
Jul 21, 2026
1.0.0
ThreatQ Versions >= 6.5.0
RansomLook CDF
Overview
The RansomLook CDF integration enables ThreatQ to ingest ransomware victim intelligence from the RansomLook API. The integration creates Event objects for reported incidents and automatically associates related Identity and Adversary objects, providing analysts with timely visibility into ransomware activity and the threat groups responsible.
The integration provides the following feed:
- RansomLook Victims - retrieves recently reported ransomware victim intelligence from the RansomLook API and ingests related events, victims, and associated ransomware groups into ThreatQ.
The integration ingests the following system objects:
- Adversaries
- Event Attributes
- Events
- Identities
- Identity Attributes