awesome-threat-actor-resources
收藏资源简介:
这是一个精心策划的元列表,收录了开源威胁行为者档案数据库和APT组织数据集的公共参考资源。它涵盖了各种威胁行为者群体,如APT、网络犯罪团伙、国家支持的行为者和其他敌对实体。列表中的资源在范围、格式和覆盖深度上各不相同,从简要总结到详细的威胁情报报告。该合集通过表格形式组织,列出了每个数据源的名称、描述、条目数量和相关链接,旨在为威胁情报研究和分析提供一个集中的数据集资源索引。
This is a curated meta-list of public reference resources for open-source threat actor profile databases and APT group datasets. It covers various threat actor groups, including APT groups, cybercriminal gangs, state-sponsored actors, and other hostile entities. The resources in this list vary in scope, format, and depth of coverage, ranging from brief summaries to detailed threat intelligence reports. This collection is organized in a tabular format, listing the name, description, entry count, and relevant links for each data source, aiming to provide a centralized dataset resource index for threat intelligence research and analysis.
数据集概述
该页面是一个精选的、开源威胁行为者(Threat Actor)档案来源的元列表,旨在追踪各类网络威胁组织,包括APT、网络犯罪团伙、国家支持行为体等。这些来源在范围、格式和覆盖深度上各不相同,从简要摘要到详细威胁情报报告均有涉及。
核心内容:威胁行为者档案来源主列表
该列表包含来自不同组织或社区的32个主要来源,每个来源提供不同数量(从9个到821个不等)的威胁行为者档案。以下为部分代表性来源及其关键信息(完整列表请参考原文):
| 来源 | 简要描述 | 收录数量 | 链接(转为绝对) |
|---|---|---|---|
| EternalLiberty | 收录威胁行为者名称及别名的汇编。 | 821 | https://github.com/StrangerealIntel/EternalLiberty/blob/main/EternalLiberty.csv |
| Malpedia | 提供821个威胁行为者的简要描述(1-2句话)及其相关链接。 | 821 | https://malpedia.caad.fkie.fraunhofer.de/actors |
| MISP Galaxy | 列出816个威胁行为者的别名,但缺乏描述性信息。 | 816 | https://misp-galaxy.org/threat-actor/ |
| MITRE ATT&CK | 关于攻击技术和威胁组织的权威参考资料。 | 170 | https://attack.mitre.org/groups/ |
| Microsoft | 提供约130个威胁行为者的名称和别名。 | ~130 | https://download.microsoft.com/download/4/5/2/45208247-c1e9-432d-a9a2-1554d81074d9/microsoft-threat-actor-list.xlsx 和 https://learn.microsoft.com/en-us/unified-secops-platform/microsoft-threat-actor-naming?view=o365-worldwide |
| CrowdStrike | 当前在线展示73个,累计追踪超过250个威胁行为者。 | 73+ | https://www.crowdstrike.com/adversaries/ |
| Dragos | 专门针对ICS/OT领域的23个威胁行为者档案。 | 23 | https://www.dragos.com/threat-groups/ |
其他说明
- 数据特性:各来源的收录数量为近似值,可能随时间变化;部分来源侧重别名,部分提供详细描述或TTP(战术、技术与程序)信息,还有的专门针对云或工控环境。
- 访问方式:部分来源需要手动提取数据(例如通过XLS文件或交互式网站)。
- 目标受众:适用于CTI(网络威胁情报)分析师、红队、蓝队及安全研究人员。
贡献方式
该页面允许通过提交问题(Issue)来推荐其他高质量的开源威胁行为者数据库或追踪项目。




