mlab docs

Overview

A public, no-auth threat-actor encyclopedia and API, with two data views under two licences.

actors.mlab.sh is a public HTTP API and website describing threat actors: names and aliases, suspected origin, targeted countries and sectors, and the MITRE ATT&CK tools and techniques attributed to each group.

No authentication, no API key. Every endpoint is a plain GET. Base URL: https://actors.mlab.sh.

Two views, two licences

The API serves the same actors through two views. Pick the one that matches what you are allowed to do with the data.

ViewHow to askSourcesLicenceCommercial reuse
Defaultno source parameterETDA Threat Group Cards, MITRE ATT&CKCC BY-NC-SA 4.0No
MISP?source=mispMISP Galaxy threat-actor, MITRE ATT&CKCC0 1.0 and the MITRE ATT&CK Terms of UseYes

Default view. The richest data: descriptions, operations, aliases and the CVEs each actor is documented exploiting. It is derived from the Threat Group Cards published by ETDA (ThaiCERT) under CC BY-NC-SA 4.0, so it may only be used for non-commercial purposes, you must credit ETDA, and anything you publish from it must carry the same licence.

MISP view. Built only from the MISP Galaxy threat-actor cluster, released into the public domain (CC0), plus MITRE ATT&CK tools and techniques. It is the view to use inside a commercial product. It differs from the default view in three ways:

  • actors that MISP Galaxy does not describe are not returned;
  • there is no CVE attribution: ?cve= and /api/v1/cves/{id}/actors answer not_available;
  • every response carries a sources block. When it includes MITRE ATT&CK, its notice is required by MITRE's terms: keep it wherever you show that data.

The mlab.sh MCP tools search_actors and get_actor use the MISP view.

Quick example

# Default view (non-commercial)
curl "https://actors.mlab.sh/api/v1/actors/apt28"

# MISP view (commercial reuse allowed)
curl "https://actors.mlab.sh/api/v1/actors/apt28?source=misp"
curl "https://actors.mlab.sh/api/v1/actors?source=misp&q=fancy%20bear"

In the MISP view, q matches the actor's name and its synonyms, origin takes a country name or ISO code, motivation matches the incident type and sector the targeted sectors. All filters read MISP Galaxy fields only.

Endpoints

On this page