PDF p.26
In progress
Attributes of Threat Actors
Summary
PDF p.26Modern cybersecurity threats require profiling threat actors based on their attributes, including access level, sophistication, resources, and motivation. This helps in understanding and mitigating potential attacks.
In plain words
Supplementary — not from your PDFThreat actors are described by whether they're already inside (internal or external), how skilled they are (sophistication), and how much money and people they have (resources).
Detailed explanation
PDF p.26-
Internal/External
- Definition: Refers to the degree of access a threat actor has before initiating an attack.
- External Threat Actor: No authorized access; must infiltrate the system (e.g., hacking, physical break-in). Can attack remotely or on-premises.
- Internal/Insider Threat Actor: Has authorized access (e.g., employees, contractors, business partners).
-
Level of Sophistication/Capability
- Definition: The ability of a threat actor to use advanced exploit techniques and tools.
- Low Sophistication: Uses widely available commodity attack tools.
- High Sophistication: Creates new exploits in systems and may use non-cyber tools (e.g., political, military assets).
-
Resources/Funding
- Definition: The support needed for a threat actor's capabilities.
- Requirements: Customized attack tools, skilled personnel (strategists, designers, coders, hackers, social engineers).
- Funding Sources: Nation-states, organized crime.
Important terms
taken from the text above- Internal/External
- Refers to the degree of access a threat actor has before initiating an attack.
- External Threat Actor
- No authorized access; must infiltrate the system (e.g., hacking, physical break-in). Can attack remotely or on-premises.
- Internal/Insider Threat Actor
- Has authorized access (e.g., employees, contractors, business partners).
- Level of Sophistication/Capability
- The ability of a threat actor to use advanced exploit techniques and tools.
- Low Sophistication
- Uses widely available commodity attack tools.
- High Sophistication
- Creates new exploits in systems and may use non-cyber tools (e.g., political, military assets).
- Resources/Funding
- The support needed for a threat actor's capabilities.
- Funding Sources
- Nation-states, organized crime.
Examples & real-world scenarios
Supplementary — not from your PDF- External, low sophistication: someone using a ready-made tool found online.
- Internal: a contractor with legitimate access to the network.
- High resources: a team with custom tools, funded by a government or a crime group.
Scenario
After an incident, analysts note that the attacker used a never-before-seen exploit and kept access for months. This profile (high sophistication, high resources) points towards a well-funded group rather than a lone amateur.
Common mistakes
Supplementary — not from your PDF- Thinking 'internal' means physically inside the building. It means having authorized access.
- Assuming every attacker is highly skilled. Most attacks use common tools.
Practical skills
Supplementary — not from your PDF- Profile a threat actor from clues about access, tools and persistence.
What I should remember
Key Points PDF p.26-
Internal/External
- External Threat Actor: No authorized access; infiltrates security.
- Internal Threat Actor: Has authorized access; includes employees, contractors, partners.
-
Level of Sophistication/Capability
- Low Sophistication: Uses common attack tools.
- High Sophistication: Develops new exploits; may use non-cyber tools.
-
Resources/Funding
- Support Needed: Customized tools, skilled personnel.
- Funding Sources: Nation-states, organized crime.