Threat Actor Categories

Retrieve the full threat actor category taxonomy used across Recorded Future.

What this endpoint does

Returns Recorded Future's complete taxonomy of threat actor categories — a reference list of all classification types used to categorize cyber threat actor groups. Categories classify actors by nation-state affiliation (China, Russia, Iran, North Korea, etc.), motivation (financially motivated, hacktivist), operational type (ransomware groups, MageCart groups, mobile APT), or community membership (underground forum, dark web market). Use category IDs to filter results in Threat Actor Threat Map and Threat Actor Threat Map (Org). No parameters needed — returns all 34 categories in one response.

Response data

Returns the full classification taxonomy for threat actors — use this as a lookup table to understand what categories mean when they appear on actors in search results and threat maps. Categories include multilingual aliases (e.g., Russian Nation State Sponsored includes aliases in Korean, Arabic, Chinese, and Farsi) which are useful for cross-source intelligence correlation. The taxonomy is relatively stable (currently 34 categories) so you can cache this response. Category IDs are the filter keys accepted by the threat map endpoints — match category IDs from an actor's profile to this taxonomy to understand their classification.

Response

Language
Credentials
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json