secplus

Dashboard / 2.0 Threats, Vulnerabilities, and Mitigations

2.1 Compare and contrast common threat actors and motivations

Official exam objective outline (3 topics)
  • Threat actors
    • Nation-state
    • Unskilled attacker
    • Hacktivist
    • Insider threat
    • Organized crime
    • Shadow IT
  • Attributes of actors
    • Internal/external
    • Resources/funding
    • Level of sophistication/capability
  • Motivations
    • Data exfiltration
    • Espionage
    • Service disruption
    • Blackmail
    • Financial gain
    • Philosophical/political beliefs
    • Ethical
    • Revenge
    • Disruption/chaos
    • War

★ Starred in your notes: zero-day vulnerabilities (HW: use the exam objectives as a guide).

Breakdown 1 — Vocabulary first (from class, Day 1)

From class: Risk → the chance of harm coming to an asset. Threat → anything that can cause harm to an asset. Vulnerability → any weakness the asset has against potential threats. Breach → somebody got in.

Risk exists only where a threat can exploit a vulnerability. Threat actors are the who behind the threat.

From class — Module B threat categories: Adversarial (a person/group attacking), Accidental (a user makes a mistake), Structural (equipment/software fails), Environmental (fire, flood, power). Only the adversarial category has "threat actors" with motivations.

Breakdown 2 — The threat actors the exam names

ActorWho they areTypical resources / sophisticationTypical motivation
Nation-stateGovernment-sponsored groups; often run APTsVery high funding, very sophisticated, patientEspionage, war, disruption, data exfiltration
Unskilled attacker ("script kiddie")Uses tools/scripts others wroteLow skill, low fundingFame, chaos, curiosity
HacktivistIdeologically driven individuals/groupsVaries; moderatePhilosophical/political beliefs; defacement, leaks, DDoS
Insider threatEmployee, contractor, partner with legitimate accessAlready inside — internal, knows the systemsRevenge, financial gain, or unintentional (negligence)
Organized crimeCriminal enterprises run like businessesHigh funding, specialized roles (ransomware-as-a-service)Financial gain, blackmail
Shadow ITEmployees using unapproved hardware/software/cloudInternal, not maliciousConvenience — but creates unmanaged attack surface

From class: APT → a group of hackers active over a long period of time — Advanced Persistent Threat (usually nation-state). Shadow IT → having software/hardware not approved by IT.

From class — "hacker" labels: Unauthorized (black hat, malicious), Authorized (white hat, has permission — pen testers), Semi-authorized (gray hat — not authorized, but not malicious; may find and disclose a bug without permission).

Breakdown 3 — Attributes of actors

AttributeThe question to askWhy it matters
Internal vs. externalDo they already have access?Insiders bypass perimeter controls entirely
Resources / fundingCan they buy zero-days, rent botnets, sustain a long campaign?Nation-states & organized crime: yes. Script kiddies: no
Sophistication / capabilityCustom malware or downloaded tools?Determines what defenses are enough

Breakdown 4 — Motivations (know the vocabulary)

MotivationLooks like
Data exfiltrationStealing data (IP, PII, credentials)
EspionageNation-state or competitor spying
Service disruptionDDoS, wiper malware
Blackmail"Pay or we leak/encrypt" — ransomware, doxxing
Financial gainFraud, ransomware, card theft
Philosophical / politicalHacktivism
EthicalAuthorized/"white hat" testing, responsible disclosure
RevengeDisgruntled insider
Disruption / chaos"For the lulz", script kiddies
WarNation-state attacks on infrastructure

Breakdown 5 — Where defenders learn about actors (threat intelligence)

From class — intelligence gathering: OSINT → open-source intelligence, free public resources. CSINT → closed-source (proprietary/paid) intelligence. ISAC → Information Sharing and Analysis Center: gathers attack info and shares it, organized by sector (financial ISAC, health ISAC…). ISAO → Information Sharing and Analysis Organization — like an ISAC but not organized by sector. CISA → the U.S. Cybersecurity and Infrastructure Security Agency. Homework mention: a threat feed from an ISAC. Sites named in class: inteltechniques.com (OSINT), tryhackme.com, ctftime.org, overthewire.org, portswigger.net.

The exam lists these under 4.3 ("threat feed: OSINT, proprietary/third-party, information-sharing organization, dark web"), but they appear in threat-actor questions too.

Exam tip: "Long-term, well-funded, stealthy, targets government/defense" → nation-state / APT. "Defaces a site to protest" → hacktivist. "Employee uploads customer list to personal Dropbox" → insider (possibly unintentional) and also shadow IT. "Downloads a tool and runs it against random targets" → unskilled attacker. "Ransomware group with affiliates and a help desk" → organized crime.

Quick self-check

  • Which two actors are most likely to have the resources for a zero-day? (Nation-state, organized crime.)
  • Is shadow IT malicious? (Usually not — but it's an unmanaged, unpatched attack surface.)
  • ISAC vs. ISAO? (ISAC = sector-based; ISAO = any grouping.)

Sources: 20260917_173205.jpg, 20260917_173210.jpg