About this interactive
What you're doing: six incidents have been written up by an intelligence analyst, each one describing an attacker's motivation, target, capability and position without ever naming who it was. Six archetype cards have been drafted. You place each archetype against the incident whose profile matches it. Why it matters: profiling a threat actor is how defenders turn an event into a prediction. If you know which archetype you are facing, you know what they are likely to do next, how long they are likely to stay, and which of your controls is the one actually being tested — and none of that follows from a single characteristic. The whole difficulty of this board is built out of overlaps that occur in the real world. Two of these actors are politically motivated, and one is a state intelligence service burning a zero-day while the other rents a stress-testing service by the hour, which is the cleanest available demonstration that motivation and capability are independent axes. Two are after money, and one of them is a criminal enterprise with a leak site and a negotiation desk while the other is a support-desk contractor exporting customer records through the reporting tool the job required. Two were already inside, and they share nothing except position: one wants revenge for a passed-over promotion, the other wants a payout. How to use it: read all four characteristics before you reach for a card, and read the ones the write-up says are unremarkable as carefully as the ones it says are advanced. The absence of an exploit in the insider cases is not missing evidence — it is the evidence, because an insider never had to solve the access problem the perimeter exists to create. Likewise, the absence of any demand in the espionage case is what separates it from extortion: an actor who wants money must eventually ask for it, and asking is a detection event, while an actor who wants secrets never has to ask and can stay for fourteen months. Carry that habit out of the activity. When you meet an unlabeled attack description on an exam or in a report, ask the four questions in order — what did they want, who did they pick, could they build it or only run it, and were they inside or outside — and the archetype names itself.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →