<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/collaborative-effort-to-standardize-threat-actor-naming-in-cybersecurity-1fzag9cxq" -->

---
title: Collaborative Effort to Standardize Threat Actor Naming...
description: Microsoft and CrowdStrike have launched a collaboration to address the confusion caused by inconsistent threat actor naming across cybersecurity vendors. Their...
canonical: https://daily.dev/posts/collaborative-effort-to-standardize-threat-actor-naming-in-cybersecurity-1fzag9cxq
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Collaborative Effort to Standardize Threat Actor Naming in Cybersecurity | daily.dev
og:description: Microsoft and CrowdStrike have launched a collaboration to address the confusion caused by inconsistent threat actor naming across cybersecurity vendors. Their...
og:url: https://daily.dev/posts/collaborative-effort-to-standardize-threat-actor-naming-in-cybersecurity-1fzag9cxq
og:image: https://api.daily.dev/og/posts/1fzaG9Cxq.png
og:image:alt: Collaborative Effort to Standardize Threat Actor Naming in Cybersecurity
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Collaborative Effort to Standardize Threat Actor Naming in Cybersecurity

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 1 upvotes · 0 comments

## Summary

Microsoft and CrowdStrike have launched a collaboration to address the confusion caused by inconsistent threat actor naming across cybersecurity vendors. Their solution creates a mapping system that cross-references different aliases used for the same hacking groups, rather than enforcing a single naming standard. The initiative has already mapped over 80 threat actors and is supported by Google Mandiant and Palo Alto Networks. This effort aims to reduce the 15-30% of time security analysts currently waste on attribution confusion and improve incident response efficiency.

## Content

# Microsoft and CrowdStrike Tackle Threat Actor Naming Confusion

In the world of cybersecurity, the variability in naming conventions for threat actors has long posed challenges for security analysts and incident response teams. With multiple vendors referring to the same hacking groups by different names, the industry has faced significant inefficiencies and confusion. To address this issue, Microsoft and CrowdStrike have announced a collaboration aimed at creating clarity in threat actor naming.

## The Cyber Rosetta Stone Initiative

Recognizing the complexity of standardizing names across different vendors, Microsoft and CrowdStrike propose a nuanced solution: a mapping system akin to a "cyber Rosetta Stone." This system lists multiple aliases used by various cybersecurity platforms for the same groups, facilitating easier cross-referencing without imposing a single naming standard.

While the initiative promises greater clarity, it stops short of unifying naming schemes. Experts cite technical challenges, intelligence protection, and marketing considerations as barriers to adopting a uniform standard. Despite promises of a streamlined process, each vendor maintains its unique naming conventions, which can cause interoperability issues.

## Aligning Threat Actors

So far, more than 80 threat actors have been successfully mapped through this initiative. Among the notable aligned names are Cozy Bear, also known as Midnight Blizzard, APT29, or UNC2452. The collaboration between Microsoft and CrowdStrike is further supported by Google Mandiant and Palo Alto Networks Unit 42, bringing critical insights and expertise to the table.

## Impact on Cybersecurity

The chaos in threat actor naming is known to waste 15-30% of security analysts' time, hindering effective incident response. The mapping system created by Microsoft and CrowdStrike is expected to help security professionals better connect insights and make more informed decisions, thus minimizing delays in incident response.

However, the constant evolution of threat groups and differing confidence levels between vendors remain challenges to the initiative’s success. There is a need to continually update the mappings to ensure accuracy and relevance as threat landscapes change.

In conclusion, the collaboration between Microsoft, CrowdStrike, and other leading cybersecurity entities seeks to reduce attribution confusion without enforcing a monolithic naming standard. Through sharing and mapping, the initiative aims to bring greater transparency and efficiency to the cybersecurity community.

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#microsoft](https://daily.dev/tags/microsoft)

[View this post on daily.dev](https://daily.dev/posts/collaborative-effort-to-standardize-threat-actor-naming-in-cybersecurity-1fzag9cxq)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Collaborative Effort to Standardize Threat Actor Naming in Cybersecurity","url":"https://daily.dev/posts/collaborative-effort-to-standardize-threat-actor-naming-in-cybersecurity-1fzag9cxq","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/collaborative-effort-to-standardize-threat-actor-naming-in-cybersecurity-1fzag9cxq"},"datePublished":"2025-06-03T13:03:37.008Z","dateModified":"2025-06-03T22:26:01.855Z","description":"Microsoft and CrowdStrike have launched a collaboration to address the confusion caused by inconsistent threat actor naming across cybersecurity vendors. Their...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a21c5e9ce7bb09a0dfb5d286bf74067e?_a=AQAEulh","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/a21c5e9ce7bb09a0dfb5d286bf74067e?_a=AQAEulh","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/collaborative-effort-to-standardize-threat-actor-naming-in-cybersecurity-1fzag9cxq","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,microsoft","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Collaborative Effort to Standardize Threat Actor Naming in Cybersecurity"}]}
```

