TechKnowSurge
Cisco CCST Cybersecurity 1.1 Cisco CyberOps Associate 1.3 CompTIA Network+ 4.1 Cisco CCST Cybersecurity 1.2 Cisco CyberOps Associate 2.1 CompTIA Network+ 4.2 CompTIA SecurityX 2.6
VideoNetworkFree

Threat Agents

Threat agents range from novice script kiddies to state-sponsored operatives, each bringing different intentions, attack methods, and skill levels to the networks they target. Understanding who these actors are, how they gain access, and what they're after is foundational to building an effective cybersecurity defense.

Complete this video to capture a CTF flag worth 1 point.

About this video

Threat agents are the individuals or groups behind cyberattacks, and understanding them requires examining their motivations, methods, and skill levels. They are broadly classified into three categories based on intent: white hat hackers, who conduct authorized security testing such as contracted penetration assessments; black hat hackers, who engage in illegal activity for monetary gain or notoriety; and gray hat hackers, who occupy an ethical middle ground by probing systems without permission but with the stated goal of exposing vulnerabilities for the public good. These distinctions matter because intent shapes both the nature of an attack and the legal and organizational responses it demands. The types of attacks these actors carry out generally fall into three categories tied directly to the CIA triad. Reconnaissance involves mapping a target network, gathering organizational intelligence, and identifying weaknesses before striking. Access attacks occur when a threat agent exploits a discovered vulnerability to gain entry and establish persistence, such as by creating unauthorized accounts. Denial of service attacks focus specifically on degrading or eliminating availability, bringing systems or services offline without necessarily stealing data. Threat agents gain footholds through a variety of vectors, including phishing emails, social media intelligence gathering, lost or stolen removable media, unencrypted devices, misconfigured access controls, improperly secured cloud storage, and physical documents recovered through dumpster diving. Each of these represents a gap between policy and practice that attackers are trained to recognize and exploit. The diversity of these vectors reinforces why a layered security posture is essential. Hacker maturity exists on a spectrum as well. Script kiddies are entry-level actors who rely on pre-built tools and target low-hanging fruit to build experience. Vulnerability brokers actively seek and disclose security flaws, often straddling legal boundaries in the process. Hacktivists pursue ideological or political goals, using cyberattacks as a form of protest. Cybercriminals operate with clear self-serving motives, whether financial or reputational. At the most sophisticated end, state-sponsored hackers execute coordinated campaigns on behalf of governments, as illustrated by the Stuxnet worm, which was widely attributed to a nation-state effort to sabotage Iran's nuclear program and is considered one of the most advanced cyberweapons ever deployed.

What you'll learn

What's covered

Threat Agents

Aligned to

Cisco CCST Cybersecurity
1.1 Define essential security principles
1.2 Explain common threats and vulnerabilities
Cisco CyberOps Associate
1.3 Describe security terms
2.1 Compare attack surface and vulnerability
CompTIA Network+
4.1 Explain the importance of basic network security concepts
4.2 Summarize various types of attacks and their impact to the network
CompTIA SecurityX
2.6 Explain how threat and vulnerability management techniques are used in the enterprise

Key terms

Threat Actor
An individual or group responsible for a security incident or attack.
Penetration Testing
An authorized simulated attack on a system to identify and evaluate security vulnerabilities.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Denial of Service
DoS
An attack that floods a system or network with traffic to make it unavailable to legitimate users.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
White Hat Hacker
An ethical security professional who is authorized to test and identify vulnerabilities in systems to improve security.
Black Hat Hacker
A malicious actor who illegally compromises systems for personal gain, financial profit, or disruption.
Gray Hat Hacker
A hacker who operates between ethical and unethical boundaries, often exposing vulnerabilities without authorization but claiming good intent.
Script Kiddie
A low-skill threat actor who uses pre-written scripts or tools created by others to attempt attacks without deep technical knowledge.
Vulnerability Broker
A gray hat actor who discovers and exposes vulnerabilities, often publicly, to pressure vendors or organizations into applying fixes.
Cybercriminal
A black hat threat actor who conducts illegal cyberattacks for financial gain, notoriety, or other self-serving purposes.
State-Sponsored Actor
A threat actor funded or directed by a government to conduct cyber operations, espionage, or sabotage against other nations or organizations.

Transcript

Threat agent types

When it comes to hackers, there's a lot of different intentions that hackers have towards the networks that they're trying to hack, so we categorize them in different types.

There's the white hat hackers, those who are supposedly doing something for the intention of something good. You have the black hat hackers, who are just flat out doing illegal things for their own personal gain, whether it is for monetary purposes or for the clout that they hacked some sort of network — this is full-out illegal activity. And there's a continuum here, and some people draw the lines differently with this.

A good example of a white hat hacker is that I pay a company every year to come in and do penetration testing against my networks to make sure that they are secure. What they do is we sign a contract saying that they're going to do penetration testing and they're going to test out to see if they can find any vulnerabilities that we have, and then at the end they give us a report saying what exactly they found. So this is considered the ethical hacker on this side. On this side is the person that's just trying to get into the network to either disrupt availability or grab some sort of information — it's back to the CIA, the confidentiality, the integrity or the availability of the network.

Then you have the in between here. These are the people that tread on the line of doing illegal activity, but they are claiming that it's for the good of all, and they're trying to hack systems and find vulnerabilities to expose them so that companies can take steps into protecting their resources. But there is some grayer area with this, hence the term gray hat hacker, since some of the activities that they're doing are more on the illegal side.

Types of attacks

You can categorize what they're trying to do into three different categories.

First of all, reconnaissance. Maybe they're trying to grab information about the network and map out the network and figure out what's going on with the network, and do some dumpster diving to get some additional information. So they're grabbing information to figure out the bounds of these networks, to figure out where some of the weaknesses are and what is going on with it.

Then you have access. Once they have found maybe a weakness, they get in there and they start creating accounts so that they can leverage the system. So they're doing some sort of access of the network.

And then you have denial of service. The whole idea behind a denial of service is they are trying to figure out a way to the network to bring availability down. So this is affecting the availability of the CIA triad, the security triad. That is the denial of service, when they are hacking a system to actually bring it down.

Vectors

So what are some of the ways hackers start prying into a network? They need to do that reconnaissance and start finding information, and there are some ways that they can start finding information.

One of the ways is through email and social networks. We post a lot of information on social networks, and a lot of information about companies on social networks, so that's a way they can start gathering that information. Or they send email to specific people within the company to get information from those people within the company. Or even going to the company website and seeing who the execs are — now they have a list of execs, and they can either leverage those execs or leverage other people within the company with the execs' names to be able to do that. I've seen that happen a lot.

Another is through removable media. There are a lot of times that people will have information on media and they'll throw it away, or they'll lose it, and then that information is gone — it's out there in the world. I've had employees before lose information, and that is not a good thing.

Then there's improper access control. This is that configuration that we talked about in one of the other videos, where there are configuration errors leaving doors open, where hackers can get into those doors and start scoping things out and start mapping out the networks and start leveraging it to their advantage.

Then you have unencrypted devices. If a laptop gets stolen and the drive on those devices is unencrypted, then that information, similar to removable media, is out there. There are also cloud storage devices, and if that's improperly configured, then that information can be exposed to the outside world as well.

And then you also have hard copies. If you pay a pentester, a penetration tester, to come in and pentest your network, one thing that they have done in the past is they've actually gone through the dumpster and looked for confidential information, names of employees and social security numbers on printed-out forms, documents that have not been destroyed properly. So these are all vectors of information that they can start gathering. The social security document that was found in the dumpster can be problematic obviously in itself, but they can also find information in that stuff in the dumpster to help leverage to get into the networks.

Hacker maturity levels

As I mentioned before, hackers have different intentions. They also have different maturity levels, or different experience levels. Here are some of the categories that we can put hackers into.

One of them is script kiddies. Script kiddies are just the beginner hackers. They don't have a lot of experience, and what they do is they know of these different scripts that they can use to run the scripts against the different environments to see if they can hack into the system. They're only looking for low-hanging fruit and they're trying to gain experience here.

Then you have the vulnerability broker. The vulnerability broker is that gray hat hacker, the one that treads on the line of illegal activity, but they're doing it for a cause. The cause is so they can expose vulnerabilities — they want to expose a vulnerability and get that information out there so it can be corrected.

Then you have activists. Activists have some sort of intention or statement that they want to make. Either they're protesting the government or a certain company, or they're for a social cause, but they're trying to make a statement out there.

Then you have cyber criminals. These are the black hat hackers. These are the ones that are out there trying to make a name for themselves, or they're trying to get some sort of monetary gain. The idea behind this is they are the ones that are doing illegal activity for some sort of self-serving purpose — all they are out there doing it for is themselves.

Then you have the state sponsored. There's a whole cyber warfare that can happen, and there are some governments that will pay hackers to be able to hack systems. A good example of this is Stuxnet. Stuxnet was a malicious computer worm that was invented to penetrate Iran's nuclear program and mess it up and set them back years, and it actually was pretty effective. It's a pretty interesting, fascinating story, and you can find a story on YouTube in regards to that. It was most likely some sort of state-sponsored paying somebody to create this virus, this worm, to slow down the production that Iran had for their nuclear program. That type of stuff, that cyber warfare stuff, is happening all the time.

So we talked about some threat agents, some threat agent types, some different types of attacks, some vectors that they use to get into these systems, and some hacker maturity levels.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →