• Last Updated
    Jul 21, 2026
  • Version
    1.0.0
  • Compatibility
    ThreatQ Versions >= 6.5.0
  • RansomLook CDF

    ThreatQuotient

    Overview

    The RansomLook CDF integration enables ThreatQ to ingest ransomware victim intelligence from the RansomLook API. The integration creates Event objects for reported incidents and automatically associates related Identity and Adversary objects, providing analysts with timely visibility into ransomware activity and the threat groups responsible.

    The integration provides the following feed:

    • RansomLook Victims - retrieves recently reported ransomware victim intelligence from the RansomLook API and ingests related events, victims, and associated ransomware groups into ThreatQ.

    The integration ingests the following system objects:

    • Adversaries
    • Event Attributes
    • Events
    • Identities
    • Identity Attributes

    Copyright © 2026, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy