POSThttps://api.deepinfo.com/v1/cti/threat-actors/search

Searches threat actors.

Authentication

Send your API key in the apikey request header.

Query Parameters

ParameterRequiredDescription
page_sizeOptional
Min 25, max 100. Default 100.
Example25
pageOptional
Min 1, max 800. Default 1.
Example1

Request Body

ParameterTypeRequiredDescription
filtersobjectOptional
See Filtering below
sortarrayOptional
List of {field, order}
application/json
{}

Filtering

Example body:

JSON
{
  "filters": {
    "must": [
      {
        "name": "name",
        "type": "eq",
        "value": "<value>"
      }
    ]
  },
  "sort": [
    {
      "field": "name",
      "order": "desc"
    }
  ]
}

See Getting Started → Search & Filters for the operators.

The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.

Searchable Fields

Grouped by the operators they accept (measured against the API; sending another operator returns 400).

Operators eq in startswith endswith contains_any contains_all exists

FieldDescription
nameThe threat actor's main name; other names are in aliases.
aliasesOther names the threat actor is known by.
actor_sizeThe threat actor's size, as text.
actor_typesThe threat actor's types, as a list of strings.
actor_sophisticationThe threat actor's level of sophistication, as text.
actor_specializationsThe threat actor's specializations, as a list of strings.
descriptionA text description of the threat actor.
law_enforcementLaw enforcement information recorded for the threat actor, as text.
contact_info.emailE-mail addresses listed in the threat actor's contact information.
contact_info.telegram_usernameTelegram usernames listed in the threat actor's contact information.
contact_info.telegram_channelTelegram channels listed in the threat actor's contact information.
contact_info.discord_usernameDiscord usernames listed in the threat actor's contact information.
contact_info.jabberJabber (XMPP) addresses listed in the threat actor's contact information.
contact_info.toxTox IDs listed in the threat actor's contact information.
contact_info.skypeSkype names listed in the threat actor's contact information.
contact_info.icqICQ contacts listed in the threat actor's contact information.
contact_info.cdnCDN entries listed in the threat actor's contact information.
contact_info.ip_rangesIP address ranges listed in the threat actor's contact information.
social_media.twitterThe threat actor's Twitter (X) accounts.
social_media.vimeoThe threat actor's Vimeo accounts.
websitesWebsites linked to the threat actor.
payment_info.bitcoinBitcoin addresses in the threat actor's payment information.
payment_info.ethereumEthereum addresses in the threat actor's payment information.
origin_countriesThe threat actor's countries of origin; the Most Actor Hosting Countries statistic counts actors per origin country.
leak_namesNames of leaks linked to the threat actor.
forum_namesNames of the forums the threat actor is active on.
market_namesNames of the markets the threat actor is active on.
forum_market_usernamesThe usernames the threat actor uses on forums and markets.
targeted_regionsThe regions the threat actor has targeted.
targeted_countriesThe countries the threat actor has targeted; the Most Targeted Countries statistic counts them.
targeted_industriesThe industries the threat actor has targeted; the Most Targeted Industries statistic counts them.
targeted_organizationsThe organizations the threat actor has targeted; the Most Targeted Organizations statistic counts them.
cves_usedCVE IDs of the vulnerabilities the threat actor has used; the Most Used CVEs statistic counts them.
tools_usedThe tools the threat actor has used; the Most Used Tools statistic counts them.

Operators eq in gte lte exists

FieldDescription
date_updatedWhen the threat actor's profile was last updated (UTC date-time).
date_first_seenWhen the threat actor was first seen (UTC date-time).
date_last_seenWhen the threat actor was last seen active (UTC date-time).

Operators eq exists

FieldDescription
is_activeWhether the threat actor is considered active.

Sortable Fields

FieldDescription
nameThe threat actor's main name; other names are in aliases.
date_updatedWhen the threat actor's profile was last updated (UTC date-time).
date_first_seenWhen the threat actor was first seen (UTC date-time).
date_last_seenWhen the threat actor was last seen active (UTC date-time).
is_activeWhether the threat actor is considered active.
actor_sizeThe threat actor's size, as text.
actor_sophisticationThe threat actor's level of sophistication, as text.

Response Fields

FieldTypeDescription
pageinteger
page_sizeinteger
result_countinteger
resultsarray of object
results[].idstring
results[].namestring
results[].aliasesarray of string
results[].date_updatedstring
date-time
results[].date_first_seenstring
date-time
results[].date_last_seenstring
date-time
results[].is_activeboolean
results[].actor_sizestring
results[].actor_typesarray of string
results[].actor_sophisticationstring
results[].actor_specializationsarray of string
results[].descriptionstring
results[].law_enforcementstring
results[].contact_infoobject
results[].social_mediaobject
results[].websitesarray of string
results[].payment_infoobject
results[].origin_countriesarray of string
results[].leak_namesarray of string
results[].forum_namesarray of string
results[].market_namesarray of string
results[].forum_market_usernamesarray of string
results[].targeted_regionsarray of string
results[].targeted_countriesarray of string
results[].targeted_industriesarray of string
results[].targeted_organizationsarray of string
results[].cves_usedarray of string
results[].tools_usedarray of string

Paginated. See Getting Started → Pagination.

Response Schema

Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

FieldTypeExample
pagenumber1
page_sizenumber25
result_countnumber0
resultsarray

Examples

Selecting one loads it into the request and response panels.

Reference updated