★ Starred in your notes: zero-day vulnerabilities (HW: use the exam objectives as a guide).
Breakdown 1 — Vocabulary first (from class, Day 1)
From class: Risk → the chance of harm coming to an asset. Threat → anything that can cause harm to an asset. Vulnerability → any weakness the asset has against potential threats. Breach → somebody got in.
Risk exists only where a threat can exploit a vulnerability. Threat actors are the who behind the threat.
From class — Module B threat categories: Adversarial (a person/group attacking), Accidental (a user makes a mistake), Structural (equipment/software fails), Environmental (fire, flood, power). Only the adversarial category has "threat actors" with motivations.
Breakdown 2 — The threat actors the exam names
| Actor | Who they are | Typical resources / sophistication | Typical motivation |
|---|---|---|---|
| Nation-state | Government-sponsored groups; often run APTs | Very high funding, very sophisticated, patient | Espionage, war, disruption, data exfiltration |
| Unskilled attacker ("script kiddie") | Uses tools/scripts others wrote | Low skill, low funding | Fame, chaos, curiosity |
| Hacktivist | Ideologically driven individuals/groups | Varies; moderate | Philosophical/political beliefs; defacement, leaks, DDoS |
| Insider threat | Employee, contractor, partner with legitimate access | Already inside — internal, knows the systems | Revenge, financial gain, or unintentional (negligence) |
| Organized crime | Criminal enterprises run like businesses | High funding, specialized roles (ransomware-as-a-service) | Financial gain, blackmail |
| Shadow IT | Employees using unapproved hardware/software/cloud | Internal, not malicious | Convenience — but creates unmanaged attack surface |
From class: APT → a group of hackers active over a long period of time — Advanced Persistent Threat (usually nation-state). Shadow IT → having software/hardware not approved by IT.
From class — "hacker" labels: Unauthorized (black hat, malicious), Authorized (white hat, has permission — pen testers), Semi-authorized (gray hat — not authorized, but not malicious; may find and disclose a bug without permission).
Breakdown 3 — Attributes of actors
| Attribute | The question to ask | Why it matters |
|---|---|---|
| Internal vs. external | Do they already have access? | Insiders bypass perimeter controls entirely |
| Resources / funding | Can they buy zero-days, rent botnets, sustain a long campaign? | Nation-states & organized crime: yes. Script kiddies: no |
| Sophistication / capability | Custom malware or downloaded tools? | Determines what defenses are enough |
Breakdown 4 — Motivations (know the vocabulary)
| Motivation | Looks like |
|---|---|
| Data exfiltration | Stealing data (IP, PII, credentials) |
| Espionage | Nation-state or competitor spying |
| Service disruption | DDoS, wiper malware |
| Blackmail | "Pay or we leak/encrypt" — ransomware, doxxing |
| Financial gain | Fraud, ransomware, card theft |
| Philosophical / political | Hacktivism |
| Ethical | Authorized/"white hat" testing, responsible disclosure |
| Revenge | Disgruntled insider |
| Disruption / chaos | "For the lulz", script kiddies |
| War | Nation-state attacks on infrastructure |
Breakdown 5 — Where defenders learn about actors (threat intelligence)
From class — intelligence gathering: OSINT → open-source intelligence, free public resources. CSINT → closed-source (proprietary/paid) intelligence. ISAC → Information Sharing and Analysis Center: gathers attack info and shares it, organized by sector (financial ISAC, health ISAC…). ISAO → Information Sharing and Analysis Organization — like an ISAC but not organized by sector. CISA → the U.S. Cybersecurity and Infrastructure Security Agency. Homework mention: a threat feed from an ISAC. Sites named in class: inteltechniques.com (OSINT), tryhackme.com, ctftime.org, overthewire.org, portswigger.net.
The exam lists these under 4.3 ("threat feed: OSINT, proprietary/third-party, information-sharing organization, dark web"), but they appear in threat-actor questions too.
Exam tip: "Long-term, well-funded, stealthy, targets government/defense" → nation-state / APT. "Defaces a site to protest" → hacktivist. "Employee uploads customer list to personal Dropbox" → insider (possibly unintentional) and also shadow IT. "Downloads a tool and runs it against random targets" → unskilled attacker. "Ransomware group with affiliates and a help desk" → organized crime.
Quick self-check
- Which two actors are most likely to have the resources for a zero-day? (Nation-state, organized crime.)
- Is shadow IT malicious? (Usually not — but it's an unmanaged, unpatched attack surface.)
- ISAC vs. ISAO? (ISAC = sector-based; ISAO = any grouping.)
Sources: 20260917_173205.jpg, 20260917_173210.jpg