Threat Group Profile
Definition
An ATT&CK entry for a named threat actor, listing the techniques attributed to that group based on public reporting. Analysts use group profiles to prioritise detection of techniques relevant to adversaries who target their sector or region.
- Source framework
- MITRE ATT&CK
- Content
- Techniques attributed to a named group
- Basis
- Public reporting
- Use
- Prioritise detection for relevant adversaries
Common questions
How reliable is a threat group profile as a complete picture of that actor?+
Profiles reflect only publicly reported and attributed activity, so a group's actual technique set may be broader than what appears in the entry, and older or unreported techniques may be missing as detection blind spots.
How do defenders use a group profile in practice?+
Analysts cross-reference the group's listed techniques against their own detection coverage to find gaps, prioritising new detections for techniques most relevant to actors known to target their sector.
Related terms
- ATT&CK Navigator
- A free, browser-based visualisation tool from MITRE that renders the ATT&CK matrix as an interactive heat map. Teams use it to annotate...
- Sub-Technique
- A finer-grained variation of a technique, identified with a decimal suffix such as T1059.001 for PowerShell under the Command and Scripting Interpreter...
- Tactic
- The adversary's high-level objective at a given stage of the attack: for example, Initial Access, Execution, Persistence, Privilege Escalation, or Exfiltration. ATT&CK...
- Technique
- A specific method an adversary uses to achieve a tactic. Each technique has a unique identifier such as T1059 (Command and Scripting...
- TTP (Tactics, Techniques, and Procedures)
- The three levels of specificity used to describe attacker behaviour. Tactics are the goal (e.g., persistence). Techniques are the method (e.g., scheduled...