Threat Actors

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/50

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 11:39 PM on 7/31/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

51 Terms

1
New cards

Threat Actor

An individual or entity responsible for incidents that impact security and data protection

2
New cards

Threat Actor Motivators

War, Espionage, Money, Political and Philosophical beliefs, Data theft, revenge, ethics, disrupting service, blackmail

3
New cards

Threat Actors Intent

The goal of objective of the threat actor’s attack

4
New cards

Threat Actor Motivation

The reason why the threat actor attacked

5
New cards

Internal Threat Actors

These actors pose a security threat from within the organization

6
New cards

External Threat Actors

These actors attack the organization from the outside by breaching the cybersecurity defenses

7
New cards

Resources and funding the threat actor has available

Tools, skills, and personnel at the disposal of a given threat actor. Can show how capable the threat is

8
New cards

Level of sophistication and capability of the threat actor

The technical skill, how complex the tools and skills they use, and how well the evade countermeasures and detection

9
New cards

Script kiddies

Lowest skilled threat actors. Usually uses pre-made malware and exploits

10
New cards

Usually use sophisticated tools and techniques to attack cyber defenses

Nation-state actors, Advanced Persistent Threats (APD), Organized criminals, etc

11
New cards

Script Kiddie’s favorite method

DDoS attacks. Attack a simple IP address and flood it with requests

12
New cards

Hactivists

Groups of individuals that commit cyberattacks for ideological reasons. Political, Social Change, or personal

13
New cards

Hactivism

The action of hacking for ideological reasons

14
New cards

Hactivist techniques

Website defacement, DDoS (Distributed Denial of Service), Doxing, Leaking Sensitive data

15
New cards

Website Defacement

Hactivist method that involves vandalizing systems or websites

16
New cards

(Distributed Denial of Service) DDoS attacks

Overwhelming the victims servers or networks so they become unusable for legitimate users

17
New cards

Organized Crime

Organized cybercrime groups that are very sophisticated and well structured. Have a lot of resources and high technical skill. Motivated by financial gain

18
New cards

Organized Criminal Techniques

Custom malware, ransomware, sophisticated phishing campaigns

19
New cards

Ways Organized Criminal organizations gain finances

Data Breaches, Identity Theft, Online Fraud, Ransomware Attacks

20
New cards

Nation-state Actor

Groups or individuals sponsored by governments to commit cyberattacks against other countries, organizations, or people

21
New cards

Common Nation-State Actor attack methods

Faldo Flag Attack, Custom Malware, Zero-Day exploits, APTs

22
New cards

False Flag Attack

Attack that’s made to look like it came from a different source to mislead investigators by framing another group

23
New cards

Advanced Persistent Threat (APT)

Another name for nation-state actor due to long-term persistence and stealth. Basically a prolonged and targeted cyberattack that remains undetected for a long time while stealing data and spying

24
New cards

Nation-State Actor Motivations

Long-term strategic goals like espionage, not financial gain

25
New cards

Insider Threats different forms

Data Theft, Sabotage, Misuse of access privileges

26
New cards

Insider threat motivations

Financial Gain, Revenge, Carelessness or lacking awareness of best security practices

27
New cards

Insider Threat Risk

Individuals inside the organization have access to sensitive information and systems and may end up misusing this for malicious or accidental purposes

28
New cards

How to mitigate insider threats

Zero-Trust Architecture, have robust access controls, conduct regular audits, have good employee security awareness programs and training

29
New cards

Shadow IT

Using technology systems, devices, software, apps, and service without approval from the organization or the knowledge of the It Department

30
New cards

Reasons for Shadow IT

Security posture is too high and negatively affects business operations, so employees find ways to circumvent it for convenience. Sometimes BYOD devices contribute to this

31
New cards

Threat Vectors

The way an attacker gains unauthorized access to a computer or network to do something malicious or unwanted

32
New cards

Attack Surface

All the points an unauthorized user can try to enter or take data from an environment

33
New cards

How to minimize an attack surface

Restrict Access, Remove unnecessary software, disable unused protocols

34
New cards

Types of Threat Vectors

Messages, Images, Files, Voice Calls (Vhishing), Removable Devices, Unsecured Networks

35
New cards

Baiting

Leaving a malware infected device like a USB in a location where a target may find it and hopefully use it

36
New cards

Physical Network Weakness

MAC Address cloning, VLAN Hopping

37
New cards

Wireless Network vulnerabilities if not well secured

Vulnerable to interceptions of wireless communications and bad actors gaining access to the network

38
New cards

BlueBorne

A type of Bluetooth vulnerability that lets an attacker take over devices, spread malware, or intercept communications

39
New cards

BlueSmack

A type of Bluetooth attack. A Denial of Service attack that sends a specially crafted Logical Link Control and Adaptation Protocol packet to a target device

40
New cards

Best way learn about the threat actors attacking your network

Deception and disruption technology

41
New cards

Tactics, Techniques, and Procedures (TTPs)

Basically how a particular threat actors attacking acts. Their methods and behavior

42
New cards

Deceptive and Disruption Technologies

Tech used to mislead and divert attackers from critical assets while analyzing and neutralizing them. Honeypots, Honeynets, Honeyfiles, Honeytokens, etc

43
New cards

Honeypots

Decoy system or network set up to attract potential hackers

44
New cards

Honeynets

A Network of honeypots that mimics a whole network of systems, with servers, routers, and switches

45
New cards

Honeyfiles

Decoy file in a system that lures attacks

46
New cards

Honeytokens

A bit of data or a resource with no value but is monitored for misuse. It being access alone shows an attack

47
New cards

Bogus DNS entries

A disruptive technology. A fake Domain Name System entry on the system’s DNS server

48
New cards

Making Decoy Directories

A disruption tactic. Fake folders and files in the system’s storage

49
New cards

Dynamic page generation

Disruptive technology that is Effective against automated scraping tools or bots trying to index or steal content from organization’s website

50
New cards

Port Triggering

Disruptive Technology, security mechanism where specific ports or services on a network device stay closed until it detects a specific outbound traffic pattern

51
New cards

Spoofing fake telemetry Data

Disruptive technology. The system detects a malicious network scan and sends out fake data