TechKnowSurge
CompTIA Security+ 2.1 Cisco CCST Cybersecurity 1.2 ISC2 CC 1.1 CompTIA Network+ 4.2
InteractiveSecurityFree

Threat Actor Profile Builder

Read four characteristics out of an incident write-up — motivation, target, capability, position — and name the threat actor archetype they describe.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

What you're doing: six incidents have been written up by an intelligence analyst, each one describing an attacker's motivation, target, capability and position without ever naming who it was. Six archetype cards have been drafted. You place each archetype against the incident whose profile matches it. Why it matters: profiling a threat actor is how defenders turn an event into a prediction. If you know which archetype you are facing, you know what they are likely to do next, how long they are likely to stay, and which of your controls is the one actually being tested — and none of that follows from a single characteristic. The whole difficulty of this board is built out of overlaps that occur in the real world. Two of these actors are politically motivated, and one is a state intelligence service burning a zero-day while the other rents a stress-testing service by the hour, which is the cleanest available demonstration that motivation and capability are independent axes. Two are after money, and one of them is a criminal enterprise with a leak site and a negotiation desk while the other is a support-desk contractor exporting customer records through the reporting tool the job required. Two were already inside, and they share nothing except position: one wants revenge for a passed-over promotion, the other wants a payout. How to use it: read all four characteristics before you reach for a card, and read the ones the write-up says are unremarkable as carefully as the ones it says are advanced. The absence of an exploit in the insider cases is not missing evidence — it is the evidence, because an insider never had to solve the access problem the perimeter exists to create. Likewise, the absence of any demand in the espionage case is what separates it from extortion: an actor who wants money must eventually ask for it, and asking is a detection event, while an actor who wants secrets never has to ask and can stay for fourteen months. Carry that habit out of the activity. When you meet an unlabeled attack description on an exam or in a report, ask the four questions in order — what did they want, who did they pick, could they build it or only run it, and were they inside or outside — and the archetype names itself.

What you'll learn

Aligned to

CompTIA Security+
2.1 Compare and contrast common threat actors and motivations.
Cisco CCST Cybersecurity
1.2 Explain common threats and vulnerabilities
ISC2 CC
1.1 Understand cybersecurity concepts
CompTIA Network+
4.2 Compare and contrast common types of attacks.

Key terms

Threat Actor
An individual or group responsible for a security incident or attack.
Nation-State Actor
A government-sponsored threat actor that conducts offensive cyber operations against other governments or organizations for political, military, or economic advantage.
Advanced Persistent Threat
APT
Advanced Persistent Threat describes a sophisticated, long-term intrusion campaign in which a threat actor maintains unauthorized access to a target network over an extended period to steal data, conduct espionage, or pre-position for future attacks.
Organized Crime
Structured criminal enterprises that sponsor or conduct cybercriminal activities for financial gain, operating similarly to legitimate businesses.
Hacktivist
A threat actor who conducts hacking activities to promote political, ideological, or social change.
Insider Threat
A security risk that originates from individuals who have authorized access to an organization's systems — such as employees, contractors, or partners — and misuse that access either maliciously or through negligence.
Script Kiddie
An unskilled threat actor who uses pre-written scripts or tools to attempt unauthorized access without deep technical knowledge.
Organizationally Sponsored Threat Actor
A hacker or hacking group funded and supported by an organization such as a government, corporation, or criminal enterprise, providing greater resources and manpower.
Self-Sponsored Threat Actor
An individual hacker who operates independently without organizational backing, limited to their own time and financial resources.
Tactics, Techniques, and Procedures
TTP
Tactics, Techniques, and Procedures describe the behavior and methods used by threat actors during cyberattacks, with TTPs forming the basis for frameworks such as MITRE ATT&CK and enabling defenders to develop detection and response strategies.
Threat Modeling
The process of identifying and enumerating potential threats to an organization by analyzing threat actors, their motivations, and methods of attack to evaluate and prioritize risks.
Attack Vector
The specific path or method a threat actor uses to gain unauthorized access to a system or network, such as a phishing email, an unpatched vulnerability, or a misconfigured network port.

Topics

Interactive Build

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →