API Reference
The actors.mlab.sh threat-actor API - list, profile, CVE lookup, STIX and bulk exports.
Query Parameters
Suspected country of origin (exact match)
Filter by motivation (e.g. 'Information theft and espionage')
Filter by target sector
ISO timestamp; returns only actors changed since
date-timeReverse lookup: which actors are documented exploiting this CVE
^CVE-\d{4}-\d{4,7}$misp: serve MISP Galaxy data only (CC0), for commercial reuse. Actors without a galaxy match are absent, other filters apply to galaxy fields, q searches name and synonyms, cve is refused. Default data is ETDA-based and CC BY-NC-SA 4.0 (non-commercial).
Value in
- "misp"
source=misp only: substring of the name or a synonym
value <= 5001000Response Body
curl -X GET "https://example.com/api/v1/actors"Path Parameters
Query Parameters
misp: MISP Galaxy profile (CC0) plus MITRE ATT&CK tools and techniques, with a sources block carrying MITRE's notice. No ETDA content, no CVEs.
Value in
- "misp"
Response Body
curl -X GET "https://example.com/api/v1/actors/string"curl -X GET "https://example.com/api/v1/cves/string/actors"curl -X GET "https://example.com/actors/string.stix.json"Query Parameters
"targets"Value in
- "targets"
- "origins"
- "flows"
layer=targets only: restrict to actors from this country
layer=flows only: drop pairs carried by fewer actors
2Response Body
curl -X GET "https://example.com/api/v1/map"Query Parameters
Actor slug
2Value in
- 1
- 2
Node budget; the response flags truncated when it bites
value <= 600220Response Body
curl -X GET "https://example.com/api/v1/graph?root=string"Query Parameters
Restrict the count to actors attributed to this country
Include sub-techniques alongside their parents
falseResponse Body
curl -X GET "https://example.com/api/v1/attack"curl -X GET "https://example.com/export/actors.csv"curl -X GET "https://example.com/export/actors.jsonl"curl -X GET "https://example.com/healthz"