# Threat Actor **Entity class:** Adversarial-security concept ## Definition A **threat actor** is an individual, group, organization, or state that intentionally pursues harmful action against a protected system or asset. The term emphasizes agency, objective, capability, and behavior rather than the weakness being exploited. ## Relevance to this collection A dangerous individual can be the threat actor, while trusted access and surrounding control weaknesses constitute the vulnerability-bearing condition. Keeping these roles distinct makes the human-CVE ontology precise. ## Relationships - **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]]. - **sociotechnical system:** [[wiki/Sociotechnical Attack Surface|Sociotechnical Attack Surface]]. ## Sources / Provenance - [NIST Computer Security Resource Center, “Threat Source” glossary](https://csrc.nist.gov/glossary/term/threat_source) (accessed 2026-09-23). **As of:** 2026-09-23