Ransomware Defence Summer Bootcamp

Student Projects

Graduate students from around the world spent five intensive days in Amsterdam building practical ransomware-defence resources for Local Community Organizations — municipalities, non-profits and SMEs that keep communities running with limited security capacity.

Built by students

Seven teams of graduate students designed, built and presented every tool on this page during the Bootcamp week at the Amsterdam Business School.

Free for communities

Each project is published openly so municipalities, non-profits and small businesses can use and adapt it at no cost. Each project is published openly so municipalities, non-profits and small businesses can use and adapt it at no cost.

From learning to practice

Turning research into resources

Working in teams, students applied what they learned to projects designed to help LCOs strengthen their ransomware defences. The projects explored different aspects of ransomware preparedness and response, from vulnerability scanning and open-source intelligence to incident-response planning, awareness tools and analysis of the ransomware ecosystem.

The aim was to translate research and technical knowledge into resources that organizations can understand, use and build upon.

Explore the student projects

Seven teams, seven approaches

This portal brings the student projects together in one place. It provides an overview of the different approaches developed during the Bootcamp and introduces the teams behind them.

Together, the projects demonstrate how technical expertise, policy thinking and accessible communication can help organizations better understand ransomware risks and take action to reduce them.

Bootcamp winner
Web app

RansomReady: Ransomware Awareness Tool

Ransomware Awareness Tool is a digital tool aimed at helping local community organizations better understand ransomware risks and take steps to reduce them. 

Called ‘RansomReady,’ the tool is an AI-enhanced ransomware preparedness platform which helps organizations assess cyber resilience. Instead of generic advice, the tool provides tailored guidance for specific operating environments. RansomReady combines a readiness assessment, structured learning modules, and interactive practice tools within a single browser-based experience accessible to non-technical teams. The goal is not a ‘one-size-fits-all’ solution. Instead, after assessments across risk areas, each organization receives a tailored preparedness pack. The personalisation is based on sector, size, score, and category-level results. Using LLM-assisted tools, these recommendations best meet organizations’ profiles and maturity levels. RansomReady can also generate customised executive-level summaries which translate technical results into clear communication for organisational leadership. This is paired with a 30-day action plan, a first-hour incident checklist, awareness guidance, and exercise material (e.g., practice games).

In sum, RansomReady combines transparent, rule-based scoring with AI-driven personalisation to help organizations understand risks and prioritise the right steps to reduce them before an incident occurs.

Team

Luca Tortoriello · Emmanuel Atwam · Gustavo Ferreira de Lima · Erika Oliveri · Nicole Bovolenta

Playbook

Ransomware Response Playbook

The Ransomware Response Playbook is a practical incident-response guide developed to help local community organizations.

It helps organizations make informed decisions during and after an incident without an in-house digital forensics team. Working with a recent case study (the Akira ransomware attack on Sib-Tryck Holding in 2025), the playbook guides an organization through the process of responding to a ransomware attack. It covers steps for detecting, analysing, containing, remediating, and recovering from a ransomware incident. The playbook further provides role-by-role checklists, guidance on ransom negotiations and payment decisions, requirements for data breach reporting, and steps to contain threats. This includes, for instance, isolating networks, resetting credentials, or removing malware.

In sum, the Ransomware Response Playbook offers vital guidance for situations in which time is limited, responsibilities may be unclear, and coordinated action is essential.

Team
Otuekong Ekpo · Rana Shafi · Nikola Nachevski · Alexanter Kapai · Caleb Price
Chatbot & guidebook

Ransomware Negotiation Simulation Chatbot

The Ransomware Negotiation Simulation Chatbot is an interactive tool that allows small and medium-sized enterprises and non-profits to explore how ransomware negotiations unfold.

Engaging with the chatbot, these organizations can learn, test, and gain hands-on insight into ransomware threats and negotiation scenarios. The chatbot exposes them to challenging decisions which they may face if they become victims of a ransomware attack. Using publicly available and ethically sourced data, the provided scenarios are based on existing ransomware negotiation transcripts (sources include Casualtek & Ransomchats archive). The chatbot also includes an ‘expert mode’ which helps interpret and rationalise response outcomes. Additionally, a performance score gives feedback on how effectively an organisation managed a simulated incident. By combining preparation with guidance, the chatbot explains how attackers might respond to different strategies.

In brief, the ransomware negotiation simulation chatbot helps users understand and make verified, coordinated decisions under pressure.

Team

Elisabeth Postigo Leoni · Sara Lilli · Maria Vittoria Zucca · Ellie Carter · Karoline Bjørvik Kulsveen · Sali Khalil

PDF guide

OSINT Guide

The Open-Source Intelligence (OSINT) Guide helps organizations discover what kind of information about them is publicly available online.
The guide introduces responsible investigation techniques and explains how exposed information can contribute to cyber risks more broadly, and to ransomware incidents specifically. Understanding how available information, for instance, employee contact details or online services, could be used for reconnaissance is critical. For instance, while open ports are not dangerous by default, poorly configured or unpatched services behind them can give attackers an easy opportunity to probe or even compromise a system. The OSINT guide foregrounds ethical principles and works with an intelligence cycle of identification, collection, processing, analysis, and dissemination. The ‘KinderRechteForum’ case illustrates how third-party data breaches can expose personal and organisational details even without a more direct, internal compromise.
Team

Azra Ocak · Elena Schörling · Parto Afshari · Ioannis Biternas · Marlene Flintrop · Quitterie Jacheet

Presentation

DIANA: Vulnerability Scanning Pipeline

The vulnerability-scanning tool, called ‘DIANA’, is a responsible vulnerability scanner that helps users find common vulnerabilities and understand their potential impact, linked to ransomware and fraud.

DIANA carefully translates every finding into plain language which, for instance, a non-technical charity organization can engage with and act on. Focusing on the Dutch local community ecosystem, this includes ‘ready-to-send’ fix emails in Dutch. The tool is innovatively built on the CERT-PL Artemis engine, with a custom detection module and a consent-first, responsible-scanning framework.

In short, the vulnerability-scanning tool translates highly technical findings into clear, actionable recommendations.

Team
Célia Joséphine Perret · Meli Imelda · Tsafac Nkombong Regine Cyrille · João Victor Figueiredo Dal Mas
GitHub repository

SafetyRoutes: Vulnerability Scanning Pipeline

The vulnerability-scanning tool called ‘SafetyRoutes’ is best thought of as a friendly health check-up for the websites of local community organizations.
SafetyRoutes can carefully check websites for common weak spots and then explain what it found in easy, non-technical language. This is key to illustrating what the problem is, why it matters, and which simple steps an organization can take to address it. Later, it checks again to confirm the fix worked, and sends a gentle reminder if anything is still open. Artemis (with Nuclei built in) checks the website, Trivy checks the packages on a server, and a threat-intelligence database called ‘MITRE Explorer’ connects software an organization runs to the security flaws known to affect it.
Team

Kelly T. · Florance de Valk · Perikles Panagouleas · Razan Ayoub

Research report

Ransomware Ecosystem Analysis Tool

The Ransomware Ecosystem Analysis Tool is a research-focused tool that brings together data on the contemporary ransomware ecosystem.
The report is tailored to best match the needs of local community organizations that rarely have a dedicated security team. It innovatively helps users explore key trends, ransomware groups, common attack techniques, and changing approaches to monetisation through evidence-based analysis and intuitive visualisations. For instance, it prioritises explaining key techniques over brand names, since rebranding is common while underlying methods often persist. Even technical detail is explained in easy language and practical implications are foregrounded throughout.
Team

Christopher Nyandoro · Amira Fathalla · Naveen Chandra Joshi · Mia Bauza Mas

Please note

These projects were created by students during the Ransomware Defence Summer Bootcamp and are hosted independently by the teams themselves. Virtual Routes does not endorse the projects and takes no responsibility for their accuracy, functionality, security or any other aspect of them. Please review and test anything you use before relying on it in your own organization.

Thank you! RSVP received for Ransomware Defence Summer Bootcamp – Student Projects

Thank you for signing up to our newsletter!

Ransomware Defence Summer Bootcamp – Student Projects

Loading...

Loading…