1/35
Vocabulary and distinction flashcards for OPIM 3207 Unit 2 covering threat actors, threat intelligence concepts, confusion pairs, and decision frameworks.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Threat actor
A person or group that can cause harm to information assets.
White hat
An authorized security tester working within permission and scope.
Black hat
A malicious, unauthorized attacker.
Gray hat
An unauthorized actor who may claim a helpful purpose.
Script kiddie
An inexperienced attacker using existing tools or code without deep understanding.
Hacktivist
An ideologically or politically motivated attacker.
Insider threat
A trusted person who intentionally or accidentally creates harm.
Organized crime
A coordinated group usually motivated by money.
Nation-state
A government-backed actor pursuing espionage, disruption, or strategic advantage.
APT (Advanced Persistent Threat)
A capable, coordinated actor or campaign that pursues an objective over time and may work to maintain access.
Threat intelligence
Analyzed information about threats that supports a decision.
Indicator of compromise (IoC)
Observable evidence that may signal compromise.
Tactic, technique, and procedure (TTP)
A pattern describing an attacker's goals and behavior.
Attack vector
The path or method used to reach a target.
Attribution
Assessment of who likely performed an attack.
White hat vs. gray hat
Fast distinction: Authorized testing vs. unauthorized testing.
IoC vs. TTP
Fast distinction: Specific observable trace vs. behavioral pattern.
Nation-state vs. organized crime
Fast distinction: Strategic state goal vs. mainly financial criminal goal.
Threat data vs. intelligence
Fast distinction: Raw observation vs. analyzed, decision-ready context.
Threat model
A framework that connects actor to asset by stating what the actor wants, what access they have, which weakness or vector they may use, and the likely business impact to choose a proportionate control.
Shelf life of threat intelligence
The concept that indicators decay over time (e.g., a rented IP changing owners), requiring evaluation of recency, source confidence, and environment relevance.
Classify actors with evidence
The principle of evaluating authorization, motivation, resources, sophistication, and persistence rather than labeling an actor from a single flashy technique.
Raw data transformation
The principle that raw data (like an IP address) becomes intelligence when context shows it belongs to active malicious infrastructure, enabling defenders to hunt, block, or prioritize.