Define threat actors
Define threat actors who are individuals, groups, or organizations who act with malicious intent.
Before you begin
Role required: sn_ti.admin
Procedure
- Navigate to .
- Click New.
-
Complete the fields in the form as appropriate.
Field Description Name Enter a name to identify the malware instance or family, as specified by the producer of the SDO. For a malware family, the name must be defined. First Seen The time that this malware instance or family was first seen performing malicious activities. Last Seen The time that this malware instance or family was last seen performing malicious activities. Primary Motivation The primary reason, motivation, or purpose behind this threat actor. The motivation is why the threat actor wants to achieve the goal (what they are trying to achieve). For example, a threat actor with a goal to disrupt the finance sector in a country might be motivated by ideological hatred of capitalism.
Resource Level The organizational level at which this threat actor typically works, which in turn determines the resources available to this Threat Actor for use in an attack. Source Specifies the threat source from which this record is created. Description A description that provides more details and context about the threat actor, potentially including its purpose and its key characteristics. Aliases A list of other names to identify this threat actor. Goals The high-level goals of this threat actor, namely, what are they trying to do. For example, they may be motivated by personal gain, but their goal is to steal credit card numbers. Source ID Unique identifier for this object in the threat source. Created Time in Source Specifies the time the object is created in the source. Modified Time in Source Specifies the time the object is modified in the source. - Click Submit.
What to do next
Click any of the following related lists to view additional information about objects associated with the threat actor.
| Related Links and Related Lists | Description |
|---|---|
| Show Relationships | Opens the STIX Visualizer where you can view the relationship of the STIX
object. Show Relationships appears only when the object has an associated object. |
| External References | Lists external references which refer to non-STIX information. This property is used to provide one or more external object identifiers. |
| Associated Types | Lists indicator types associated with this object. |
| Associated Roles | Lists the associated roles with the threat actor. |
| Associated Attack Motivations | Lists the associated attack motivations with the threat actor. |
| Attack Patterns | Lists the attack patterns that help categorize attacks that are associated with this object. |
| Campaigns | Lists campaigns associated with this object. |
| Identities | List of identities associated with this object. |
| Indicators | Lists related Indicators of Compromise (IoC) that have been identified by the threat source associated with this object. |
| Infrastructure | Lists systems, software services, and any associated physical or virtual resources that are associated with this object. |
| Intrusion Set | Lists a set of adversarial behaviors and resources with common properties associated with this object. |
| Locations | Lists locations that provide geographic context to this object. |
| Malware | Lists malicious code associated with this object. |
| Tools | Lists legitimate software that is used by threat actors to perform attacks associated with this object. |
| Vulnerabilities | Lists a weakness or defect in a software or hardware that attackers exploit which is associated with this object. |