consolidated_actor_observables_ng

The consolidated_actor_observables_ng search table is one of the data sources for the AI Actor Profile dashboard. It checks each Actor association provided in the consolidated_actor_profiles_ng and links the corresponding observable information based on the Actor ID. The table is read-only and not subject to modification.

(Click the image to enlarge it)

Field Value Type Description Example
actor_id numeric ID of the Actor. 190789.0
actor_name string Name of the Actor. HAZY TIGER
confidence numeric Risk score from 0 to 100, assigned by ThreatStream's predictive analytics technology to the observable. 70
created_ts date

Time stamp of when the observable was first created in ThreatStream.

Date is specified in the following format:

MMM dd, yyyy HH:mm:ss.SSS Z where

  • MMM - month name

  • dd - day of the month

  • yyyy - year

  • HH - hour (24-clock, 2 digits)

  • mm - minutes

  • ss - seconds

  • .SSS - milliseconds (3 digits)

  • Z - timezone offset from UTC

May 05, 2024 17:15:01.000
feed_name string Name of the threat feed that created the observable on ThreatStream. CrowdStrike Falcon X
indicator string Indicator name associated with The Actor.
  • folkmusicstreams.com

  • e462a6710d9b71ecdc41ff7941b2d177

  • 194.37.95.173

 

itype string Indicator type of the observable associated with the Actor. mal_md5
modified_ts date

Time stamp of when the observable was last updated in ThreatStream.

Date is specified in the following format:

MMM dd, yyyy HH:mm:ss.SSS Z where

  • MMM - month name

  • dd - day of the month

  • yyyy - year

  • HH - hour (24-clock, 2 digits)

  • mm - minutes

  • ss - seconds

  • .SSS - milliseconds (3 digits)

  • Z - timezone offset from UTC

Jun 24, 2025 13:40:20.000
observable_id numeric ID of the observable. 57634912361
severity string

Criticality associated with the threat feed that supplied the observable

Possible values: low, medium, high, very-high.

high