🎉 New here? Use code WELCOME10 for 10% off any plan at checkout
TL;DR

What the APT Rosetta Stone does

  • Cross-references 172 threat actors from Microsoft’s official naming taxonomy with aliases from CrowdStrike, Mandiant, ESET, Kaspersky, and community names.
  • Search by any name — type "APT29" and find Midnight Blizzard (Microsoft), COZY BEAR (CrowdStrike), and NOBELIUM (legacy Microsoft).
  • Filter by origin country or category: China, Russia, Iran, North Korea, financially motivated, and 18 more.
  • Expand any actor to see the full alias list with origin details.
  • Export matching results as CSV for threat-intel reports, SOC playbooks, or SIEM correlation rules.
Threat Intelligence · free

APT Naming Rosetta Stone

172 threat actors from Microsoft’s official naming taxonomy, cross-referenced with 448 aliases from CrowdStrike, Mandiant, ESET, Kaspersky, and others. Search by any name — Microsoft, CrowdStrike PANDA/BEAR/KITTEN, Mandiant UNC/APT, or community names.

Data source: Microsoft Threat Actor List (XLSX) · Published by Microsoft Threat Intelligence (MSTIC / MSECR).

172
Threat Actors
448
Known Aliases
20
Origin Categories
China
Most Actors (46)
Actors by origin — click a bar to filter
Showing all 172 actors

Frequently asked questions

What is the Microsoft threat actor naming taxonomy?

In April 2023, Microsoft switched from element-based names (like NOBELIUM) to weather-based names (like Midnight Blizzard). The weather type encodes the suspected nation-state or motivation: Typhoon for China, Blizzard for Russia, Sandstorm for Iran, Sleet for North Korea, Tempest for financially motivated actors, Flood for influence operations, and others. This tool maps every Microsoft name to its equivalents at CrowdStrike, Mandiant, and the broader threat-intel community.

Where does this data come from?

The authoritative source is Microsoft’s official threat actor list spreadsheet, published by the Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Exposure & Countermeasures Research (MSECR). The alias cross-references are compiled by the same team. This tool presents their data in a searchable format.

How do I decode a CrowdStrike PANDA/BEAR/KITTEN name?

CrowdStrike uses animal names to encode origin: PANDA for China, BEAR for Russia, KITTEN for Iran, CHOLLIMA for North Korea, SPIDER for eCrime, JACKAL for hacktivists, LEOPARD for Pakistan, BUFFALO for Vietnam. Type the CrowdStrike name in the search box to find the corresponding Microsoft and community names.

Can I use this for SIEM or SOAR correlation?

Yes. Export the CSV and use it to build correlation rules or lookup tables. When your SIEM alerts on "APT28", you’ll know it’s the same group as Forest Blizzard (Microsoft), FANCY BEAR (CrowdStrike), and Sofacy/Sednit (community names).

Is this free?

Yes, completely free with no signup. Searching, filtering, and CSV export all run in your browser. No data is sent to any server.

APT Naming Rosetta Stone — Translate Threat Actor Names (Free) · PlayCISO