consolidated_actor_profiles_ng
The consolidated_actor_profiles_ng search table is one of the data sources for the AI Actor Profile dashboard. It consolidates information about aliases, associations, motivations, and other details about threat actors available on ThreatStream. The table is read-only and not subject to modification.
(Click the image to enlarge it)
| Field | Value Type | Description | Example |
|---|---|---|---|
| actor_ids | string | ID of the Actor. | 784170 |
| actor_name | string | Name of the Actor | kasparoff |
| alias | array of strings | Other names associated with the Actor. | [APT-C-36, Blind Eagle] |
| attack_pattern_associations | array of strings | Attack Patterns associated with the Actor. | [T1036 - Masquerading, T1566 - Phishing, ] |
| campaign_associations | array of strings | Campaigns associated with the Actor. | [] |
| created_ts | date |
Time stamp of when the Actor was created on ThreatStream. Date is specified in the following format:
|
Jun 25, 2025 08:50:46.000 -07 |
| feed_ids | numeric array | ID of the feed that created the Actor on ThreatStream. | [383] |
| feed_names | array of strings | Name of the feed that created the Actor on ThreatStream. | [CrowdStrike Falcon X] |
| malware_associations | array of strings | Malware entities associated with the Actor. | [HTRAN, MIMIKATZ, ] |
| modified_ts | date | Time stamp of when the Actor was last updated in ThreatStream. Date is specified in the following format:
|
Jun 25, 2025 08:50:57.000 -07 |
| motivations | array of strings | Reasons, motivations, or purposes behind the Actor. | [Military, Political] |
| operation_types | array of strings | Operation types associated with the Actor. | [Cyber Espionage Operations, State Actor / Agency] |
| primary_motivation | array of strings | The primary reason, motivation, or purpose behind the Actor. The motivation is why the Actor wishes to achieve the goal (what they are trying to achieve). | [personal-gain] |
| secondary_motivations | array of strings | Secondary reasons, motivations, or purposes behind the Actor. | [organizational-gain] |
| sophistication_type | array of strings |
Level of sophistication observed about the Actor. The Sophistication levels available on ThreatStream follow the Threat Actor Sophistication Vocabulary for STIX. The levels are: No Type (Default), Innovator, Expert, Practitioner, Novice, Aspirant. |
[Innovator] |
| source_locations | array of strings | Source location associated with the Actor (as defined by STIX 2.1). | [Ecuador, Chile] |
| tags | array of strings | Additional comments and context associated with the Actor. | [TTPs, Phishing, Retail, Banking-and-Finance, ABSA_PIR-001_Phishing] |
| target_industry | array strings |
Target industries associated with the Actor. Target industry options available for selection are defined by the STIX 2.1 Industry Sector vocabulary. |
[aerospace, energy, financial-services, government, telecommunications, transportation, utilities] |
| target_locations | array of strings | Target locations associated with the Actor (as defined by STIX 2.1). | [Belarus] |
| threat_actor_types | array of strings | Type of the Actor. | [criminal] |
| tipreport_associations | array of strings | Threat Bulletins associated with the Actor. | [Actor SubComandanteVPN offers to sell access to 34 entities worldwide] |
| tlp | array of strings | Traffic Light Protocol designation for the Actor—red, amber, amber+strict, green, white or clear. | [red] |
| vulnerability_associations | array of strings | Vulnerabilities associated with the Actor. | [CVE-2022-30190, ] |
