1/50
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Threat Actor
An individual or entity responsible for incidents that impact security and data protection
Threat Actor Motivators
War, Espionage, Money, Political and Philosophical beliefs, Data theft, revenge, ethics, disrupting service, blackmail
Threat Actors Intent
The goal of objective of the threat actor’s attack
Threat Actor Motivation
The reason why the threat actor attacked
Internal Threat Actors
These actors pose a security threat from within the organization
External Threat Actors
These actors attack the organization from the outside by breaching the cybersecurity defenses
Resources and funding the threat actor has available
Tools, skills, and personnel at the disposal of a given threat actor. Can show how capable the threat is
Level of sophistication and capability of the threat actor
The technical skill, how complex the tools and skills they use, and how well the evade countermeasures and detection
Script kiddies
Lowest skilled threat actors. Usually uses pre-made malware and exploits
Usually use sophisticated tools and techniques to attack cyber defenses
Nation-state actors, Advanced Persistent Threats (APD), Organized criminals, etc
Script Kiddie’s favorite method
DDoS attacks. Attack a simple IP address and flood it with requests
Hactivists
Groups of individuals that commit cyberattacks for ideological reasons. Political, Social Change, or personal
Hactivism
The action of hacking for ideological reasons
Hactivist techniques
Website defacement, DDoS (Distributed Denial of Service), Doxing, Leaking Sensitive data
Website Defacement
Hactivist method that involves vandalizing systems or websites
(Distributed Denial of Service) DDoS attacks
Overwhelming the victims servers or networks so they become unusable for legitimate users
Organized Crime
Organized cybercrime groups that are very sophisticated and well structured. Have a lot of resources and high technical skill. Motivated by financial gain
Organized Criminal Techniques
Custom malware, ransomware, sophisticated phishing campaigns
Ways Organized Criminal organizations gain finances
Data Breaches, Identity Theft, Online Fraud, Ransomware Attacks
Nation-state Actor
Groups or individuals sponsored by governments to commit cyberattacks against other countries, organizations, or people
Common Nation-State Actor attack methods
Faldo Flag Attack, Custom Malware, Zero-Day exploits, APTs
False Flag Attack
Attack that’s made to look like it came from a different source to mislead investigators by framing another group
Advanced Persistent Threat (APT)
Another name for nation-state actor due to long-term persistence and stealth. Basically a prolonged and targeted cyberattack that remains undetected for a long time while stealing data and spying
Nation-State Actor Motivations
Long-term strategic goals like espionage, not financial gain
Insider Threats different forms
Data Theft, Sabotage, Misuse of access privileges
Insider threat motivations
Financial Gain, Revenge, Carelessness or lacking awareness of best security practices
Insider Threat Risk
Individuals inside the organization have access to sensitive information and systems and may end up misusing this for malicious or accidental purposes
How to mitigate insider threats
Zero-Trust Architecture, have robust access controls, conduct regular audits, have good employee security awareness programs and training
Shadow IT
Using technology systems, devices, software, apps, and service without approval from the organization or the knowledge of the It Department
Reasons for Shadow IT
Security posture is too high and negatively affects business operations, so employees find ways to circumvent it for convenience. Sometimes BYOD devices contribute to this
Threat Vectors
The way an attacker gains unauthorized access to a computer or network to do something malicious or unwanted
Attack Surface
All the points an unauthorized user can try to enter or take data from an environment
How to minimize an attack surface
Restrict Access, Remove unnecessary software, disable unused protocols
Types of Threat Vectors
Messages, Images, Files, Voice Calls (Vhishing), Removable Devices, Unsecured Networks
Baiting
Leaving a malware infected device like a USB in a location where a target may find it and hopefully use it
Physical Network Weakness
MAC Address cloning, VLAN Hopping
Wireless Network vulnerabilities if not well secured
Vulnerable to interceptions of wireless communications and bad actors gaining access to the network
BlueBorne
A type of Bluetooth vulnerability that lets an attacker take over devices, spread malware, or intercept communications
BlueSmack
A type of Bluetooth attack. A Denial of Service attack that sends a specially crafted Logical Link Control and Adaptation Protocol packet to a target device
Best way learn about the threat actors attacking your network
Deception and disruption technology
Tactics, Techniques, and Procedures (TTPs)
Basically how a particular threat actors attacking acts. Their methods and behavior
Deceptive and Disruption Technologies
Tech used to mislead and divert attackers from critical assets while analyzing and neutralizing them. Honeypots, Honeynets, Honeyfiles, Honeytokens, etc
Honeypots
Decoy system or network set up to attract potential hackers
Honeynets
A Network of honeypots that mimics a whole network of systems, with servers, routers, and switches
Honeyfiles
Decoy file in a system that lures attacks
Honeytokens
A bit of data or a resource with no value but is monitored for misuse. It being access alone shows an attack
Bogus DNS entries
A disruptive technology. A fake Domain Name System entry on the system’s DNS server
Making Decoy Directories
A disruption tactic. Fake folders and files in the system’s storage
Dynamic page generation
Disruptive technology that is Effective against automated scraping tools or bots trying to index or steal content from organization’s website
Port Triggering
Disruptive Technology, security mechanism where specific ports or services on a network device stay closed until it detects a specific outbound traffic pattern
Spoofing fake telemetry Data
Disruptive technology. The system detects a malicious network scan and sends out fake data