Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Define Threat Actor

Define threat actors who are individuals, groups, or organizations who act with malicious intent.

Before you begin

Role required: sn_sec_tisc.analyst

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Click on Threat Intel Library icon on the workspace.

  3. Go to Threat Actor object.

  4. Click New.

    Note: Whenever you create new object records for observables, indicators, entities or objects a source record is created and a prompt message is displayed that the new object record is created and then the user is redirected to the aggregated record.

  5. On the form, fill in the fields.

FieldDescription
IDUnique ID for a course of action to prevent an attack.
NameEnter a descriptive name to identify the location.
DescriptionA description that provides more details and context about the intrusion set, potentially including its purpose and its key characteristics.
AliasesA list of other names to identify this threat actor.Note: To add new alias which is not existing in the application click on the Add New Aliases icon which is available within the Alias field itself.
GoalsThe high-level goals of this threat actor, namely, what are they trying to do. For example, they may be motivated by personal gain, but their goal is to steal credit card numbers.
Threat Actor TypesThe type\(s\) of this threat actor.
Threat Actor RolesThe various threat actor role\(s\) for this object.
First SeenThe time that this Threat Actor was first seen.This property is a summary property of data from sightings and other data that may or may not be available in STIX. If new sightings are received that are earlier than the first seen timestamp, the object may be updated to account for the new data.
Last SeenThe time that this Threat Actor was last seen.
Primary MotivationThe primary reason, motivation, or purpose behind this Threat Actor. The motivation is why the Threat Actor wishes to achieve the goal \(what they are trying to achieve\).For example, a Threat Actor with a goal to disrupt the finance sector in a country might be motivated by ideological hatred of capitalism.
SophisticationThe skill, specific knowledge, special training, or expertise a Threat Actor must have to perform the attack.
Secondary MotivationsThis property specifies the secondary reasons, motivations, or purposes behind this Threat Actor.These motivations can exist as an equal or near-equal cause to the primary motivation. However, it does not replace or necessarily magnify the primary motivation, but it might indicate additional context. The position in the list has no significance.
Resource LevelThe organizational level at which this Threat Actor typically works, which in turn determines the resources available to this Threat Actor for use in an attack. This attribute is linked to the sophistication property — a specific resource level implies that the Threat Actor has access to at least a specific sophistication level.
ConfidenceEnter the confidence for this course of action.
TLPTLP is used to ensure that sensitive information is shared with the appropriate audience. It employs four colors \(White, Green, Amber, and Red\) to indicate different degrees of sensitivity.
SourceSpecifies the threat source from which this object record is created.
RevokedIndicates that the revoked objects are no longer considered valid by the object creator.
|Field|Description|
|-----|-----------|
|Notes|Add any additional notes for this threat actor.|
FieldDescription
Additional ContextAdd any additional context for this attack pattern.
Spec VersionThe version of the STIX specification used to represent this object.The value of this property must be 2.1 for STIX Objects defined according to this specification.
LangThis property identifies the language of the text content in this object.
Created Time In SourceSpecifies the time the object is created in the source.
ExtensionsIndicates the extensions of attack pattern.
Modified Time in SourceSpecifies the time the object is modified in the source.
Processing StatusRepresents the processing status of this object, course of action.
CreatedSpecifies the date and time when the object is created in the source.
UpdatedSpecifies the date and time when the object was updated in the source.
Created By RefThis property specifies that the identity object that describes the entity had created this object.
  1. Click Save.

    After you save, a prompt message is displayed indicating that A new observable record is created. Click Continue to edit the record and create new relationships.

  2. Click Continue.

    Important: After you create a new observable record, Prevent System Updates check box is displayed.

    Select this check box to prevent any updates from the system after the observable or indicator or STIX objects records are created.

    FieldDescription
    Tags
    Select TagsSelect the tags that are associated with the threat actor.
    Add TagsAdd new tags.
    Taxonomies
    Select TaxonomySelect a Taxonomy that is associated with this threat actor.
    Add Taxonomy ValuesAdd Taxonomy values that are associated with this threat actor.

What to do next

Click any of the following related lists to view additional information about objects associated with the threat actor.

FieldDescription
External ReferencesLists the external references which refer to non-STIX information. This property is used to provide one or more external object identifiers.
Attack PatternsLists the attack patterns that help categorize attacks that are associated with this object.
CampaignsLists the campaigns associated with this object.
IdentitiesList of identities associated with this object.
InfrastructureLists systems, software services, and any associated physical or virtual resources that are associated with this object.
Intrusion SetsLists a set of adversarial behaviors and resources with common properties associated with this object.
LocationsList of locations associated with this object.
MalwareLists the malicious code associated with this object.
Marketing DefinitionsLists the marketing definitions associated with this object.
ObservablesLists the observables associated with this object.
SightingsLists the sightings associated with this object.
ToolsLists legitimate software that is used by threat actors to perform attacks associated with this object.

Note:

  1. You can link and unlink the related records associated with this object. For more information, see Link Threat Intel Related Records.
  2. The various SDOs within the TI library also contains the potential relationships. To establish a relationships between any two objects, you use the Potential Relationships link from the Threat Intel Library to confirm the relationships between the objects. For more information, see Confirm object-object potential relationships.
  3. Also, use the Related Records section from the objects form view to confirm the relationships between two Objects using the Potential Relationships section available on the form view. For more information on see, Confirm Potential Relationships from Related Records.
  4. You can add objects to cases. For more information, see Add to Case.

Parent Topic:Threat Actor