Unit 2 Study Guide: Threat Actors and Threat Intelligence

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/35

flashcard set

Earn XP

Description and Tags

Vocabulary and distinction flashcards for OPIM 3207 Unit 2 covering threat actors, threat intelligence concepts, confusion pairs, and decision frameworks.

Last updated 1:48 PM on 10/1/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

36 Terms

1
New cards

Threat actor

A person or group that can cause harm to information assets.

2
New cards

White hat

An authorized security tester working within permission and scope.

3
New cards

Black hat

A malicious, unauthorized attacker.

4
New cards

Gray hat

An unauthorized actor who may claim a helpful purpose.

5
New cards

Script kiddie

An inexperienced attacker using existing tools or code without deep understanding.

6
New cards

Hacktivist

An ideologically or politically motivated attacker.

7
New cards

Insider threat

A trusted person who intentionally or accidentally creates harm.

8
New cards

Organized crime

A coordinated group usually motivated by money.

9
New cards

Nation-state

A government-backed actor pursuing espionage, disruption, or strategic advantage.

10
New cards

APT (Advanced Persistent Threat)

A capable, coordinated actor or campaign that pursues an objective over time and may work to maintain access.

11
New cards

Threat intelligence

Analyzed information about threats that supports a decision.

12
New cards

Indicator of compromise (IoC)

Observable evidence that may signal compromise.

13
New cards

Tactic, technique, and procedure (TTP)

A pattern describing an attacker's goals and behavior.

14
New cards

Attack vector

The path or method used to reach a target.

15
New cards

Attribution

Assessment of who likely performed an attack.

16
New cards

White hat vs. gray hat

Fast distinction: Authorized testing vs. unauthorized testing.

17
New cards

IoC vs. TTP

Fast distinction: Specific observable trace vs. behavioral pattern.

18
New cards

Nation-state vs. organized crime

Fast distinction: Strategic state goal vs. mainly financial criminal goal.

19
New cards

Threat data vs. intelligence

Fast distinction: Raw observation vs. analyzed, decision-ready context.

20
New cards

Threat model

A framework that connects actor to asset by stating what the actor wants, what access they have, which weakness or vector they may use, and the likely business impact to choose a proportionate control.

21
New cards

Shelf life of threat intelligence

The concept that indicators decay over time (e.g., a rented IP changing owners), requiring evaluation of recency, source confidence, and environment relevance.

22
New cards

Classify actors with evidence

The principle of evaluating authorization, motivation, resources, sophistication, and persistence rather than labeling an actor from a single flashy technique.

23
New cards

Raw data transformation

The principle that raw data (like an IP address) becomes intelligence when context shows it belongs to active malicious infrastructure, enabling defenders to hunt, block, or prioritize.

24
New cards
Attack surface
All the points where an attacker could reach a system or exploit a weakness.
25
New cards
Attack surface vs. attack vector
Attack surface is the set of possible entry points; an attack vector is the method used in a particular attempt.
26
New cards
Common attack vectors
Email, removable media, direct access, remote access, supply chain, websites, and cloud services.
27
New cards
Malicious insider
A person with current or past authorized access who intentionally causes harm.
28
New cards
Unintentional insider
A person whose mistake or unsafe behavior causes harm without intending to.
29
New cards
Targeted vs. opportunistic attack
A targeted attack selects a particular victim; an opportunistic attack looks for any vulnerable victim.
30
New cards
Competitor as a threat actor
A rival organization that seeks another organization's information or business advantage, potentially through espionage or an insider.
31
New cards
Tactic in a TTP
What the attacker is trying to achieve.
32
New cards
Technique in a TTP
The general method the attacker uses to achieve that goal.
33
New cards
Procedure in a TTP
The specific way that actor carries out the technique.
34
New cards
Examples of threat intelligence sources
Incident investigations, honeypots, academic research, information-sharing groups, and threat-data feeds.
35
New cards
What makes a threat-intelligence source useful?
Its reliability, recency, relevance to your environment, and whether it supports a defensive decision.
36
New cards
Why is attribution uncertain?
Actors can reuse tools and infrastructure or plant misleading clues, so evidence may support a likely actor without proving identity.