Threat Actor
A threat actor is any individual, group, or organization that conducts malicious cyber activity. Threat actors are classified by motivation (financial, espionage, hacktivism), capability (nation-state, organized crime, script kiddie), and targeting patterns. Attribution helps predict future attack patterns.
Frequently Asked Questions
What is Threat Actor?
A threat actor is any individual, group, or organization that conducts malicious cyber activity. Threat actors are classified by motivation (financial, espionage, hacktivism), capability (nation-state, organized crime, script kiddie), and targeting patterns. Attribution helps predict future attack patterns.
How is Threat Actor related to TTP (Tactics, Techniques, and Procedures)?
Threat Actor and TTP (Tactics, Techniques, and Procedures) are both key concepts in threat intelligence. TTPs describe the behavior of threat actors: the high-level goals they pursue (tactics), the specific methods they use to achieve those goals (techniques), and the detailed, repeatable actions that implement those methods (procedures). The MITRE ATT&CK framework catalogues TTPs used by real adversaries.
Related Terms
TTP (Tactics, Techniques, and Procedures)
TTPs describe the behavior of threat actors: the high-level goals they pursue (tactics), the specific methods they use to achieve those goals (techniques), and the detailed, repeatable actions that implement those methods (procedures). The MITRE ATT&CK framework catalogues TTPs used by real adversaries.
IOC (Indicator of Compromise)
An indicator of compromise is an indicator supported by evidence of compromise or malicious activity. Security teams use IOCs to detect, contain, and investigate threats; an arbitrary IP address, domain, URL, file hash, or email address is only an observable until evidence supports that promotion.
Threat Intelligence
Threat intelligence is evidence-based knowledge about cyber threats, including observed infrastructure, behaviors, campaigns, and likely intent. It combines source observations with context so security teams can make a specific detection, triage, containment, or response decision.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.