Skip to content
Back to the index

ransomtriage

PyPIInfrastructure

No liveness check has reached it yet; it is registered on GitHub and PyPI and has been in the index since 8 Oct 2026. How this is checked

ransomtriage is an offline, privacy-preserving command-line tool for first-hour ransomware incident response. It helps security teams identify ransomware families, extract indicators of compromise, and locate available free decryptors without uploading files or data.

Inferred · not functionally tested

Open SourceMITCLISelf-hosted
Visit PyPI

Overview

6 features

Purpose: Rapidly triaging ransomware incidents and identifying useful indicators and decryptors without uploading sensitive data.

Inferred · not functionally tested

Audience: incident responders and digital forensics teams

Inferred · not functionally tested

Functions: data_extraction

Inferred · not functionally tested

Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)

Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli, self_hosted

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: pypi.org · github.com. These links do not verify the individual claims.

ransomtriage sits in PulseGate's Malware analysis & digital forensics category. Inferred · not functionally tested: Rapidly triaging ransomware incidents and identifying useful indicators and decryptors without uploading sensitive data. Inferred · not functionally tested: It is built as an open-source project for incident responders and digital forensics teams. Basis unknown · not verified: The project is open source (MIT). Basis unknown · not verified: ransomtriage is available on the command line, and it can be self-hosted.

It is developed by redhat1032, and it first shipped in 2026. The project is developed in the open on GitHub with 3 commits in the last 90 days. Inferred · not functionally tested: Among its 6 catalogued features are ransomware identification, IOC extraction, and decryptor discovery.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • Ransomware identification
  • IOC extraction
  • Decryptor discovery
  • Offline analysis
  • Ransom-note triage
  • YARA support

Topics: Inferred · not functionally tested

Tags
ransomware-triageioc-extractiondecryptor-discoverydfiroffline-analysis

JSON profile · Text profile · Access guide

Built with & integrations

Runs on
CLISelf-hosted

Trust & compliance

License
MIT
Public signals
HTTPSOpen SourceFree tierGitHubActive maintenance

Indexing history

1

What PulseGate has recorded for this listing

  1. Indexed8 Oct · 20:57 UTC
    ransomtriage seen via PyPI Bulk Enumerator
    Source: PyPI Bulk Enumerator · Open

Frequently asked questions about ransomtriage

What does ransomtriage do?
Inferred · not functionally tested: Rapidly triaging ransomware incidents and identifying useful indicators and decryptors without uploading sensitive data. It is catalogued under Malware analysis & digital forensics on PulseGate.
Who is ransomtriage for?
Inferred · not functionally tested: ransomtriage is an open-source project built for incident responders and digital forensics teams.
Is ransomtriage free?
Basis unknown · not verified: Yes — ransomtriage is open source under the MIT license and free to use.
What platforms does ransomtriage run on?
Basis unknown · not verified: ransomtriage runs on the command line. It can also be self-hosted.
Is ransomtriage still maintained?
The GitHub repository shows 3 commits in the last 90 days.
What are alternatives to ransomtriage?
Similar projects tracked by PulseGate include TSFactory, Outguess, and MailXaminer.TSFactoryOutguessMailXaminer
Who develops ransomtriage?
ransomtriage is developed by redhat1032.
When did ransomtriage launch?
ransomtriage first shipped in 2026.

Also in Malware analysis & digital forensics

Same category — not a similarity match