Enrich Actor Profiles With Current IOCs
Analyst question: What observables are connected to an actor or malware family?
When To Use This
Use this workflow when you need a repeatable, evidence-aware way to move from raw intelligence to structured CTI output inside AdversaryGraph.
Workflow
- Open an actor page.
- Use the IOCs tab to review current observables.
- Sync ThreatFox or enrich from OTX/Malpedia/custom feeds.
- Export actor IOCs as CSV when needed.
- Review mapped TTPs or unmapped observables.
Expected Output
Actor-linked IOC set with source, type, first/last seen, malware family, and optional TTP mapping.
Quality Checks
- Validate every technique against the source evidence.
- Treat similarity and enrichment as analytical signals, not final conclusions.
- Mark weak mappings as
needs-evidenceorrejectedinstead of forcing them into the final layer. - Export only reviewed data when using results for customer, SOC, or detection engineering handoff.
Related Platform Areas
- AI Analysis
- ATT&CK Navigator
- ATT&CK Group Library
- IOC Library
- Reference Sync
- Report export