Cyber Risk Management - Threat Identification and APTs

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/75

flashcard set

Earn XP

Description and Tags

Comprehensive vocabulary flashcards covering threat identification, STRIDE, DREAD, CVSS, threat actors, APT lifecycles, and risk management strategies from Lessons 7 and 8.

Last updated 5:40 PM on 10/5/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

76 Terms

1
New cards
<p>Asset, Threat, and Vulnerability Trio</p>

Asset, Threat, and Vulnerability Trio

The fundamental cybersecurity relationship where an Asset is something valuable, a Threat is what we defend against, and a Vulnerability is a gap or weakness undermining defenses, intersecting to form Risk.

2
New cards

Passive Attacks

Attacks such as eavesdropping, packet sniffing, and traffic analysis aimed at gathering information without altering data, which violates confidentiality.

3
New cards

Active Attacks

Attacks involving unauthorized system alterations—such as data modification, Denial of Service (DoS), and spoofing—that target integrity and availability.

4
New cards

Cybercriminals

Profit-driven threat actors relying heavily on ransomware, phishing, identity theft, and Cybercrime-as-a-Service (CaaS).

5
New cards

Hacktivists

Ideologically or socially motivated threat actors seeking public embarrassment through DDoS attacks, website defacements, and doxxing.

6
New cards

Nation-States / APTs

Highly funded, politically or strategically motivated actors focusing on long-term espionage, critical infrastructure targeting, and IP theft that adapt, pivot, or bypass rather than abandon targets when blocked.

7
New cards

Insider Threats

Malicious or negligent internal personnel, partners, or stakeholders who misuse legitimate credentials or access to compromise systems or leak data.

8
New cards

Script Kiddies

Amateur threat actors who utilize pre-made tools without understanding the underlying code.

9
New cards

Zero-Day Exploits

Cyberattacks targeting unknown, unpatched software vulnerabilities before security patches are available.

10
New cards

Supply Chain Attacks

Cyberattacks that target third-party vendors or software suppliers (nth Party) to compromise a primary target organization.

11
New cards

STRIDE Model

A threat modeling framework developed by Microsoft that categorizes threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

12
New cards

Spoofing

Pretending to be someone else to violate system authenticity.

13
New cards

Tampering

Unauthorized alteration of data or information, violating system integrity.

14
New cards

Repudiation

Performing an action while denying responsibility without proof, violating non-repudiation.

15
New cards

Elevation of Privilege

Gaining unauthorized administrative or elevated access rights, violating system authorization.

16
New cards

PASTA (Process for Attack Simulation and Threat Analysis)

An attacker-centric threat modeling methodology that aligns business objectives with technical threats.

17
New cards

VAST (Visual, Agile, and Strategic Threat Modeling)

A threat modeling framework scalable across large software development pipelines.

18
New cards

Data Flow Diagram (DFD)

A visual diagram used in threat modeling to map system boundaries, processes, data stores, and external entities, identifying threats as data flows cross trust boundaries.

19
New cards

Network Indicators of Compromise (IoCs)

Network-level artifacts such as unusual outbound traffic patterns, spikes in data transfer, or connections to known bad IP addresses.

20
New cards

Host Indicators of Compromise (IoCs)

System-level artifacts including unauthorized registry alterations, unexpected file modifications, or rogue administrator accounts.

21
New cards

DREAD Scoring System

A threat assessment system evaluating Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability.

22
New cards

CVSS (Common Vulnerability Scoring System)

An industry standard framework providing numerical vulnerability severity scores from 0.00.0 to 10.010.0 based on Base, Temporal, and Environmental metrics.

23
New cards

Threat Register

A risk management log that organizes threat data by Threat ID, Description, Threat Actor, Associated Vulnerability, and Risk Score.

24
New cards

Cybercrime-as-a-Service (CaaS)

A business model in which cybercriminals purchase malware kits, zero-day exploits, and access credentials from external providers.

25
New cards

Living off the Land (LotL)

A post-exploitation technique where attackers use legitimate, native administrative tools like PowerShell or WMI to evade detection.

26
New cards

Pass-the-Hash (PtH) Attacks

Attacks using stolen password hashes to authenticate across systems without requiring cleartext passwords.

27
New cards

SolarWinds Supply Chain Attack

A 2020 supply chain attack attributed to Russian Foreign Intelligence Service (SVR/Cozy Bear-APT29) that injected malicious code into software updates for SolarWinds Orion.

28
New cards

MTTD and MTTC

MTTD (Mean Time to Detect) measures how quickly an organization discovers a threat, while MTTC (Mean Time to Contain) measures how quickly an organization isolates the threat to stop harm.

29
New cards

MITRE ATT&CK Framework

A globally accessible knowledge base documenting real-world adversary tactics, techniques, and procedures (TTPs).

30
New cards

Strategic Cyber Threat Intelligence

High-level threat intelligence analyzing broad trends, geopolitical alignments, and threat motivations for executive boardrooms.

31
New cards

Operational Cyber Threat Intelligence

Threat intelligence detailing upcoming threat actor campaigns, specific capabilities, and active attack vectors.

32
New cards

Tactical Cyber Threat Intelligence

Technical threat intelligence providing immediate Indicators of Compromise (IoCs) such as IP addresses, file hashes, and domain registries.

33
New cards

Zero Trust Architecture

A security framework operating on the principle 'never trust, always verify,' eliminating implicit internal network trust.

34
New cards

War Exclusion Clause

A traditional insurance policy clause excluding damages caused by military action or sovereign conflict, which creates legal debate when applied to nation-state cyberattacks.

35
New cards

Merck & Co. v. Ace American Insurance Co.

A key legal benchmark ruling that a traditional war exclusion clause did not apply to the state-sponsored NotPetya malware attack.

36
New cards
<p>Asset, Threat, and Vulnerability Trio</p>

Asset, Threat, and Vulnerability Trio

A foundational risk model where an Asset is something valuable, a Threat is something being defended against, a Vulnerability is a gap or weakness undermining defense, and Risk is their intersection.

37
New cards

Threat Agent

Any individual, group, or entity that initiates an action to compromise an information system, evaluated by intent, capability, and opportunity.

38
New cards

Passive Attack

An attack aimed at gathering information without altering data (such as eavesdropping, packet sniffing, and traffic analysis), violating confidentiality.

39
New cards

Active Attack

An attack involving unauthorized alterations to systems (such as data modification, Denial of Service, and spoofing), violating integrity and availability.

40
New cards

Cybercriminals

Profit-driven threat actors relying heavily on ransomware, phishing, identity theft, and Cybercrime-as-a-Service (CaaS).

41
New cards

Nation-States / APTs

Politically or strategically motivated threat actors funded by sovereign government budgets that focus on long-term espionage, IP theft, and critical infrastructure disruption.

42
New cards

Hacktivists

Ideologically or socially motivated threat actors who use tactics like website defacements, doxxing, and DDoS attacks to cause public embarrassment for a cause.

43
New cards

Insider Threats

Disgruntled employees seeking revenge/espionage or negligent staff who ignore policies and misuse legitimate internal privileges.

44
New cards

Script Kiddies

Amateur threat actors who use pre-made attack tools without understanding the underlying code.

45
New cards

Supply Chain Attacks

An emerging threat targeting third-party vendors (nthn^{\text{th}} Party) to compromise a larger primary target organization.

46
New cards

Zero-Day Exploits

Attacks targeting unknown, unpatched software vulnerabilities where vendor patches are not yet available.

47
New cards

STRIDE Model

A Microsoft threat modeling framework assessing Spoofing identity, Tampering with data, Repudiation, Information disclosure, Denial of Service, and Elevation of privilege.

48
New cards

Spoofing

Pretending to be someone else (such as an administrator), which violates Authenticity.

49
New cards

Tampering

Altering information without permission (such as unauthorized database modification), which violates Integrity.

50
New cards

Repudiation

Denying an action without proof (such as deleting system logs to deny a malicious action), which violates Non-repudiation.

51
New cards

Information Disclosure

Data leakage or unauthorized data exfiltration, which violates Confidentiality.

52
New cards

Denial of Service (DoS)

Overwhelming resources or crashing systems to render them unavailable, which violates Availability.

53
New cards

Elevation of Privilege

Gaining unauthorized access rights (such as escalating from a guest account to admin rights), which violates Authorization.

54
New cards

PASTA

Process for Attack Simulation and Threat Analysis; an attacker-centric methodology that aligns business objectives with technical threats.

55
New cards

VAST

Visual, Agile, and Strategic Threat Modeling; a threat modeling framework designed to scale across large software development pipelines.

56
New cards

Threat Modeling

A structured approach to identifying, quantifying, modeling, prioritizing security, and mitigating threats relative to software, networks, or business processes.

57
New cards

Data Flow Diagram (DFD)

A diagramming tool used to visualize boundaries, data stores, external entities, and processes to identify threats as data crosses trust boundaries.

58
New cards

DREAD Scoring System

A threat assessment system evaluating Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability.

59
New cards

CVSS

Common Vulnerability Scoring System; an industry standard framework rating vulnerability severity from 0.00.0 to 10.010.0 (Critical) by combining Base, Temporal, and Environmental metrics.

60
New cards

Threat Register

A risk management database organizing threat data by Threat ID, Description, Threat Actor, Associated Vulnerability, and Score.

61
New cards
<p>Threat Agent Taxonomy</p>

Threat Agent Taxonomy

A classification structure categorizing threat agents (Cybercriminals, Hacktivists, Insiders, Nation-States, Corporate Espionage) by motivation, capability level, and primary targets.

62
New cards

Advanced Persistent Threat (APT)

A well-funded, human-driven threat actor using customized stealthy malware and engineered zero-day exploits to carry out a specific, long-term "low and slow" mission.

63
New cards

Living off the Land (LotL)

A persistence tactic where attackers use legitimate, native administrative tools (such as PowerShell or WMI) to perform operations without triggering security detections.

64
New cards

Pass-the-Hash (PtH) Attack

An attack technique where threat actors use extracted password hashes to authenticate across network systems without needing cleartext passwords.

65
New cards

Lateral Movement

Systematically hopping horizontally from workstation level to server level access across internal corporate network zones (East-West traffic).

66
New cards

Command & Control (C2) Channels

Covert communication lines established between compromised internal hosts and external malicious infrastructure to direct attacks and exfiltrate data.

67
New cards

SolarWinds Supply Chain Attack (2020)

A major cyber attack attributed to Russian Foreign Intelligence Service (SVR/Cozy Bear-APT29) that injected malicious code into software updates for SolarWinds Orion, compromising over 18,000 organizations.

68
New cards

Mean Time to Detect (MTTD)

A high-value business metric measuring how quickly an organization discovers a threat or vulnerability in its environment to minimize attacker dwell time.

69
New cards

Mean Time to Contain (MTTC)

A critical metric measuring how quickly an organization isolates an active threat to halt further operational or data harm.

70
New cards

MITRE ATT&CK Framework

A globally accessible open knowledge base of adversary tactics, techniques, and procedures (TTPs) used to build behavior profiles and run security simulations.

71
New cards

Strategic Cyber Threat Intelligence

High-level intelligence covering overall threat trends, geopolitical alignments, and adversary motivations tailored for executive boardrooms.

72
New cards

Operational Cyber Threat Intelligence

Intelligence offering specific details into upcoming threat actor campaigns, technical capabilities, and active attack vectors.

73
New cards

Tactical Cyber Threat Intelligence

Direct technical Indicators of Compromise (IoCs) including IP addresses, file hashes, and domain registries.

74
New cards

Zero Trust Architecture

A security methodology based on the principle of "Never trust, always verify," eliminating implicit trust inside internal networks.

75
New cards

War Exclusion Clause

A traditional insurance policy provision excluding damages caused by military action or sovereign conflict, creating legal coverage disputes when attributing nation-state APT attacks.

76
New cards

Merck & Co. v. Ace American Insurance Co.

A benchmark legal ruling establishing that a traditional war exclusion clause did not apply to the state-sponsored NotPetya malware attack.