Adversary capabilities refer to the combination of skills, knowledge, tools, and resources a threat actor uses to carry out an attack. Understanding these capabilities—from unskilled script kiddies to advanced persistent threats—is essential for building effective defenses.
Adversary Capabilities
One of the terms that you're going to run across, that you're going to need to know what it means, is adversary capabilities — the capabilities that the adversaries have, what they're capable of doing.
Different adversaries have different levels of capabilities, and their levels of capabilities depend on the tools that they have, the knowledge that they have, the skills that they have, and the resources that they have available to them. So capabilities is the skills, resources and techniques an individual or group uses to carry out an attack.
I like to think of it as different jobs. If you have a construction worker who has a certain tool and a certain knowledge of how to use that tool, they have capabilities to go out there and construct something. Versus if you have an accountant, they have a different tool set and a different knowledge set, and they're capable of doing something very different than that construction worker. If you have something like a superhero that can go out there and fly and maybe have lasers shoot out of their eyes, they have different capability sets. So each one of these is equipped with different tools and resources and skill levels to be able to carry out what their function is, what they're designed to do.
A big part of this is the knowledge and skill, and different people have different knowledge levels and different skill levels.
Knowledge is just knowing something. For instance, I could know about the target, I could know about different hacks, but that doesn't necessarily mean I have the skills to carry out those types of attacks. So that's the knowledge part of it. The skill part of it is how much experience do I have, how capable am I to carry out whatever type of attack it is. That's the skill level. And there's everything from very basic people out there that are doing hacks because of some of the other capabilities that they have, to people who are much more advanced in carrying out these types of attacks.
And there are shortcuts. So it's not just your skill level and also your knowledge level, but it's also: do you have scripts and programs that are available to you? Do you know how to program scripts and programs that can help you out during this process? What kind of access do you have to supply chains? What kind of access do you have to malware? What type of access do you have to internal threats, or are you an internal threat? And what type of brokers are out there, and what access to brokers do you have?
Internal threats are just if you're sitting inside the network. If you're an employee that's already inside the network, then you have a much greater advantage to taking over that network or inflicting problems on that network than if you were outside that network.
One of those shortcuts is access to the supply chain. A supply chain is where a business or an organization gets its supplies or gets its equipment. An example might be a laptop. There are a lot of things that go into the laptop. There are batteries, there are different electronic components that go in there, maybe it's the screen, maybe it's the CPU. Those are all gotten from all different companies and then assembled together, and then sold maybe to a distributor, which then sells it to the company.
Well, there are a lot of steps along the way, and so one thing that an adversary can access is anywhere along the supply chain. They might be able to insert a virus into this computer to get it inside the company. So it is a viable threat that's out there that we need to take a look at, because adversaries could have access to the supply chain, and we need to guard against that type of an attack.
Also, what kind of scripts and programs are available to you? Now more than ever, there are a lot of resources that are available for somebody who's very basic, that has very basic skills. We call this a script kiddie, because if they don't have a lot of knowledge on how to carry out an attack, but they have scripts and they have little programs that they can use to carry out this attack, they don't need a lot of skill and knowledge level. So that's why it's a script kiddie — because they're just a kid, maybe somebody who's young, somebody who doesn't know very much, and they're using these scripts.
So on one side here we've got the unskilled, or script kiddie, but there are also advanced users out there as well. Advanced users can create vulnerabilities and create exploits. They're a lot more knowledgeable, so they can create these things, which becomes much more dangerous, because it's easier to spot those things that are really prevalent out there — we've got mechanisms to spot that a lot easier. It's a lot harder to guard against something that you're not aware of, that you don't know is out there, that's been freshly created.
On that other side too, we have something called an advanced threat, or there's actually something called an advanced persistent threat. An advanced persistent threat is a threat — so this is an adversary, a threat agent, somebody that might be already inside of your network. They're advanced, so they're much more skilled. They know how to get along and escape: evasion. For that reason, once they get into your network, they can remain there for a long time. That's the persistent part of this. So advanced persistent threats are one of the worst threats to our network, because they go undetected and they're inside your network. This is one of the big things that we need to guard against, to make sure it doesn't happen.
Even if an adversary doesn't have the capabilities to create new scripts and create new programs and create new viruses, that doesn't necessarily mean that they don't have access to that kind of stuff. So that's where brokers come in. Brokers is another shortcut, where an adversary can go to a broker — this would be the broker right here — and buy access, or buy some sort of viruses, or buy scripts, or buy some sort of malware, or buy some sort of programs, or buy whatever they need to carry out their attack. So there are brokers that are specifically out there doing exactly that.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →