1
00:00:00,000 --> 00:00:02,130
Threat Actor Attributes.

2
00:00:02,130 --> 00:00:04,860
In the world of cybersecurity understanding the attributes

3
00:00:04,860 --> 00:00:06,600
of threat actors is as crucial

4
00:00:06,600 --> 00:00:08,640
as understanding their motivations.

5
00:00:08,640 --> 00:00:11,070
These attributes provide valuable insights

6
00:00:11,070 --> 00:00:12,390
into their procedures.

7
00:00:12,390 --> 00:00:14,730
In this lesson, we will discuss the different attributes

8
00:00:14,730 --> 00:00:17,850
of threat actors, including their origin being internal

9
00:00:17,850 --> 00:00:20,490
versus external, resources and funding,

10
00:00:20,490 --> 00:00:23,430
and their level of sophistication and capability.

11
00:00:23,430 --> 00:00:25,140
By understanding these attributes

12
00:00:25,140 --> 00:00:26,850
and the threat actor's motivations,

13
00:00:26,850 --> 00:00:28,650
we can gain valuable insights

14
00:00:28,650 --> 00:00:30,960
into their attack styles and the amount of danger

15
00:00:30,960 --> 00:00:33,150
that they pose to our organizations.

16
00:00:33,150 --> 00:00:36,000
First, we have to compare the two most basic attributes

17
00:00:36,000 --> 00:00:37,140
of a threat actor.

18
00:00:37,140 --> 00:00:38,730
Are they an internal threat actor

19
00:00:38,730 --> 00:00:40,650
or an external threat actor?

20
00:00:40,650 --> 00:00:43,710
This classification as either an internal or external

21
00:00:43,710 --> 00:00:47,100
threat actor is based on the threat actor's relationship

22
00:00:47,100 --> 00:00:49,230
to the targeted organization.

23
00:00:49,230 --> 00:00:51,720
Internal threat actors are individuals or entities

24
00:00:51,720 --> 00:00:55,140
within an organization who pose a threat to its security.

25
00:00:55,140 --> 00:00:57,900
These internal threat actors could be angry employees,

26
00:00:57,900 --> 00:01:00,120
contractors, or business associates

27
00:01:00,120 --> 00:01:02,700
who have legitimate access to the organization's systems

28
00:01:02,700 --> 00:01:05,880
and data but are using it unauthorized way.

29
00:01:05,880 --> 00:01:08,490
Internal threat actors can cause significant damage

30
00:01:08,490 --> 00:01:09,840
due to their intimate knowledge

31
00:01:09,840 --> 00:01:11,730
of the organization's infrastructure

32
00:01:11,730 --> 00:01:13,890
and its potential vulnerabilities,

33
00:01:13,890 --> 00:01:15,540
and their actions may be motivated

34
00:01:15,540 --> 00:01:19,020
by various factors including revenge, financial gain,

35
00:01:19,020 --> 00:01:21,390
or coercion by external entities.

36
00:01:21,390 --> 00:01:24,030
For example, if you worked for the Coca-Cola company

37
00:01:24,030 --> 00:01:26,190
and decided to walk into your office today,

38
00:01:26,190 --> 00:01:27,750
plug in an external hard drive,

39
00:01:27,750 --> 00:01:30,540
downloaded the proprietary formula for Coca-Cola,

40
00:01:30,540 --> 00:01:32,910
and then drive over to Pepsi's headquarters

41
00:01:32,910 --> 00:01:34,440
and handed them that drive,

42
00:01:34,440 --> 00:01:36,690
you would be considered an internal threat actor

43
00:01:36,690 --> 00:01:39,390
because you used your legitimate access at Coca-Cola

44
00:01:39,390 --> 00:01:40,830
to steal data from their network

45
00:01:40,830 --> 00:01:43,680
and give it to their biggest competitor, Pepsi.

46
00:01:43,680 --> 00:01:45,390
External threat actors, on the other hand,

47
00:01:45,390 --> 00:01:48,210
are individuals or groups outside an organization

48
00:01:48,210 --> 00:01:51,090
who attempt to breach its cybersecurity defenses.

49
00:01:51,090 --> 00:01:53,880
These external threat actors could be cyber criminals,

50
00:01:53,880 --> 00:01:57,660
hacktivists, competitors, or state-sponsored actors.

51
00:01:57,660 --> 00:02:00,300
External threat actors typically do not have authorized

52
00:02:00,300 --> 00:02:02,160
access to the organization systems,

53
00:02:02,160 --> 00:02:04,590
and must therefore employ various techniques

54
00:02:04,590 --> 00:02:07,200
such as using malware or social engineering techniques

55
00:02:07,200 --> 00:02:09,449
to gain unauthorized access.

56
00:02:09,449 --> 00:02:12,360
Second, we have to look at the resources and funding

57
00:02:12,360 --> 00:02:14,100
available to a specific threat actor

58
00:02:14,100 --> 00:02:16,050
when we are categorizing them.

59
00:02:16,050 --> 00:02:18,690
The resources and funding available to a threat actor

60
00:02:18,690 --> 00:02:20,970
can significantly influence their activities,

61
00:02:20,970 --> 00:02:23,730
including the scale, frequency, and sophistication

62
00:02:23,730 --> 00:02:24,930
of their attacks.

63
00:02:24,930 --> 00:02:27,810
Resources and funding refers to the tools, skills,

64
00:02:27,810 --> 00:02:31,260
and personnel at the disposal of a given threat actor.

65
00:02:31,260 --> 00:02:33,930
For example, a hacker working by themselves

66
00:02:33,930 --> 00:02:35,700
might only have their personal computer

67
00:02:35,700 --> 00:02:38,040
and their individual skills available to them.

68
00:02:38,040 --> 00:02:40,140
But a nation-state actor might have access

69
00:02:40,140 --> 00:02:42,270
to some extremely advanced hacking tools,

70
00:02:42,270 --> 00:02:45,540
a team of skilled operatives, significant computing power,

71
00:02:45,540 --> 00:02:49,110
and a huge budget to support their hacking operations.

72
00:02:49,110 --> 00:02:51,540
Third, we need to consider the level of sophistication

73
00:02:51,540 --> 00:02:54,300
capability of the specific threat actor.

74
00:02:54,300 --> 00:02:57,240
The level of sophistication or capability of a threat actor

75
00:02:57,240 --> 00:03:00,420
refers to their technical skill, the complexity of the tools

76
00:03:00,420 --> 00:03:02,520
and techniques they use, and their ability

77
00:03:02,520 --> 00:03:04,740
to evade detection and countermeasures.

78
00:03:04,740 --> 00:03:08,670
Usually we rate threat actors on a scale from low to high.

79
00:03:08,670 --> 00:03:10,440
Threat actors with a low level

80
00:03:10,440 --> 00:03:13,560
of sophistication capability typically use widely

81
00:03:13,560 --> 00:03:16,950
available tools and techniques such as common malware

82
00:03:16,950 --> 00:03:18,270
or phishing attacks.

83
00:03:18,270 --> 00:03:20,700
In the world of cybersecurity we usually classify

84
00:03:20,700 --> 00:03:24,060
the lowest skilled threat actors as Script Kiddies.

85
00:03:24,060 --> 00:03:26,280
A Script Kiddie is an individual with limited

86
00:03:26,280 --> 00:03:28,860
technical knowledge who uses pre-made software

87
00:03:28,860 --> 00:03:31,860
or scripts to exploit computer systems and networks

88
00:03:31,860 --> 00:03:34,950
often without understanding the underlying principles.

89
00:03:34,950 --> 00:03:36,480
On the other side of the scale

90
00:03:36,480 --> 00:03:39,150
we have threat actors with high levels of sophistication

91
00:03:39,150 --> 00:03:42,360
and capabilities who possess advanced technical skills

92
00:03:42,360 --> 00:03:44,670
and use sophisticated tools and techniques,

93
00:03:44,670 --> 00:03:46,680
including custom developed malware,

94
00:03:46,680 --> 00:03:49,080
zero day exploits against vulnerabilities,

95
00:03:49,080 --> 00:03:52,440
and their ability to employ advanced evasion techniques.

96
00:03:52,440 --> 00:03:55,170
High level threat actors, such as nation-state actors,

97
00:03:55,170 --> 00:03:57,060
groups, and advanced persistent threats

98
00:03:57,060 --> 00:04:00,000
or APT groups can penetrate even the most

99
00:04:00,000 --> 00:04:02,610
well defended networks, maintain a presence

100
00:04:02,610 --> 00:04:05,340
for extended periods of time without detection

101
00:04:05,340 --> 00:04:07,980
when provided with enough time and resources.

102
00:04:07,980 --> 00:04:10,410
So remember, threat actors are classified

103
00:04:10,410 --> 00:04:11,700
based on their attributes,

104
00:04:11,700 --> 00:04:13,590
including whether they are internal or external

105
00:04:13,590 --> 00:04:16,350
threat actors, how many resources and how much funding

106
00:04:16,350 --> 00:04:18,000
they have available for their use,

107
00:04:18,000 --> 00:04:21,480
and their level of sophistication and capabilities.

108
00:04:21,480 --> 00:04:22,980
By understanding these attributes

109
00:04:22,980 --> 00:04:25,800
we can better dissipate a threat actor's actions,

110
00:04:25,800 --> 00:04:28,470
develop effective defenses against their attacks,

111
00:04:28,470 --> 00:04:32,043
and protect our enterprise networks against their attacks.

