Threat Actor Icon System
A scalable icon language for Microsoft's threat intelligence. It turns complex adversary profiles into one cohesive system, legible to security analysts worldwide.
Title: Senior Product Designer
Project-specific role: Lead Icon Designer
Team: Security Expressions Team, Security UX, for Microsoft Defender Threat Intelligence
Key Deliverables: Icon system, Usage guidance, Creation tools, Convention collateral and environmental touch pieces
A new taxonomy that needed
a visual language
Microsoft replaced its disjointed system of elements and "DEV" tags with an intuitive threat taxonomy built to handle 84 trillion daily signals. The system pairs descriptive adjectives with distinct weather patterns, using a vocabulary security teams already speak: forecasts, watches, hazards. The result: clear, memorable adversary profiles like Volt Typhoon and Midnight Blizzard.
That solved the naming problem. It left the visual one wide open.
The easy win: a weather symbol reads across a language barrier in a way previous metaphors never could.
The challenge: hundreds of individual actors (and counting) can't each get a bespoke icon.
I made a call early. The icon represents the group, region, or type. The modifier, whether adjective, color, or pattern, lives in the name itself.
Microsoft's own RSAC 2023 recap put it simply: the icon system was built to "make it even easier to identify and remember threat actors."
The tension I was designing for
Familiar
Built on Fluent's language, inheriting Microsoft's brand equity and already-tested production standards.
Ownable
Housed in a polygonal container found nowhere else in Fluent, so the icon reads as a Threat Actor before anyone parses the symbol inside it.
I treated alignment with Fluent as leverage, not a constraint to design around.
Those choices let us move fast without losing distinctiveness. They also made the system easier to defend at the executive level.
Every icon follows the same formula: a Fluent-inspired weather glyph, abstracted and rebuilt inside that hexagonal container, recognizable pieces reassembled into something ownable.
The core six
Rather than design in isolation, we prioritized the six most-referenced groups: Typhoon, Blizzard, Sandstorm, Sleet, Tempest, and Storm. We made those six maximally distinct from each other first, weighing line forms, angles, and negative space so each still read as one family.
Get the most visible icons right, and the rest of the family has a foundation to build upon.
That bet held up. The system now covers well over 300 tracked threat actors, tools, and vulnerabilities, far past what the original six were built for.
Take it, but don't break it
A system this visible needed rules simple enough for another designer, or an outside agency, to extend the library later.
Distinctive: never confused with another icon in the family
Consistent: built to Fluent's tested grid
Functional: regular and filled variants, light and dark theme support
Scalable: legible at 24, 28, 32, and 48px
I shipped full production documentation alongside it: grid construction, stroke weights by size, corner radius standards, even the exact boolean-operation sequence for building filled variants.
At this scale, I couldn't be the bottleneck. Quality control had to hold up without my direct oversight.
An ever-expanding library
Each icon had to be representative and recognizable when paired with its weather name, and read as part of one distinctive family. That meant weighing line forms, angles, negative space, legibility, and accessibility on every addition.
Impact
Simplified and memorable
One weather name, paired with one family icon, replaced years of inconsistent, hard-to-track actor names.
Scalable by design
Built to absorb new threat actors without a redesign each time.
Less confusion, better story
One glance gives SOC analysts context from 84 trillion daily threat signals.
Where the icons live today
These icons are a working part of Microsoft's day-to-day threat reporting. Years after launch, they still show up as the visual identifier on the Microsoft Security blog every time a new threat actor is covered: Blizzard, Sleet, Storm, and dozens more, layered into the featured image of incident write-ups published as recently as this year.
Built to be instantly recognizable, and to hold up over time across a wide range of applications.
Now public
Introduced publicly alongside the new naming taxonomy, and demoed live at RSA Conference 2023.
→ Read the taxonomy announcement on microsoft.com
→ Read the RSAC recap on microsoft.com
→ See the system in current use on the Microsoft Security Blog