fastfire / deepdarkCTI

Collection of Cyber Threat Intelligence sources from the deep and dark web
GNU General Public License v3.0
4.47k stars 783 forks source link

Discussion on ransomware_groups.md #740

Open idarlund opened 2 weeks ago

idarlund commented 2 weeks ago

When cleaning up ransomware markdown file (https://github.com/fastfire/deepdarkCTI/pull/739) I discovered that someone (in 2022, commit id ef005e80c7fe32adc2739ede3a606183c6f911fa) added a threat intel company to it.

In my pull request I comment; "we should also have a discussion on what we want in this file; in my opinion this file should contain URLs to the ransomware threat actors and maybe other publicly available lists on these threat actors. what it should not contain in my opinion is "disguised marketing" for threat intel companies such as eCrime Services and others."

I propose that we do that in this issue.

fastfire commented 1 week ago

@idarlund I agree with what you said. There are 2 options: either we put the services/platforms in the file https://github.com/fastfire/deepdarkCTI/blob/main/others.md, or we create a new file calling it products/services or something like that. I propose to discuss this in the Telegram channel.