How to Investigate a Threat Actor
An evidence-led method for investigating a threat actor: gather attribution, map techniques, connect campaigns and CVEs, then evaluate confidence and build an investigation.
Quick Answer
To investigate a threat actor, collect attribution and aliases, map their techniques with MITRE ATT&CK, link their campaigns and CVEs, then weigh the confidence of each claim and begin a structured investigation.
Definition
Threat actor investigation is the evidence-based process of building a profile of a hostile operator — their aliases, sponsorship, techniques, campaigns and notable activity — from openly published intelligence.
Answer first
Build an actor profile from attribution → techniques → campaigns/CVEs → confidence.
1. Attribution and aliases
Collect the actor’s primary name, aliases and sponsorship (who is behind them). Treat attribution as a claim that needs a source and a confidence label.
2. Map techniques
Relate the actor to MITRE ATT&CK techniques they use — this turns a vague name into an operational profile of how they operate.
3. Connect campaigns and CVEs
Link campaigns and CVEs the actor is associated with. Cross-reference to see whether the same tooling appears across incidents.
4. Weigh confidence
Attribution is difficult. Note where sources agree, where they conflict, and what confidence you can honestly support.
5. Begin an investigation
Use the entity page as your working record and start an investigation to track findings, evidence and open questions.
Sources and caution
Rely on CISA, MITRE ATT&CK, vendor disclosures and reliable security research. Avoid circular citations and do not invent activity: use “no confirmed evidence” when nothing is verified.
References
Ask OpenTrojan's evidence-backed assistant about this topic — answers cite their sources.