2.1 — Threat Actors

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/24

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:37 PM on 9/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

25 Terms

1
New cards

Threat Actor

An individual or group responsible for a security event or attack.

2
New cards

Internal Threat Actor

A threat actor operating from inside an organization, often with legitimate access or knowledge of internal systems.

3
New cards

External Threat Actor

A threat actor operating from outside the organization.

4
New cards

Threat Actor Resources and Funding

The money, tools, personnel, and infrastructure available to a threat actor.

5
New cards

Threat Actor Sophistication

The technical skill and capability a threat actor has to develop, modify, and execute attacks.

6
New cards

Threat Actor Motivation

The reason a threat actor conducts an attack, such as money, ideology, espionage, revenge, or disruption.

7
New cards

Nation-State

Government-associated threat actor with extensive funding, resources, and technical sophistication.

8
New cards

Nation-State Motivation

Often espionage, political objectives, disruption, or warfare.

9
New cards

Advanced Persistent Threat APT

A sophisticated and well-resourced threat that can maintain long-term access to a target, often associated with nation-state activity.

10
New cards

Stuxnet

Example of sophisticated malware designed to target nuclear centrifuges.

11
New cards

Unskilled Attacker

Threat actor with limited technical knowledge who commonly uses existing scripts and attack tools.

12
New cards

Unskilled Attacker Limitation

May successfully use existing tools but have difficulty modifying an attack when it fails.

13
New cards

Hacktivist

Threat actor motivated by political or philosophical beliefs rather than primarily by money.

14
New cards

Hacktivist Activities

May perform denial-of-service attacks, website defacement, or leak information to promote a cause.

15
New cards

Insider Threat

Threat originating from someone inside the organization who already has legitimate access or internal knowledge.

16
New cards

Insider Threat Advantage

Already understands internal systems and may have authorized access that can be abused.

17
New cards

Insider Threat Motivation

May include revenge or financial gain.

18
New cards

Organized Crime

Well-funded and sophisticated criminal groups primarily motivated by financial gain.

19
New cards

Organized Crime Motivation

Money and profit.

20
New cards

Shadow IT

Hardware, software, or services used within an organization without approval or control from the IT department.

21
New cards

Shadow IT Risk

Can bypass security reviews, backups, change controls, and other organizational security processes.

22
New cards

Nation-State vs Organized Crime

Nation-states are commonly motivated by government objectives or espionage, while organized crime is primarily motivated by financial gain.

23
New cards

Hacktivist vs Organized Crime

Hacktivists are primarily motivated by ideology, while organized crime is primarily motivated by money.

24
New cards

Insider vs External Threat

An insider already has organizational access or knowledge, while an external attacker begins outside the organization.

25
New cards

Threat Actor vs Threat Vector

Threat actor identifies who performs the attack, while threat vector describes how the attack reaches the target.