# Threat Actor
**Entity class:** Adversarial-security concept
## Definition
A **threat actor** is an individual, group, organization, or state that intentionally pursues harmful action against a protected system or asset. The term emphasizes agency, objective, capability, and behavior rather than the weakness being exploited.
## Relevance to this collection
A dangerous individual can be the threat actor, while trusted access and surrounding control weaknesses constitute the vulnerability-bearing condition. Keeping these roles distinct makes the human-CVE ontology precise.
## Relationships
- **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]].
- **sociotechnical system:** [[wiki/Sociotechnical Attack Surface|Sociotechnical Attack Surface]].
## Sources / Provenance
- [NIST Computer Security Resource Center, “Threat Source” glossary](https://csrc.nist.gov/glossary/term/threat_source) (accessed 2026-09-23).
**As of:** 2026-09-23