
from asi30
Collect and analyze ransomware data-leak site (DLS) posts to extract victim, group, sector and geographic trends for threat intelligence and proactive defense.
This skill provides a reproducible workflow to safely collect, parse, and analyze ransomware data-leak site (DLS) postings from public tracking feeds. It shows how to ingest victim posts (e.g. Ransomwatch), extract structured fields (group, sector, country, discovery date), compute group activity trends, assess sector/geographic risk, and produce an intelligence report with recommendations for SOCs and defenders. The materials include Python examples and analysis patterns for monthly trend aggregation, new-group detection, and sector-level risk scoring.
Use this skill when investigating a security incident potentially tied to ransomware, when building detection rules informed by active actors, or when producing periodic threat intelligence reports for executive and operational stakeholders. It's intended for security analysts, threat intel teams, and SOC engineers working in isolated research environments.
This skill contains procedural Python examples and defensive analysis guidance; it is compatible with agents or tooling that can run Python notebooks or scripts (security research assistants, code-capable agents like Copilot/Code models) and with human analyst workflows.
Ransomware leak site intelligence skill that fetches victim data from public GitHub feeds (ransomwatch), analyzes group activity trends, assesses sector/geographic risk, and generates threat intel reports. No bundled scripts — all code is inline in SKILL.md as Python examples. Well-written educational content but demo-style code rather than production tooling. Safe: uses public data sources, explicitly advises against direct DLS access.
Legitimate cybersecurity/threat-intelligence skill. Code fetches from well-known public GitHub repos (ransomwatch). No security concerns. Architecture is flat — all code embedded in SKILL.md with no scripts/ directory. Useful for SOC teams but niche audience.
nhero — Aftermarket Dispenser Network
Framework treating pill dispensers as network devices: routing, access control, scramble-indexing and confidential supply tracking for custom dispenser workflow
snix — Rust Nix Reimplementation
snix is a Rust reimplementation of Nix focused on content-addressed build stores and minimal rootfs images for lightweight VM agent runtimes.
Flox Services Guide
Practical patterns and commands for running and managing background services in Flox environments: service manifests, logging, venv handling, and common service
WASM Goblins — Capability-Secure Runtime Patterns
Technical cookbook describing capability-safe interactions between Goblins actors and verified WASM runtimes, with runtime selection guidance, syscall mappings,
Performing Container Escape Detection
Audit Kubernetes pods to detect container escape vectors like privileged containers, dangerous capabilities, host namespace sharing, writable hostPath mounts, a
Condensed Mathematics (Scholze-Clausen)
Implements the Scholze-Clausen framework for combining topology with algebra using condensed sets and liquid/solid modules.
Immutable Backup with Restic
Implements ransomware-resistant backup strategies using Restic with S3-compatible object locking for tamper-proof data protection.
Phyllotaxis Growth Simulation
Models spiral leaf arrangement as a propagator network where the golden angle emerges as a Nash equilibrium.
Local K8s with KIND
Automates the installation and setup of local Kubernetes clusters using KIND (Kubernetes IN Docker) and kubectl.
Domain Name Brainstormer
Generates creative, brandable domain names for projects and checks availability across a wide range of TLDs.