Back to blog

Blog Post

Get to know the Ransomware File Explorer

Share on social

Jan 22, 2026

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Get to know the Ransomware File Explorer

[Ransomware File Explorer]

Detect when your files are exposed in undisclosed ransomware attacks. This feature lets you search and set alerts for keywords found in the file names within unpacked file trees.

Contact sales

The Ransomware File Explorer securely downloads and indexes ransomware leak-site file-tree data into Cerberus. This enables pre-emptive detection of compromised files, accelerating your incident response even when your organization is not the primary victim.

Key benefits

  • Save time identifying and accessing file trees on leak sites
  • Pre-emptively detect leaked PII & intellectual property
  • Prevent operational, legal, or reputational damage

Saving security and investigation teams time

Although leak data is publicly accessible, obtaining and processing the file-tree structures and data behind them is highly time-consuming. Searchlight automatically gathers and indexes this information, making it searchable forever — even if the file-tree is later deleted from the dark web.

"Before Searchlight, we had to manually identify the source and review ransomware files to check if we were mentioned. This process can take hours, and sometimes the files are removed before we can analyze them."
— Managing Director, Enterprise Organization

How it works

Within the victim search tab in the Ransomware Search and Insights Dashboard, Searchlighters can now search and set alerts to identify file names that may contain sensitive documents, files, and intellectual property belonging to your organization that have been leaked, ranging from roadmaps and financial reports to PII. Keyword search also enables alerting on organization-specific variables, for example:

  • Finance Report Searchlight Cyber 2025
  • Finance Report SL Cyber 2025
  • Finance Report SLC 2025

Early success stories

Although this feature has only just been released to Searchlighters, during testing, our Threat Intelligence team was able to use the Ransomware File Explorer to identify a database containing over 300GB of personal data records belonging to a major sportswear manufacturer, and preemptively alert them to this potential breach.

Bio

Alex Blackman is the Head of Product Marketing at Searchlight Cyber, where he leads the go-to-market strategy for the company’s Preemptive Threat Exposure Management suite. With over a decade of experience serving global brands like Unilever and Allianz, Alex focuses on bridging the gap between deep technical intelligence and strategic business value. He is the voice behind Searchlight’s webinar series, helping MSSPs, enterprises, and public sector organizations identify threats before they become attacks.

Alex Blackman

Author

Alex Blackman

Head of Product Marketing at Searchlight Cyber

Alex Blackman leads product marketing at Searchlight Cyber, where he's responsible for taking the company's Preemptive Threat Exposure Management platform to market. Before joining Searchlight, Alex worked with global brands including Unilever and Allianz. He runs Searchlight's webinar programme and spends most of his time helping security teams understand why preemptive beats reactive and how that works in the Searchlight platform.

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient