TechKnowSurge
VideoSecurityFree

Knowing the Adversary

Understanding who threatens an organization—and how they think, operate, and choose their targets—is foundational to building effective defenses. This content introduces threat actors, their motivations and capabilities, and the role of threat modeling in identifying and assessing organizational risk.

Complete this video to capture a CTF flag worth 1 point.

About this video

Security risk does not exist in a vacuum—it is shaped by the adversaries who create it. Threat actors, also referred to as threat agents, malicious actors, or cybercriminals, are individuals or entities with the intent to cause harm to an organization through unauthorized access, data theft, disruption, or other malicious activity. Understanding who these actors are is as important as understanding what they do, because the nature of the threat changes significantly depending on the target. A small business with limited assets will attract a different class of attacker than a financial institution or a government agency, where the potential payoff—or political impact—is far greater. Threat modeling is the structured process used to identify and enumerate the potential threats an organization faces. It involves analyzing threat actors through several lenses: their objectives, their skill level, their methods, their likely targets, and their underlying motivations. This analysis allows security teams to move beyond reactive defense and anticipate how an adversary would approach their specific environment. By thinking like an attacker, organizations can prioritize resources, harden the right systems, and design defenses that address credible, real-world threats rather than abstract ones. While not all organizational risk comes from external adversaries—insider threats, human error, and legacy systems all contribute to the threat landscape—the primary focus here is on intentional, external actors who deliberately target networks and data. Building a clear picture of these adversaries and the tactics they employ is the essential first step toward a mature, intelligence-informed security posture.

What you'll learn

What's covered

Understanding Adversaries

Key terms

Threat Actor
An individual or group responsible for a security incident or attack.
Threat
Any potential event or action that could cause harm to a system, network, or organization.
Threat Intelligence
Information about existing or emerging threats that helps organizations make informed security decisions.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Threat Modeling
The process of identifying and enumerating potential threats to an organization by analyzing threat actors, their motivations, and methods of attack to evaluate and prioritize risks.

Topics

Threat Actors Threat Modeling Adversarial Tactics Cybersecurity Attacker Motivations Risk Assessment

Transcript

Getting Into the Mind of an Adversary

As security professionals, we need to take a look at our organization and what are the risks to that organization. But a lot of the risks that come into play when it comes to the organization is going to be carried out by some sort of adversary, some sort of threat agent, somebody that's going to be attacking our systems, or trying to get into our systems, or trying to steal data, or trying to do something malicious to our organization. But to really understand what they would be doing and how they would approach that, we have to get into the minds of an adversary. What are their thinking and what are their capabilities?

What We Call Them

The first thing to understand about adversaries is it could go by many different names: threat actors, threat agents, bad actors, malicious actors, hackers, cyber criminals. These are some of the different names that you'll see out there. Now, some of these really essentially have the same meaning behind it and really have the same definition behind it, and we could use them interchangeably. Some of these mean something a little bit different. Just understand, as we go through this curriculum I'm going to use all of these terms probably throughout this curriculum, and essentially we just mean the adversary who's carrying out the attack on our organization.

So what is the definition? A threat agent or threat actor is an individual or entity — so it could be a whole organization as well — that has the intent to do harm. So the adversary is going to be somebody who is trying to do harm to our company, to carry out some sort of malicious behavior to our company.

Different Adversaries, Different Targets

There are many different threat actors that are out there. If I'm in charge of security for a government organization, the threat actor that's going to attack that government organization is probably going to look quite a bit different than somebody that's going to attack maybe a school, or maybe it's going to be a financial institute, or maybe it's going to be some individual. Those threat actors look very different. So by understanding the threat actors, we can better understand who their targets are and better equip ourselves to protect against those threat actors.

By understanding who is the threat actor, the processes that they use, objectives that they have, their targets that they may target, the skills that they have, and the motivations they have — by fully understanding this, we can get in the minds of the actor and then prepare our organization to protect itself against these threat actors.

As an example, maybe I have a small business and maybe I have just a small office with just a few users. Well, I don't really maybe have that much money invested into this business and I'm not going to be a high target. Maybe it's going to be just some sort of threat agent that really is just looking for the low-hanging fruit, somebody that's an easy target. But now step it up. Maybe I'm a financial institute and there is lots of money to be had for hacking my network. Well, now I'm going to have a much more complex target, and there's going to be a lot more threat actors and a lot more advanced threat actors that are going to try to get into my network.

Threat Modeling

So what we're going to do is we're going to go through a process using threat modeling. The idea behind threat modeling is that we're going to assess what is the threat to our systems and evaluate what the threat is to our systems. And we do that by really understanding what the threat agents are, what their motivations are, and how they would go about attacking our network. So threat modeling is identifying and enumerating potential threats to our organization. There's a lot of different threat models that are out there. We're not going to get real in-depth into this at this point in time, but just understand that we are going to be going through this threat modeling process to identify risks to our organization.

Not All Threats Are Intentional

Not all threats are intentional. We have people within the company that pose a threat to the company, and their actions, and how much experience they have, and how much understanding around security they have, and old processes and old systems within our organization all can pose a threat to our organization. We may cover that to a certain degree within this course. But the intention of this course is really to understand more of adversaries and how adversaries are going to carry out attacks against an organization. So we're going to be taking a deep dive into adversaries, those who are really intentionally going after our network, and how they're going to go about doing that.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →