Threat Actor Search
https://api.deepinfo.com/v1/cti/threat-actors/searchSearches threat actors.
Authentication
Send your API key in the apikey request header.
Query Parameters
| Parameter | Required | Description |
|---|---|---|
page_ | Optional | Min 25, max 100. Default 100.Example 25 |
page | Optional | Min 1, max 800. Default 1.Example 1 |
Request Body
| Parameter | Type | Required | Description |
|---|---|---|---|
filters | object | Optional | See Filtering below |
sort | array | Optional | List of {field, order} |
{}
Filtering
Example body:
{
"filters": {
"must": [
{
"name": "name",
"type": "eq",
"value": "<value>"
}
]
},
"sort": [
{
"field": "name",
"order": "desc"
}
]
}
See Getting Started → Search & Filters for the operators.
The Request Template example holds this body with every filter of this endpoint, one entry per field, each with an operator the field accepts and a placeholder value. Copy it, keep the filters you need and set their values.
Searchable Fields
Grouped by the operators they accept (measured against the API; sending another operator returns 400).
Operators eq in startswith endswith contains_ contains_ exists
| Field | Description |
|---|---|
name | The threat actor's main name; other names are in aliases. |
aliases | Other names the threat actor is known by. |
actor_ | The threat actor's size, as text. |
actor_ | The threat actor's types, as a list of strings. |
actor_ | The threat actor's level of sophistication, as text. |
actor_ | The threat actor's specializations, as a list of strings. |
description | A text description of the threat actor. |
law_ | Law enforcement information recorded for the threat actor, as text. |
contact_ | E-mail addresses listed in the threat actor's contact information. |
contact_ | Telegram usernames listed in the threat actor's contact information. |
contact_ | Telegram channels listed in the threat actor's contact information. |
contact_ | Discord usernames listed in the threat actor's contact information. |
contact_ | Jabber (XMPP) addresses listed in the threat actor's contact information. |
contact_ | Tox IDs listed in the threat actor's contact information. |
contact_ | Skype names listed in the threat actor's contact information. |
contact_ | ICQ contacts listed in the threat actor's contact information. |
contact_ | CDN entries listed in the threat actor's contact information. |
contact_ | IP address ranges listed in the threat actor's contact information. |
social_ | The threat actor's Twitter (X) accounts. |
social_ | The threat actor's Vimeo accounts. |
websites | Websites linked to the threat actor. |
payment_ | Bitcoin addresses in the threat actor's payment information. |
payment_ | Ethereum addresses in the threat actor's payment information. |
origin_ | The threat actor's countries of origin; the Most Actor Hosting Countries statistic counts actors per origin country. |
leak_ | Names of leaks linked to the threat actor. |
forum_ | Names of the forums the threat actor is active on. |
market_ | Names of the markets the threat actor is active on. |
forum_ | The usernames the threat actor uses on forums and markets. |
targeted_ | The regions the threat actor has targeted. |
targeted_ | The countries the threat actor has targeted; the Most Targeted Countries statistic counts them. |
targeted_ | The industries the threat actor has targeted; the Most Targeted Industries statistic counts them. |
targeted_ | The organizations the threat actor has targeted; the Most Targeted Organizations statistic counts them. |
cves_ | CVE IDs of the vulnerabilities the threat actor has used; the Most Used CVEs statistic counts them. |
tools_ | The tools the threat actor has used; the Most Used Tools statistic counts them. |
Operators eq in gte lte exists
| Field | Description |
|---|---|
date_ | When the threat actor's profile was last updated (UTC date-time). |
date_ | When the threat actor was first seen (UTC date-time). |
date_ | When the threat actor was last seen active (UTC date-time). |
Operators eq exists
| Field | Description |
|---|---|
is_ | Whether the threat actor is considered active. |
Sortable Fields
| Field | Description |
|---|---|
name | The threat actor's main name; other names are in aliases. |
date_ | When the threat actor's profile was last updated (UTC date-time). |
date_ | When the threat actor was first seen (UTC date-time). |
date_ | When the threat actor was last seen active (UTC date-time). |
is_ | Whether the threat actor is considered active. |
actor_ | The threat actor's size, as text. |
actor_ | The threat actor's level of sophistication, as text. |
Response Fields
| Field | Type | Description |
|---|---|---|
page | integer | |
page_ | integer | |
result_ | integer | |
results | array of object | |
results[]. | string | |
results[]. | string | |
results[]. | array of string | |
results[]. | string | date-time |
results[]. | string | date-time |
results[]. | string | date-time |
results[]. | boolean | |
results[]. | string | |
results[]. | array of string | |
results[]. | string | |
results[]. | array of string | |
results[]. | string | |
results[]. | string | |
results[]. | object | |
results[]. | object | |
results[]. | array of string | |
results[]. | object | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string | |
results[]. | array of string |
Paginated. See Getting Started → Pagination.
Response Schema
Inferred from examples Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.
| Field | Type | Example |
|---|---|---|
page | number | 1 |
page_size | number | 25 |
result_count | number | 0 |
results | array |
Examples
Selecting one loads it into the request and response panels.