Navigating the Threat Actor Maze: A Tool for Mapping Names, Families and Insights @FIRSTdotorg
Navigating the Threat Actor Maze: A Tool for Mapping Names, Families and Insights  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 7 hours ago
Dave Matthews (Avast (Gen Digital), AU)

After getting his PhD in Mathematics, Dave spent the next 25 years consulting for the Australian Government, primarily working with Defence, Intelligence, and Law Enforcement, before moving to CrowdStrike and Gen Digital (which was formed from the merger of Avira, Avast, and NortonLifelock). He has continually worked in Incident Response and Forensics and has had the privilege of helping people during their worst days at work.

He has experience with all aspects of cybersecurity, ranging from attack and defence to incident response and security capability development. He is particularly passionate about digital forensics and incident response, helping people prevent and recover from attacks and breaking down barriers to sharing information.
--
Overwhelmed with the myriad of Threat Actor names? Fancy Bear vs Forest Blizzard? Wicked Panda vs BRONZE ATLAS? What about malware families? CageyChameleon vs Cabbage RAT? Qakbot vs Pinkslipbot?In this talk, we release a free tool that enables mapping between different Threat Actor naming conventions and malware families. We demonstrate its use and show how it allows for easy offline search of threat actors and published research. It provides rapid access to Threat Actor and malware family information - undoubtedly helpful for your intelligence analysis, research and operational work.
Navigating the Threat Actor Maze: A Tool for Mapping Names, Families and InsightsStepping up the ENISAs role in Support of EU Vulnerability ServicesFrom Zero to Prepared: Implementing a Weekly Incident Response Drill ProgramIndicator Message eXchange (IMX): Enabling Structured Cyber Threat Intelligence SharingEpisode 57: Vijay Sarvepalli and Christopher Cullen, FIRSTCON26 SpeakersImproving Security Across Nations with FIRST: Éireann Leverett, FIRST LiaisonTechnical Recovery Plan (TRP) Exercise in a Cloud-Native Environment: Practical Lessons ...CVE Decaf: Brewing Better and More Actionable Data QualityLeveraging AI to Review and Strengthen Your Incident Response Plan: A Proof of ConceptWho Did It? Getting Started with Threat Actor ProfilingFIRSTCON26 Event RecapEpisode 59: Julie Agnes Sparks and Greg Foss, Datadog, FIRSTCON26 Speakers
FIRST |

Navigating the Threat Actor Maze: A Tool for Mapping Names, Families and Insights

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER