consolidated_actor_profiles_ng

The consolidated_actor_profiles_ng search table is one of the data sources for the AI Actor Profile dashboard. It consolidates information about aliases, associations, motivations, and other details about threat actors available on ThreatStream. The table is read-only and not subject to modification.

(Click the image to enlarge it)

Field Value Type Description Example
actor_ids string ID of the Actor. 784170
actor_name string Name of the Actor kasparoff
alias array of strings Other names associated with the Actor. [APT-C-36, Blind Eagle]
attack_pattern_associations array of strings Attack Patterns associated with the Actor. [T1036 - Masquerading, T1566 - Phishing, ]
campaign_associations array of strings Campaigns associated with the Actor. []
created_ts date

Time stamp of when the Actor was created on ThreatStream.

Date is specified in the following format:

MMM dd, yyyy HH:mm:ss.SSS Z where

  • MMM - month name

  • dd - day of the month

  • yyyy - year

  • HH - hour (24-clock, 2 digits)

  • mm - minutes

  • ss - seconds

  • .SSS - milliseconds (3 digits)

  • Z - timezone offset from UTC

Jun 25, 2025 08:50:46.000 -07
feed_ids numeric array ID of the feed that created the Actor on ThreatStream. [383]
feed_names array of strings Name of the feed that created the Actor on ThreatStream. [CrowdStrike Falcon X]
malware_associations array of strings Malware entities associated with the Actor. [HTRAN, MIMIKATZ, ]
modified_ts date Time stamp of when the Actor was last updated in ThreatStream.

Date is specified in the following format:

MMM dd, yyyy HH:mm:ss.SSS Z where

  • MMM - month name

  • dd - day of the month

  • yyyy - year

  • HH - hour (24-clock, 2 digits)

  • mm - minutes

  • ss - seconds

  • .SSS - milliseconds (3 digits)

  • Z - timezone offset from UTC

Jun 25, 2025 08:50:57.000 -07
motivations array of strings Reasons, motivations, or purposes behind the Actor. [Military, Political]
operation_types array of strings Operation types associated with the Actor. [Cyber Espionage Operations, State Actor / Agency]
primary_motivation array of strings The primary reason, motivation, or purpose behind the Actor. The motivation is why the Actor wishes to achieve the goal (what they are trying to achieve). [personal-gain]
secondary_motivations array of strings Secondary reasons, motivations, or purposes behind the Actor. [organizational-gain]
sophistication_type array of strings

Level of sophistication observed about the Actor.

The Sophistication levels available on ThreatStream follow the Threat Actor Sophistication Vocabulary for STIX. The levels are: No Type (Default), Innovator, Expert, Practitioner, Novice, Aspirant.

[Innovator]
source_locations array of strings Source location associated with the Actor (as defined by STIX 2.1). [Ecuador, Chile]
tags array of strings Additional comments and context associated with the Actor. [TTPs, Phishing, Retail, Banking-and-Finance, ABSA_PIR-001_Phishing]
target_industry array strings

Target industries associated with the Actor.

Target industry options available for selection are defined by the STIX 2.1 Industry Sector vocabulary.

[aerospace, energy, financial-services, government, telecommunications, transportation, utilities]
target_locations array of strings Target locations associated with the Actor (as defined by STIX 2.1). [Belarus]
threat_actor_types array of strings Type of the Actor. [criminal]
tipreport_associations array of strings Threat Bulletins associated with the Actor. [Actor SubComandanteVPN offers to sell access to 34 entities worldwide]
tlp array of strings Traffic Light Protocol designation for the Actor—red, amber, amber+strict, green, white or clear. [red]
vulnerability_associations array of strings Vulnerabilities associated with the Actor. [CVE-2022-30190, ]