Overview
A public, no-auth threat-actor encyclopedia and API, with two data views under two licences.
actors.mlab.sh is a public HTTP API and website describing threat actors: names and aliases, suspected origin, targeted countries and sectors, and the MITRE ATT&CK tools and techniques attributed to each group.
No authentication, no API key. Every endpoint is a plain GET. Base URL:
https://actors.mlab.sh.
Two views, two licences
The API serves the same actors through two views. Pick the one that matches what you are allowed to do with the data.
| View | How to ask | Sources | Licence | Commercial reuse |
|---|---|---|---|---|
| Default | no source parameter | ETDA Threat Group Cards, MITRE ATT&CK | CC BY-NC-SA 4.0 | No |
| MISP | ?source=misp | MISP Galaxy threat-actor, MITRE ATT&CK | CC0 1.0 and the MITRE ATT&CK Terms of Use | Yes |
Default view. The richest data: descriptions, operations, aliases and the CVEs each actor is documented exploiting. It is derived from the Threat Group Cards published by ETDA (ThaiCERT) under CC BY-NC-SA 4.0, so it may only be used for non-commercial purposes, you must credit ETDA, and anything you publish from it must carry the same licence.
MISP view. Built only from the MISP Galaxy threat-actor cluster, released
into the public domain (CC0), plus MITRE ATT&CK tools and techniques. It is the
view to use inside a commercial product. It differs from the default view in
three ways:
- actors that MISP Galaxy does not describe are not returned;
- there is no CVE attribution:
?cve=and/api/v1/cves/{id}/actorsanswernot_available; - every response carries a
sourcesblock. When it includes MITRE ATT&CK, itsnoticeis required by MITRE's terms: keep it wherever you show that data.
The mlab.sh MCP tools search_actors and get_actor use the MISP view.
Quick example
# Default view (non-commercial)
curl "https://actors.mlab.sh/api/v1/actors/apt28"
# MISP view (commercial reuse allowed)
curl "https://actors.mlab.sh/api/v1/actors/apt28?source=misp"
curl "https://actors.mlab.sh/api/v1/actors?source=misp&q=fancy%20bear"In the MISP view, q matches the actor's name and its synonyms, origin
takes a country name or ISO code, motivation matches the incident type and
sector the targeted sectors. All filters read MISP Galaxy fields only.