{
    "type": "bundle",
    "id": "bundle--e17c7368-dc46-41e7-864c-6a9ed072f7e1",
    "objects": [
        {
            "type": "identity",
            "spec_version": "2.1",
            "id": "identity--a361b290-d09a-4e0e-a13d-681ca0c3dcc7",
            "created": "2023-03-08T12:51:43.404685Z",
            "modified": "2024-08-31T04:09:59.408166Z",
            "name": "Microsoft",
            "identity_class": "organization"
        },
        {
            "type": "threat-actor",
            "spec_version": "2.1",
            "id": "threat-actor--0f4c4657-f9bc-5abe-bace-19905645a02b",
            "created": "2026-06-24T19:51:05.740595Z",
            "modified": "2026-06-24T19:51:05.740595Z",
            "name": "Sleet"
        },
        {
            "type": "report",
            "spec_version": "2.1",
            "id": "report--cad932ba-7c78-4238-85d7-78a13c3c0472",
            "created_by_ref": "identity--a361b290-d09a-4e0e-a13d-681ca0c3dcc7",
            "created": "2026-06-24T19:51:05.741666Z",
            "modified": "2026-06-24T19:51:05.741666Z",
            "name": "How Microsoft names threat actors - Unified security operations",
            "published": "2025-06-03T00:00:00Z",
            "object_refs": [
                "identity--a361b290-d09a-4e0e-a13d-681ca0c3dcc7",
                "threat-actor--0f4c4657-f9bc-5abe-bace-19905645a02b"
            ],
            "external_references": [
                {
                    "source_name": "source",
                    "url": "https://learn.microsoft.com/en-us/unified-secops-platform/microsoft-threat-actor-naming"
                }
            ]
        }
    ]
}