OSINT Threat Actor Profiling
OSINT threat actor profiling answers a narrow question: who exactly is coming after us, and how do they work? We build a profile of the group or individual from open sources, map their methods to MITRE ATT&CK, trace their infrastructure and personas, and tell you how sure we are about each point.
- Aliases, motivation and targeting
- TTPs mapped to MITRE ATT&CK
- Infrastructure and personas
- Confidence stated for every judgment
OSINT threat actor profiling is the open-source study of a specific group or individual that targets your organization or sector. The profile covers aliases, motivation, tactics and techniques mapped to MITRE ATT&CK, infrastructure, online personas and an activity timeline, with a confidence level for each judgment. It ends with what your defenders should detect, block or test next.
When a Threat Actor Profile Is Worth Commissioning
When an actor has a name or a handle and a reason to care about you. Profiles are expensive to do well, so they are built around a trigger, not out of curiosity.
Typical triggers we see:
- An extortion group has named you, or a peer in your sector, on its leak site.
- The same phishing kit or look-alike domains keep hitting your staff, and you want to know whether one operator is behind them.
- A forum seller is advertising access to a network that looks like yours.
- A sector advisory names a group, and the board asks whether it matters to you.
- An anonymous persona keeps posting your internal information or threatening your executives.
- Your red team wants a realistic adversary to emulate.
Broad questions, such as "which threats matter to our sector this year", are better served by the wider OSINT threat intelligence service, of which profiling is one part.
What Goes Into an OSINT Threat Actor Profile
Seven elements, from names and motives to the specific detections your team should check. Each element carries its own confidence level.
| Element | What we document | Typical open sources |
|---|---|---|
| Names and aliases | Group names used by different vendors, handles, brand changes | Vendor reports, advisories, forum history |
| Motivation and targeting | Financial, ideological or personal motives; sectors, regions and company sizes hit | Leak-site victim lists, statements, past campaigns |
| TTPs | Initial access, persistence, exfiltration and extortion methods, mapped to ATT&CK | Incident write-ups, advisories, malware reports |
| Infrastructure | Domains, hosting patterns, certificates, phishing kits, payment addresses | Passive DNS, certificate logs, registration data, public scans |
| Personas | Forum and channel accounts, recruitment posts, writing habits, time zones | Forums, messaging channels, paste sites |
| Timeline | First seen, active periods, pauses and rebrands | All of the above, dated |
| Defensive actions | Detections to check, controls to test, indicators to block | Our analysis against your stack |
Mapping TTPs to MITRE ATT&CK
ATT&CK gives your defenders a shared vocabulary: each mapped technique becomes a question about whether you can detect or stop it.
MITRE describes ATT&CK as a globally accessible knowledge base of adversary tactics and techniques based on real-world observations (MITRE ATT&CK). Mapping an actor's behavior to it turns a narrative report into a checklist your SOC can run: for each technique, do we log it, alert on it, or block it?
Buyers want this level of detail. In the SANS 2026 CTI Survey, 77% of security executives named specific adversary TTPs as a priority for the next 12 months, second only to vulnerabilities being actively targeted, at 79% (SANS 2026).
Public group pages are a starting point, not a complete record. MITRE notes that its technique mappings are a subset drawn from open-source reporting and that names used by different organizations may only partly overlap (ATT&CK Groups). We add what recent reporting, leak-site behavior and infrastructure show, and mark which techniques are confirmed and which are inferred.
Confidence Levels and the Limits of Attribution
We say how sure we are, and why. Most profiles attribute activity to a cluster or persona; naming a real person needs a much higher bar and a lawful reason.
We follow the discipline set out in the US intelligence community's analytic standards: explain the basis for uncertainty in major judgments, and keep underlying information separate from assumptions and judgments (ICD 203).
| Confidence | What it means in our reports |
|---|---|
| High | Several independent sources agree, and the evidence is hard to fake |
| Moderate | Credible evidence, but from fewer sources or with gaps that are stated |
| Low | Plausible lead worth tracking; not a basis for action on its own |
Attribution has hard limits. Groups rebrand, share tools, rent infrastructure and sell access to each other, and a persona can be operated by more than one person. When a profile points to an identifiable individual, we report the evidence to you and your counsel, not to the public, and the next step is usually law enforcement. For anonymous accounts on mainstream platforms, see anonymous account attribution.
How We Build an OSINT Actor Profile
Requirements, collection, pivoting, mapping, a confidence review and a briefing, then updates while the actor stays active.
- Agree the requirementsWhich actor or activity, what you already know, and which decisions the profile must support.
- CollectAdvisories, vendor reports, leak sites, forums, channels and technical records, each captured with date and source.
- Pivot on infrastructure and personasFrom one domain, certificate, handle or wallet to related ones, until the cluster stops growing.
- Map and compareTTPs mapped to ATT&CK and compared with your controls and logs.
- Review confidenceA senior analyst challenges each judgment before anything is reported.
- Brief and updateA written profile and a briefing for your team, with updates if the actor changes tools or targets you again.
Deliverables, Timelines and Lines We Do Not Cross
A written profile with ATT&CK mapping and recommended detections, usually from 10 business days, and no hack-back or infiltration under false identities.
You receive the profile, an ATT&CK layer or table of techniques, an indicator list in an agreed format, and a short list of detections and tests. A focused profile of one actor starts from 10 business days; a comparative study of several actors targeting your sector can take up to about a month. Urgent delivery costs 50% more, the price is fixed after written scoping, and the fee goes down if we miss the agreed date.
We observe and document. We do not hack back, access actor infrastructure, buy stolen data or create fake profiles to enter closed communities. Profiles feed your defense, your counsel and, where relevant, law enforcement. Indicators from a profile can also flow into curated threat intelligence feeds, and a profiled phishing operator into phishing intelligence. Actor work is one of the OSINT services that sits closest to your SOC; red teams use the same profiles for adversary emulation.
Name the Actor, Get the Profile
Send the group name, handle, domain or leak-site post you are dealing with, and the decision you need to make. We will scope the profile around it.
OSINT Threat Actor Profiling FAQ
An extortion group just listed a competitor of ours on its leak site, and our CISO wants OSINT threat actor profiling before they come for us — what would the profile tell us?
It would tell you how that group usually gets in, what it does once inside, how it extorts, and what your team should check first. OSINT threat actor profiling covers aliases, motivation, targeting, techniques mapped to MITRE ATT&CK, infrastructure, personas and an activity timeline, each with a confidence level. The practical output is a list of detections and controls to test against your own environment, ranked by how often the group uses each technique.
Our SOC already has a threat intelligence platform with pages on hundreds of groups — why would we pay for a separate profile of one actor?
Because platform pages are general and yours would be specific. MITRE itself notes that public technique mappings are a subset of what groups do, drawn from open reporting, and that names used by different vendors only partly overlap (ATT&CK Groups). A commissioned profile reconciles those names, adds recent behavior and infrastructure, and compares the actor's techniques with your controls, which no generic page can do.
If your profile points to a real person behind the attacks on us, will you give us their name, and can we go public with it?
We report what the evidence supports, with a confidence level, to you and your counsel only. Attribution to a named individual needs a high bar: groups share tools and rent infrastructure, and personas can be run by several people. Going public carries defamation and safety risks and can damage a law enforcement case. The usual route is to give the evidence to police or your national cyber agency.
We are being targeted by a persistent phishing crew and someone on our board suggested hacking back to take their servers down — would you do that?
No. Accessing someone else's systems without authorization is a crime even when the systems belong to an attacker, and hack-back can hit innocent hosting providers or tip off the crew. We observe and document: map their domains, kits and hosting patterns, which supports takedown requests to registrars and hosts, blocklists for your own controls, and reports to law enforcement.
How long does it take to profile a threat actor, and can we get something useful within the week while a ransomware incident is still unfolding?
A focused profile of one actor starts from 10 business days, and a comparative study of several actors can take up to about a month. During a live incident, a short first brief on the group's known techniques and extortion behavior is often a small task we can sometimes return within a business day, with urgent delivery at a 50% surcharge. The full profile follows on the agreed date.
Our red team wants to emulate a realistic attacker in next quarter's exercise — can your actor profile be used to plan that, and in what format?
Yes. Profiles include a table or ATT&CK layer of the techniques the actor uses, with notes on which are confirmed and which are inferred, so the red team can build an emulation plan from real behavior rather than a generic attacker. Infrastructure patterns and phishing lures help make the exercise realistic. Any testing against your staff or systems still needs written authorization from you before it starts.
Sources and Notes
- MITRE ATT&CK
- MITRE ATT&CK: Groups
- ODNI: Intelligence Community Directive 203, Analytic Standards
- SANS 2026 CTI Survey (press release)
Sources checked 8 October 2026. Figures about third-party firms and tools are as published by them or by the cited source on that date.