14 tools
Threat actor search tools help analysts identify, profile and track the individuals and groups behind cyberattacks. They aggregate intelligence on advanced persistent threat (APT) crews, ransomware operators, initial access brokers and dark web informants, letting you connect a handle, alias or malware family to a broader campaign. Good resources link tactics, techniques and procedures back to named groups so you can anticipate behaviour rather than just react to indicators.
When choosing a tool, weigh source freshness, attribution rigour and how transparently it cites evidence, since sloppy attribution can mislead an investigation. Look for coverage of both surface reporting and underground forum chatter. Use these resources for defensive research, incident response and due diligence only, and cross-reference multiple feeds before acting on a claim. For wider context, browse the full OSINT directory or related threat intelligence sources.
Know about Threat Actors, sponsored countries, their tools, methods, etc.
148 threat groups with detailed TTPs.
Provides a list of all known cyber threat actors also referred to as malicious actors, APT groups or hackers.
Cybergeist.io generates intelligence profiles about key threats and threat context that is actively being discussed and reported upon across the internet.
Tracking 854 Threat Actors as of 29th of May 2025.
Search for Threat Actor groups and their tools.
Powered by FortiGuard Labs, our Threat Actor Encyclopedia provides actionable insights, helping security teams prepare and streamline advanced threat hunting and response.
Trending Threats.
Total 203 threat actors.
Get List of threat actor groups.
Known or estimated adversary groups as identified by 360.net.
Threat Library Collecting Information.
Know threat actor tactics, techniques, and past activities. Access detailed profiles and track their activities.Keep up with the latest threats and Tactics, Techniques, and Procedures (TTPs).
Find Threat actor groups in a graphical attack explorer.
A threat actor search tool is a resource that collects and organises intelligence about the people and groups behind cyberattacks. It lets analysts look up aliases, APT designations, malware families or campaigns and retrieve linked reporting, indicators and known tactics, helping defenders attribute activity and understand an adversary's likely goals and methods.
Attribution is inherently uncertain, so treat any single database as one input rather than proof. Reputable sources cite evidence and note confidence levels. Adversaries deliberately plant false flags and reuse tooling, so cross-reference multiple feeds, weigh the analyst's reasoning, and avoid naming a specific actor publicly until the evidence is strong.
Reading published threat intelligence, advisories and open forum posts is legal in most jurisdictions and is standard defensive practice. Problems arise if you access systems without authorisation, purchase stolen data, or engage actors directly. Keep research passive and observational, document your sources, and follow your organisation's rules of engagement and applicable law.
Search all 1,200+ OSINT tools instantly, or run a target through the investigation console.
Open the OSINT directory →