Reliability graded per NATO Admiralty Code (A=best, F=unassessed). Risk level indicates how much corroboration is recommended before acting on data from each source.
BRansomlook - Leak-site scraping - ransomware group onion postsOnly claims posted to leak sites
low Bransomware.live PRO - Authenticated API - ransom notes, negotiation logs, victim claims
low Bcti.fyi - Leak-site post tracker - victim claims with .onion screenshotsOnly claims posted to leak sites
low CX / FalconFeeds + DailyDarkWeb - Ransomware + breach claims parsed from threat-intel X posts (free text)Heuristic extraction from prose - lower precision; unverified actor claims
medium ACISA KEV - Known Exploited Vulnerabilities - authoritative US govt
low ANVD - National Vulnerability Database - official CVE repo
low BMalpedia - Curated malware family reference (Fraunhofer FKIE)
low AURLhaus - Confirmed malicious URLs (abuse.ch)
low AThreatFox - Confirmed malicious IOCs with context (abuse.ch)
low AMalwareBazaar - Confirmed malware samples with hashes (abuse.ch)
low BPhishTank - Crowdsourced phishing verification
low BOpenPhish - Curated commercial phishing feed
low BCert Spotter / crt.sh - Certificate Transparency log search
low CHudson Rock - Infostealer victim dataOnly infostealer-compromised machines
moderate CLeakCheck - Breach database aggregator
moderate CXposedOrNot - Breach aggregation service
moderate CIPsum - Consensus-scored malicious IPs from 3+ lists
moderate CCINS Army - Active malicious IP list
moderate CBitwire IP Blocklist - IP blocklist
moderate CMyThreatIntel - Commercial CTI platform
moderate CAbuseIPDB - Crowdsourced IP reputation
moderate CAlienVault OTX - Open Threat Exchange pulses
moderate BVirusTotal - Multi-engine file scanner
low DTelegram Cybersec - Public Telegram channels - IOC drops, leak announcementsQuality varies by channel
high DTelegram Leak Monitor - Auto-scanned Telegram for leaksScanner heuristics produce false positives
high DReddit Cybersec - 16 cybersec subredditsDiscussion may include unsubstantiated claims
high DX/Twitter Cybersec - Researcher tweets & IOC drops
high DBluesky Cybersec - Researcher posts (smaller community)
high FAI Copilot Analysis - LLM-generated assessmentMay hallucinate attribution or IOCs
critical EActor DNA Analysis - AI-driven actor profilingPattern-matching may produce false associations
high EHeuristic CVE→Actor - Keyword-based CVE→actor matchingMatches may be coincidental
high FPredictive Intel - Forward-looking pattern extrapolationNovel TTPs not covered
critical