Threat agents range from novice script kiddies to state-sponsored operatives, each bringing different intentions, attack methods, and skill levels to the networks they target. Understanding who these actors are, how they gain access, and what they're after is foundational to building an effective cybersecurity defense.
Threat Agents
When it comes to hackers, there's a lot of different intentions that hackers have towards the networks that they're trying to hack, so we categorize them in different types.
There's the white hat hackers, those who are supposedly doing something for the intention of something good. You have the black hat hackers, who are just flat out doing illegal things for their own personal gain, whether it is for monetary purposes or for the clout that they hacked some sort of network — this is full-out illegal activity. And there's a continuum here, and some people draw the lines differently with this.
A good example of a white hat hacker is that I pay a company every year to come in and do penetration testing against my networks to make sure that they are secure. What they do is we sign a contract saying that they're going to do penetration testing and they're going to test out to see if they can find any vulnerabilities that we have, and then at the end they give us a report saying what exactly they found. So this is considered the ethical hacker on this side. On this side is the person that's just trying to get into the network to either disrupt availability or grab some sort of information — it's back to the CIA, the confidentiality, the integrity or the availability of the network.
Then you have the in between here. These are the people that tread on the line of doing illegal activity, but they are claiming that it's for the good of all, and they're trying to hack systems and find vulnerabilities to expose them so that companies can take steps into protecting their resources. But there is some grayer area with this, hence the term gray hat hacker, since some of the activities that they're doing are more on the illegal side.
You can categorize what they're trying to do into three different categories.
First of all, reconnaissance. Maybe they're trying to grab information about the network and map out the network and figure out what's going on with the network, and do some dumpster diving to get some additional information. So they're grabbing information to figure out the bounds of these networks, to figure out where some of the weaknesses are and what is going on with it.
Then you have access. Once they have found maybe a weakness, they get in there and they start creating accounts so that they can leverage the system. So they're doing some sort of access of the network.
And then you have denial of service. The whole idea behind a denial of service is they are trying to figure out a way to the network to bring availability down. So this is affecting the availability of the CIA triad, the security triad. That is the denial of service, when they are hacking a system to actually bring it down.
So what are some of the ways hackers start prying into a network? They need to do that reconnaissance and start finding information, and there are some ways that they can start finding information.
One of the ways is through email and social networks. We post a lot of information on social networks, and a lot of information about companies on social networks, so that's a way they can start gathering that information. Or they send email to specific people within the company to get information from those people within the company. Or even going to the company website and seeing who the execs are — now they have a list of execs, and they can either leverage those execs or leverage other people within the company with the execs' names to be able to do that. I've seen that happen a lot.
Another is through removable media. There are a lot of times that people will have information on media and they'll throw it away, or they'll lose it, and then that information is gone — it's out there in the world. I've had employees before lose information, and that is not a good thing.
Then there's improper access control. This is that configuration that we talked about in one of the other videos, where there are configuration errors leaving doors open, where hackers can get into those doors and start scoping things out and start mapping out the networks and start leveraging it to their advantage.
Then you have unencrypted devices. If a laptop gets stolen and the drive on those devices is unencrypted, then that information, similar to removable media, is out there. There are also cloud storage devices, and if that's improperly configured, then that information can be exposed to the outside world as well.
And then you also have hard copies. If you pay a pentester, a penetration tester, to come in and pentest your network, one thing that they have done in the past is they've actually gone through the dumpster and looked for confidential information, names of employees and social security numbers on printed-out forms, documents that have not been destroyed properly. So these are all vectors of information that they can start gathering. The social security document that was found in the dumpster can be problematic obviously in itself, but they can also find information in that stuff in the dumpster to help leverage to get into the networks.
As I mentioned before, hackers have different intentions. They also have different maturity levels, or different experience levels. Here are some of the categories that we can put hackers into.
One of them is script kiddies. Script kiddies are just the beginner hackers. They don't have a lot of experience, and what they do is they know of these different scripts that they can use to run the scripts against the different environments to see if they can hack into the system. They're only looking for low-hanging fruit and they're trying to gain experience here.
Then you have the vulnerability broker. The vulnerability broker is that gray hat hacker, the one that treads on the line of illegal activity, but they're doing it for a cause. The cause is so they can expose vulnerabilities — they want to expose a vulnerability and get that information out there so it can be corrected.
Then you have activists. Activists have some sort of intention or statement that they want to make. Either they're protesting the government or a certain company, or they're for a social cause, but they're trying to make a statement out there.
Then you have cyber criminals. These are the black hat hackers. These are the ones that are out there trying to make a name for themselves, or they're trying to get some sort of monetary gain. The idea behind this is they are the ones that are doing illegal activity for some sort of self-serving purpose — all they are out there doing it for is themselves.
Then you have the state sponsored. There's a whole cyber warfare that can happen, and there are some governments that will pay hackers to be able to hack systems. A good example of this is Stuxnet. Stuxnet was a malicious computer worm that was invented to penetrate Iran's nuclear program and mess it up and set them back years, and it actually was pretty effective. It's a pretty interesting, fascinating story, and you can find a story on YouTube in regards to that. It was most likely some sort of state-sponsored paying somebody to create this virus, this worm, to slow down the production that Iran had for their nuclear program. That type of stuff, that cyber warfare stuff, is happening all the time.
So we talked about some threat agents, some threat agent types, some different types of attacks, some vectors that they use to get into these systems, and some hacker maturity levels.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →