Disciplines

🎭 Threat Actor Intelligence (ACTORINT)

Tracking Adversary Groups Over Time
Cyber & Threat

Sources

10
9 no-auth

Mission domains

5
reach

Data points

6
covered

Related INT

4
disciplines

🔌 Sources for Threat Actor Intelligence (10)

SourceCategoryAuthFormat
APTnotes
Public archive of APT research reports.
APTNONEjsonhome↗ api↗
CFR Cyber Operations Tracker
State-sponsored cyber incident tracker (public dataset).
Nation StateNONEjsonhome↗ api↗
ETDA Threat Group Cards
APT group encyclopedia with tools and campaigns.
Nation StateNONEjsonhome↗ api↗
EuRepoC Cyber Conflicts
European Repository of Cyber Incidents — attributed state operations.
Nation StateNONEjsonhome↗
MISP Galaxy Threat Actors
Curated threat-actor cluster galaxy.
APTNONEjsonhome↗ api↗
MITRE ATT&CK Groups (STIX)
Adversary groups, software and techniques.
APTNONEjsonhome↗ api↗
MITRE ATT&CK Software/Actors
Adversary tooling & group knowledge base.
ACTORINTNONEjsonhome↗ api↗
ORKL Threat Report Library
Full-text CTI report library API.
APTNONEjsonhome↗ api↗
Ransomwatch Leak Sites
Ransomware leak-site post tracker.
Dark WebNONEjsonhome↗ api↗
AlienVault OTX Pulses
Community threat-intel pulses (free key).
Threat AnalysisKEYjsonhome↗ api↗

🔍 Lookup

📜 Playbook — Threat Actor Intelligence collection

  1. Direction — frame the requirement for Threat Actor Intelligence: what decision does this support, by when?
  2. Collection — collect from the 10 mapped sources (9 free) — filter the catalog by ACTORINT; capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎯 Mission

Threat Actor Intelligence tracks adversary groups, their infrastructure, tooling, and TTPs to attribute activity and anticipate targeting. It answers who is behind an intrusion, what malware and infrastructure they operate, and who they are likely to hit next.

📡 Collection methods

  • Mapping observed behaviors to MITRE ATT&CK technique IDs from incident and vendor reports
  • Malware sample triage and clustering (imphash, YARA, config extraction) to link tooling to actors
  • Infrastructure pivoting on C2 domains, TLS certificates, JARM and JA3 fingerprints, and passive DNS
  • Dark-web forum and ransomware leak-site monitoring for victims, claims, and recruitment
  • Alias correlation across forums, Telegram, and jabber to link personas
  • CTI feed ingestion and enrichment via MISP/OTX and abuse.ch trackers
  • Diamond Model and kill-chain reconstruction of campaigns

🔧 Tools & frameworks

  • MISP
  • Maltego
  • ATT&CK Navigator
  • YARA
  • Shodan
  • MalwareBazaar
  • Yeti
  • Diamond Model

📜 Threat Actor Intelligence Tradecraft

  1. Collect: aggregate incident reports, leak-site posts, and MISP/OTX and abuse.ch feeds tagged to the actor set
  2. Process: normalize IOCs into a graph, map behaviors to ATT&CK technique IDs, and cluster samples by YARA and imphash
  3. Analyze: pivot infrastructure via certificates, JARM/JA3, and passive DNS to expand the actor's known footprint
  4. Attribute: apply the Diamond Model and alias linkage to assign activity to a named group with an explicit confidence level
  5. Disseminate: publish an actor profile with an ATT&CK layer, IOC list, and targeting assessment for defenders
  6. Act: ship detection rules and blocklists and prioritize threat hunts against the actor's signature TTPs

📊 Dashboard KPIs

Tracked actorsNew campaigns/quarterATT&CK coverageAttribution confidenceIOCs shipped
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php