Back to blog

Blog Post

Get to know the Ransomware File Explorer

Share on social

Jan 22, 2026

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Get to know the Ransomware File Explorer

[Ransomware File Explorer]

Detect when your files are exposed in undisclosed ransomware attacks. This feature lets you search and set alerts for keywords found in the file names within unpacked file trees.

Contact sales

The Ransomware File Explorer securely downloads and indexes ransomware leak-site file-tree data into Searchlight Threat – Investigate. This enables pre-emptive detection of compromised files, accelerating your incident response even when your organization is not the primary victim.

Key benefits

  • Save time identifying and accessing file trees on leak sites
  • Pre-emptively detect leaked PII & intellectual property
  • Prevent operational, legal, or reputational damage

Saving security and investigation teams time

Although leak data is publicly accessible, obtaining and processing the file-tree structures and data behind them is highly time-consuming. Searchlight automatically gathers and indexes this information, making it searchable forever — even if the file-tree is later deleted from the dark web.

"Before Searchlight, we had to manually identify the source and review ransomware files to check if we were mentioned. This process can take hours, and sometimes the files are removed before we can analyze them."
— Managing Director, Enterprise Organization

How it works

Within the victim search tab in the Ransomware Search and Insights Dashboard, Searchlighters can now search and set alerts to identify file names that may contain sensitive documents, files, and intellectual property belonging to your organization that have been leaked, ranging from roadmaps and financial reports to PII. Keyword search also enables alerting on organization-specific variables, for example:

  • Finance Report Searchlight Cyber 2025
  • Finance Report SL Cyber 2025
  • Finance Report SLC 2025

Early success stories

Although this feature has only just been released to Searchlighters, during testing, our Threat Intelligence team was able to use the Ransomware File Explorer to identify a database containing over 300GB of personal data records belonging to a major sportswear manufacturer, and preemptively alert them to this potential breach.

Download Ransomware File Trees

[Updated August 2026]

We are pleased to share that Ransomware File Trees are now downloadable, enabling threat intelligence teams to export data for deeper analysis and integration into other systems for automated remediation. To export, click the "Download File Tree" button on any file tree viewer page – zipped files will appear in your export notification and exports page.

Alex Blackman

Author

Alex Blackman

Head of Product Marketing at Searchlight Cyber

Alex Blackman leads product marketing at Searchlight Cyber, where he's responsible for taking the company's Preemptive Threat Exposure Management platform to market. Before joining Searchlight, Alex worked with global brands including Unilever and Allianz. He runs Searchlight's webinar programme and spends most of his time helping security teams understand why preemptive beats reactive and how that works in the Searchlight platform.

Related Blog Posts

September 17, 2026

Beacon: AI agents being tested by OpenAI involved in cyber-attack on another service, say researchers

September 16, 2026

How AI Is Collapsing Exploitation Timelines

September 15, 2026

Faster Leaked Credential Search with a rebuilt experience

September 10, 2026

Beacon: Searchlight Researchers Uncover JavaScript Sandbox Flaw Enabling RCE in Zendesk and Nuclei

September 3, 2026

Beacon: FulcrumSec Claims Responsibility for Manchester Airport Group Breach

September 1, 2026

Searchlight Threat + RST Cloud: Instant insights from 1,000s of threat reports

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient