Adversary characteristics—including hacker type, motivation, organizational relationship, resources, and sophistication—determine the nature and scale of threats facing an organization. Understanding these factors allows security teams to make informed decisions about where and how to invest in defenses.
Adversary Characteristics
By understanding our adversaries, we can better understand how they're going to attack our network and what they're going to try to do. So let's start understanding what are the different characteristics that we're going to look at when it comes to these adversaries.
By understanding the different characteristics of an adversary, we can better understand what is the threat to our organization. But what are the characteristics that we look at?
At the top level, there is the hacker types. Is it going to be a white hat hacker, which means that we're paying them to do pen testing or to try to hack our network? Is it going to be a black hat hacker, where they're going to try to do something malicious on our network? That's the main one that we're tackling throughout these lessons. And then a gray hat hacker, which might be trying to hack your network just to notify you that maybe you have some sort of issue on your network.
But when it comes to these black hat hackers, we've got to look at what is their motivation. We also have to look at what is their relationship to the organization, because that makes a big difference on how we protect our organization. We have to take a look at the resources that they're going to have to carry out their attack, whether it's sponsored or not, and the level of sophistication that they're going to have in carrying out their attack.
Understanding the motivation of an attacker may give us an understanding of what their target might be. For instance, maybe there's strictly a financial reward for hacking our network, but we don't have a lot of finances, there's not a lot of assets that we have. That's going to make us a low target and they're going to quickly move on, and so maybe we don't need to spend as much money on defenses. However, if we're a financial institute, we have lots of money that's available to us, so we better fully understand the threat to our organization and really protect our organization. We better sink a lot of money into guarding our assets.
Maybe it's a company, or maybe it's an employee who's left the company and now they want to carry out some sort of revenge. Maybe we are doing something unethical, or maybe something that a lot of people don't like, and so we are a target because there's activists out there that want to change the way we do business. Or maybe there's just a bad actor out there, an adversary out there that's just trying to do it because they're curious. Or maybe they just want the clout of saying they hacked into your system.
If we have somebody that's trying to hack us from the outside, we just need to make sure our perimeter is secure to a certain degree. We actually want to still practice defense in depth, but we want to make sure that the perimeter is very solid. But if we feel like there could be an insider threat, that really changes the picture. Nowadays, with social engineering and the way it is, we need to just consider that there are insider threats within our organization.
We also have to consider the resources that are backing this individual or this entity that's trying to hack our network. How much money do they have? How much time do they have? Because the more money and time that they have, the more threat they are to our system. And how much time and money they have can depend on if they're sponsored or not. Is it just an individual working alone, or nowadays there are government agencies, and there are actually scam companies that are out there targeting people. So are they sponsored or not?
And what is the level of sophistication they have? Are they somebody that is fairly young in their career and not very experienced, or is it somebody much more advanced, that they are able to really take off and have a lot of skills and knowledge in attacking the system?
By better understanding these characteristics of an adversary, then we can better understand how they're going to approach attacking our systems and our organization.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →