🎭 Threat Actor Intelligence (ACTORINT)
Tracking Adversary Groups Over Time
Cyber & Threat
Sources
10
9 no-auth
Mission domains
5
reach
Data points
6
covered
Related INT
4
disciplines
🔌 Sources for Threat Actor Intelligence (10)
| Source | Category | Auth | Format | |
|---|---|---|---|---|
| APTnotes Public archive of APT research reports. | APT | NONE | json | home↗ api↗ |
| CFR Cyber Operations Tracker State-sponsored cyber incident tracker (public dataset). | Nation State | NONE | json | home↗ api↗ |
| ETDA Threat Group Cards APT group encyclopedia with tools and campaigns. | Nation State | NONE | json | home↗ api↗ |
| EuRepoC Cyber Conflicts European Repository of Cyber Incidents — attributed state operations. | Nation State | NONE | json | home↗ |
| MISP Galaxy Threat Actors Curated threat-actor cluster galaxy. | APT | NONE | json | home↗ api↗ |
| MITRE ATT&CK Groups (STIX) Adversary groups, software and techniques. | APT | NONE | json | home↗ api↗ |
| MITRE ATT&CK Software/Actors Adversary tooling & group knowledge base. | ACTORINT | NONE | json | home↗ api↗ |
| ORKL Threat Report Library Full-text CTI report library API. | APT | NONE | json | home↗ api↗ |
| Ransomwatch Leak Sites Ransomware leak-site post tracker. | Dark Web | NONE | json | home↗ api↗ |
| AlienVault OTX Pulses Community threat-intel pulses (free key). | Threat Analysis | KEY | json | home↗ api↗ |
🎯 Mission Domains served
🔍 Lookup
📊 Pre-built Queries · Threat Actor Intelligence
🔄 Live Datasets & APIs (8 key-free · ingestible)
📜 Playbook — Threat Actor Intelligence collection
- Direction — frame the requirement for Threat Actor Intelligence: what decision does this support, by when?
- Collection — collect from the 10 mapped sources (9 free) — filter the catalog by ACTORINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
🔗 Pivot to related disciplines
✨ Enrichment pathways
🎯 Mission
Threat Actor Intelligence tracks adversary groups, their infrastructure, tooling, and TTPs to attribute activity and anticipate targeting. It answers who is behind an intrusion, what malware and infrastructure they operate, and who they are likely to hit next.
📡 Collection methods
- Mapping observed behaviors to MITRE ATT&CK technique IDs from incident and vendor reports
- Malware sample triage and clustering (imphash, YARA, config extraction) to link tooling to actors
- Infrastructure pivoting on C2 domains, TLS certificates, JARM and JA3 fingerprints, and passive DNS
- Dark-web forum and ransomware leak-site monitoring for victims, claims, and recruitment
- Alias correlation across forums, Telegram, and jabber to link personas
- CTI feed ingestion and enrichment via MISP/OTX and abuse.ch trackers
- Diamond Model and kill-chain reconstruction of campaigns
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- MISP
- Maltego
- ATT&CK Navigator
- YARA
- Shodan
- MalwareBazaar
- Yeti
- Diamond Model
📜 Threat Actor Intelligence Tradecraft
- Collect: aggregate incident reports, leak-site posts, and MISP/OTX and abuse.ch feeds tagged to the actor set
- Process: normalize IOCs into a graph, map behaviors to ATT&CK technique IDs, and cluster samples by YARA and imphash
- Analyze: pivot infrastructure via certificates, JARM/JA3, and passive DNS to expand the actor's known footprint
- Attribute: apply the Diamond Model and alias linkage to assign activity to a named group with an explicit confidence level
- Disseminate: publish an actor profile with an ATT&CK layer, IOC list, and targeting assessment for defenders
- Act: ship detection rules and blocklists and prioritize threat hunts against the actor's signature TTPs
📊 Dashboard KPIs
Tracked actorsNew campaigns/quarterATT&CK coverageAttribution confidenceIOCs shipped
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron