mlab docs

API Reference

The actors.mlab.sh threat-actor API - list, profile, CVE lookup, STIX and bulk exports.

GET
/api/v1/actors

Query Parameters

origin?string

Suspected country of origin (exact match)

motivation?string

Filter by motivation (e.g. 'Information theft and espionage')

sector?string

Filter by target sector

updated_since?string

ISO timestamp; returns only actors changed since

Formatdate-time
cve?string

Reverse lookup: which actors are documented exploiting this CVE

Match^CVE-\d{4}-\d{4,7}$
source?"misp"

misp: serve MISP Galaxy data only (CC0), for commercial reuse. Actors without a galaxy match are absent, other filters apply to galaxy fields, q searches name and synonyms, cve is refused. Default data is ETDA-based and CC BY-NC-SA 4.0 (non-commercial).

Value in

  • "misp"
q?string

source=misp only: substring of the name or a synonym

limit?integer
Rangevalue <= 500
Default100
offset?integer
Default0

Response Body

curl -X GET "https://example.com/api/v1/actors"
Empty
GET
/api/v1/actors/{slug}

Path Parameters

slug*string

Query Parameters

source?"misp"

misp: MISP Galaxy profile (CC0) plus MITRE ATT&CK tools and techniques, with a sources block carrying MITRE's notice. No ETDA content, no CVEs.

Value in

  • "misp"

Response Body

curl -X GET "https://example.com/api/v1/actors/string"
Empty
Empty
GET
/api/v1/cves/{cve_id}/actors

Path Parameters

cve_id*string
Match^CVE-\d{4}-\d{4,7}$

Response Body

curl -X GET "https://example.com/api/v1/cves/string/actors"
Empty
GET
/actors/{slug}.stix.json

Path Parameters

slug*string

Response Body

curl -X GET "https://example.com/actors/string.stix.json"
Empty
GET
/api/v1/map

Query Parameters

layer?string
Default"targets"

Value in

  • "targets"
  • "origins"
  • "flows"
origin?string

layer=targets only: restrict to actors from this country

min?integer

layer=flows only: drop pairs carried by fewer actors

Default2

Response Body

curl -X GET "https://example.com/api/v1/map"
Empty
GET
/api/v1/graph

Query Parameters

root*string

Actor slug

depth?integer
Default2

Value in

  • 1
  • 2
max?integer

Node budget; the response flags truncated when it bites

Rangevalue <= 600
Default220

Response Body

curl -X GET "https://example.com/api/v1/graph?root=string"
Empty
Empty
GET
/api/v1/attack

Query Parameters

origin?string

Restrict the count to actors attributed to this country

subs?boolean

Include sub-techniques alongside their parents

Defaultfalse

Response Body

curl -X GET "https://example.com/api/v1/attack"
Empty
GET
/export/actors.csv

Response Body

curl -X GET "https://example.com/export/actors.csv"
Empty
GET
/export/actors.jsonl

Response Body

curl -X GET "https://example.com/export/actors.jsonl"
Empty
GET
/healthz

Response Body

curl -X GET "https://example.com/healthz"
Empty
Empty