

No. A leak-site post is the attacker's own claim about a victim. Liberty91 grades ransomware.live as usually reliable because it reports leak-site posts faithfully, which is a judgement about the aggregator rather than about the truth of the claim.

How do I get told when a claim names a domain I care about?

Turn on ransomware domain alerts in your billing account settings. They match victim domains against your suppliers, assets, tracked organizations, and your own domains.

Was this page helpful?