Cross-Domain Concepts Borrowed by CI

Threat Actor Profiling

Updated July 21, 2026

Building a behavioral model of a specific competitor (their patterns, decision cadence, resource allocation) to predict future moves.

Also known as: Adversary profiling, Threat actor analysis, Behavioral profiling

Threat actor profiling is the practice of building a behavioral model of a specific adversary (their motivations, resources, capability, decision cadence, and signature playbook) so analysts can predict that actor's next move rather than merely react to the last one. The output is a reusable profile: a named entity, the patterns it reliably exhibits, the conditions that trigger it to act, and the indicators that would confirm it has begun to move. In cybersecurity, where the term is established, profiling turns raw incident telemetry into actor-specific intelligence; in competitive intelligence, the borrowing is explicit and metaphorical, applied to a specific commercial rival rather than a named threat group.

The lineage is well documented. National-security and computer-network defense have profiled adversaries since at least the rise of named APT groups in the 2000s, and the practice is now institutionalized in public frameworks. MITRE ATT&CK catalogues tactics, techniques, and procedures observed across named threat groups, and the Diamond Model of Intrusion Analysis, published in 2013 by Andrew Caltagirone, Greg Pizzi, and Justin Blackwood, formalized adversary profiling around four vertices: adversary, victim, capability, and infrastructure. ENISA's annual Threat Landscape reports extend the same approach at sector scale.

Competitive intelligence borrowed the word, not the doctrine. There is no canonical CI author or framework for profiling a commercial rival, and practitioners who use the term mean it operationally: a working behavioral model of one competitor, built from public signals, refreshed continuously, and used to forecast that rival's likely response to a market event. The honesty matters. The cyber original is an established discipline with named groups, shared taxonomies, and curated TTP knowledge bases; the CI variant is a metaphor that profits from the same structure but cannot claim equivalent rigor.

How cybersecurity builds a threat actor profile

A cyber threat actor profile aggregates four kinds of evidence. Identity and sponsorship establish who the actor is and whether they are state-aligned, criminal, hacktivist, or insider. Motivation (financial, espionage, disruption, ideology) narrows the targets and effects the actor tries to produce. Capability rates technical sophistication, from script-kidie tooling through custom zero-day development, and together with resource reach decides whether the actor can sustain a campaign or only attempt one-shot intrusions. Tactics, techniques, and procedures (the TTP set) capture the repeatable behavioral signature, the indicators that let an analyst recognize the same actor across incidents.

Two public references cement the practice. MITRE ATT&CK maintains a knowledge base of TTPs mapped to named groups, software, and campaigns so defenders can reason about specific adversaries rather than generic threats. The Diamond Model of Intrusion Analysis (Caltagirone, Pizzi, Blackwood, 2013) frames every intrusion event as a relationship among adversary, victim, capability, and infrastructure, arguing that profiling is a search for the recurring adversary-victim pairing and the capability-credential chain that links them.

What a CI borrowing keeps and drops

Competitive intelligence keeps the four-vertex structure and drops most of the rigor. For a specific rival, the analog of identity and sponsorship is the competitor's stated strategy and ownership: public versus private, growth-stage versus incumbent, PE-backed versus independent. The analog of motivation is the rival's incentive structure: which segments pay their bills, who they report to, what their last funding or earnings call said they need to deliver. Capability maps to product and engineering depth, distribution reach, and price flexibility. The analog of TTPs is the rival's observable playbook: how they launch, how they price, how they respond to your launches, where they hire.

What CI cannot keep is the shared taxonomy and the curated indicator library. Cyber threat intelligence benefits from named groups and an industry-wide ATT&CK catalogue; a CI team profiling a commercial rival has no comparable shared reference and must build the model from its own monitoring. The result is useful but insular: a profile that works for predicting this rival and no one else.

Concrete profile dimensions for a B2B SaaS rival

The dimensions that earn their keep in a SaaS CI profile are behavioral, not demographic. Product launch cadence distinguishes a quarterly-enterprise rival from a monthly-PLG one and sets a prior for when the next release lands. Pricing change frequency and direction, observed on the pricing page over time, mark rivals that test aggressively from those that hold for years. Executive social-media and keynote patterns reveal which messages a rival is investing in: a CEO who suddenly posts about enterprise compliance is signaling where the next product investment will land.

M&A appetite separates acquisitive rivals who will buy market entry from organic ones who will build it. Response lag, measured across the last several of your launches and theirs, is the single most predictive number in a profile: do they counter within a week (a fast-follower with a standing war room), within a quarter (a normal cadence), or not at all (a rival that does not consider you a priority)? Hiring patterns by region and role add a forward indicator, since investment precedes launches. Each dimension is a separate feed to instrument, and a profile accrues value only as it is refreshed.

Threat actor profiling vs. competitor-profile and threat-landscape

The glossary treats three adjacent concepts that answer different questions. A competitor-profile is a broad factual dossier: company, leadership, funding, products, customers, messaging: the kind of static background an analyst assembles once and updates annually. Threat actor profiling is narrower and behavioral: it asks not what the rival is but how the rival moves, with repeatable patterns that support prediction. The dossier tells you who; the profile tells you what they will do next.

Threat-landscape is the whole environment: every rival, substitute, regulatory force, and technology shift that could pressure your business, usually summarized at sector scale. Threat actor profiling is one-actor and predictive: it takes a single rival and models that rival's behavior in enough detail to forecast a response. Four-corners analysis reads a rival's intent and capability along adversary axes and complements a profile. Kill-chain describes the sequence the rival walks from internal decision to market impact, while the profile describes who is most likely to walk it and how fast.

Limitations and how models go wrong

The cyber original has documented limits: actor categories overlap, false-flag and impersonation are routine, and the same activity can be classified as criminal, ideological, or state-linked depending on analyst priors. NIST warns that any threat-source characterization is tied to a time frame and organizational context, and simple threat-vulnerability pairing breaks down as threats multiply.

The CI borrowing inherits worse. A commercial rival's internal decisions are largely invisible; the analyst sees outputs, not deliberation, and infers strategy from a thin public record. Rivals also change behavior in response to their own market, so a profile built under one market regime may mispredict under another. The two recurring failures are over-fitting, building a profile so detailed it explains the past but not the future, and halo projection, where one strong pattern (a fast response lag, say) leads the analyst to assume the rival is equally decisive on every other dimension. The honest use is a profile with explicit confidence levels, dated observations, and a record of what evidence would falsify the model.

Stop looking terms up. Start tracking them.

meertrack watches your competitors' websites, pricing, and hiring, then alerts you when something meaningful changes.

Or compare 11 CI tools side by side →

Frequently Asked Questions

What is threat actor profiling?

It means modeling one specific adversary's behavior (motivations, resources, capability, decision cadence, and repeatable playbook) so analysts can predict the next move rather than only react. In cybersecurity this is established practice for named threat groups, supported by public frameworks such as MITRE ATT&CK and the Diamond Model of Intrusion Analysis. CI borrows the metaphor to model one commercial rival.

Where does the term threat actor profiling come from?

From cybersecurity and national-security intelligence, where named adversary groups have been catalogued since the 2000s. MITRE ATT&CK maps tactics, techniques, and procedures to named groups, while the Diamond Model of Intrusion Analysis, which Andrew Caltagirone, Greg Pizzi, and Justin Blackwood published in 2013, frames profiling around adversary, victim, capability, and infrastructure. ENISA's yearly Threat Landscape reports carry the same approach to sector scale. In competitive intelligence the term is a metaphorical borrowing rather than a defined framework.

Threat actor profiling vs. competitor-profile: what is the difference?

A competitor-profile is a broad factual dossier of a rival: company, leadership, funding, products, customers, messaging, updated periodically as background. Threat actor profiling is narrower and behavioral: it models how the rival moves (launch cadence, pricing change frequency, response lag to your launches, hiring patterns) to support prediction. The dossier tells you who the rival is; the profile tells you what they will do next.

Threat actor profiling vs. threat-landscape: what is the difference?

The two answer different questions. Threat-landscape covers the full environment of pressures on a business (every rival, substitute, regulator, and technology shift) usually summarized at the sector level. Threat actor profiling is single-actor and predictive: it studies one rival closely enough to anticipate how that rival will respond to a specific event. Landscape work drives portfolio thinking; profiling drives a focused prediction about one competitor.

How do CI teams profile a SaaS rival behaviorally?

By tracking concrete, repeatable dimensions over time: product launch cadence (quarterly enterprise versus monthly PLG), pricing change frequency and direction observed on the pricing page, executive social-media and keynote patterns, M&A appetite, response lag to your own launches measured across the last several cycles, and hiring by region and role. Each dimension is a separate feed to instrument, and the profile accrues value only as it is refreshed continuously rather than rebuilt once a year.

Related terms

← Browse the full glossary

You run the business.

We'll watch the competition.

14 days free. 3 competitors. Cancel anytime.