get_group
Retrieve a full intelligence profile for a ransomware group, covering background, activity dates, victim count, leak-site URLs, MITRE ATT&CK techniques, exploited CVEs, tools, and negotiation/ransom note flags.
Instructions
Get a full intelligence profile for one ransomware group.
Includes background description, first/last seen dates, victim count, known leak-site URLs (Tor and clearweb), MITRE ATT&CK TTPs, exploited CVEs with CVSS scores, tools and malware used, and flags for whether negotiation chats and ransom notes are on file.
Args: group_name: Group name, case-insensitive (e.g. "lockbit3", "blackcat", "clop").
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| group_name | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||