TechKnowSurge
VideoSecurityFree

An Adversary's Capabilities

Adversary capabilities refer to the combination of skills, knowledge, tools, and resources a threat actor uses to carry out an attack. Understanding these capabilities—from unskilled script kiddies to advanced persistent threats—is essential for building effective defenses.

Complete this video to capture a CTF flag worth 1 point.

About this video

Adversary capabilities refer to the combination of skills, knowledge, tools, and resources that an individual or group brings to bear when conducting a cyberattack. Knowledge and skill are distinct but related components: knowledge covers awareness of targets, vulnerabilities, and attack methods, while skill reflects the hands-on experience and technical ability to actually execute those methods. Not every attacker needs both in equal measure, which is what makes this concept critical to understand when assessing risk. At the lower end of the capability spectrum are unskilled attackers, often called script kiddies, who rely on pre-written scripts and automated tools to launch attacks without deep technical knowledge. At the higher end are advanced adversaries capable of discovering new vulnerabilities and building custom exploits—threats that are significantly harder to detect because they fall outside known signatures and established defenses. The most serious of these are advanced persistent threats, highly skilled actors who can infiltrate a network and remain undetected for extended periods, causing sustained damage or exfiltrating data over time. Capabilities are also expanded through access to resources that compensate for gaps in technical skill. Supply chain attacks allow adversaries to compromise hardware or software before it even reaches the target organization, inserting malicious code at any point along the manufacturing or distribution process. Internal threats—actors already operating inside a network—carry an inherent advantage due to their existing access and familiarity with the environment. Brokers further lower the barrier to entry by selling malware, exploit tools, and network access to adversaries who lack the ability to develop these capabilities on their own. Together, these factors mean that an organization's threat surface extends well beyond what any single attacker's skill level might suggest.

What you'll learn

What's covered

Adversary Capabilities

Key terms

Threat Actor
An individual or group responsible for a security incident or attack.
Malware
Software specifically designed to disrupt, damage, or gain unauthorized access to a system.
Exploit
A piece of software or technique that takes advantage of a vulnerability to gain unauthorized access or cause harm.
Zero-Day
A vulnerability that is unknown to the vendor and has no available patch at the time of exploitation.
Script Kiddie
An unskilled threat actor who uses pre-written scripts or tools to attempt unauthorized access without deep technical knowledge.
Advanced Persistent Threat
APT
Advanced Persistent Threat describes a sophisticated, long-term intrusion campaign in which a threat actor maintains unauthorized access to a target network over an extended period to steal data, conduct espionage, or pre-position for future attacks.
Supply Chain Attack
An attack that targets the less-secure elements of a product or service's supply chain to compromise the final target.
Broker
An intermediary who sells or provides access to malware, exploits, or other attack tools and capabilities to threat actors.

Topics

Threat Actors Adversary Capabilities Advanced Persistent Threats Script Kiddies Malware Cybersecurity Threat Intelligence

Transcript

What adversary capabilities means

One of the terms that you're going to run across, that you're going to need to know what it means, is adversary capabilities — the capabilities that the adversaries have, what they're capable of doing.

Different adversaries have different levels of capabilities, and their levels of capabilities depend on the tools that they have, the knowledge that they have, the skills that they have, and the resources that they have available to them. So capabilities is the skills, resources and techniques an individual or group uses to carry out an attack.

I like to think of it as different jobs. If you have a construction worker who has a certain tool and a certain knowledge of how to use that tool, they have capabilities to go out there and construct something. Versus if you have an accountant, they have a different tool set and a different knowledge set, and they're capable of doing something very different than that construction worker. If you have something like a superhero that can go out there and fly and maybe have lasers shoot out of their eyes, they have different capability sets. So each one of these is equipped with different tools and resources and skill levels to be able to carry out what their function is, what they're designed to do.

Knowledge and skill

A big part of this is the knowledge and skill, and different people have different knowledge levels and different skill levels.

Knowledge is just knowing something. For instance, I could know about the target, I could know about different hacks, but that doesn't necessarily mean I have the skills to carry out those types of attacks. So that's the knowledge part of it. The skill part of it is how much experience do I have, how capable am I to carry out whatever type of attack it is. That's the skill level. And there's everything from very basic people out there that are doing hacks because of some of the other capabilities that they have, to people who are much more advanced in carrying out these types of attacks.

Shortcuts

And there are shortcuts. So it's not just your skill level and also your knowledge level, but it's also: do you have scripts and programs that are available to you? Do you know how to program scripts and programs that can help you out during this process? What kind of access do you have to supply chains? What kind of access do you have to malware? What type of access do you have to internal threats, or are you an internal threat? And what type of brokers are out there, and what access to brokers do you have?

Internal threats are just if you're sitting inside the network. If you're an employee that's already inside the network, then you have a much greater advantage to taking over that network or inflicting problems on that network than if you were outside that network.

The supply chain

One of those shortcuts is access to the supply chain. A supply chain is where a business or an organization gets its supplies or gets its equipment. An example might be a laptop. There are a lot of things that go into the laptop. There are batteries, there are different electronic components that go in there, maybe it's the screen, maybe it's the CPU. Those are all gotten from all different companies and then assembled together, and then sold maybe to a distributor, which then sells it to the company.

Well, there are a lot of steps along the way, and so one thing that an adversary can access is anywhere along the supply chain. They might be able to insert a virus into this computer to get it inside the company. So it is a viable threat that's out there that we need to take a look at, because adversaries could have access to the supply chain, and we need to guard against that type of an attack.

Script kiddies and advanced users

Also, what kind of scripts and programs are available to you? Now more than ever, there are a lot of resources that are available for somebody who's very basic, that has very basic skills. We call this a script kiddie, because if they don't have a lot of knowledge on how to carry out an attack, but they have scripts and they have little programs that they can use to carry out this attack, they don't need a lot of skill and knowledge level. So that's why it's a script kiddie — because they're just a kid, maybe somebody who's young, somebody who doesn't know very much, and they're using these scripts.

So on one side here we've got the unskilled, or script kiddie, but there are also advanced users out there as well. Advanced users can create vulnerabilities and create exploits. They're a lot more knowledgeable, so they can create these things, which becomes much more dangerous, because it's easier to spot those things that are really prevalent out there — we've got mechanisms to spot that a lot easier. It's a lot harder to guard against something that you're not aware of, that you don't know is out there, that's been freshly created.

Advanced persistent threats

On that other side too, we have something called an advanced threat, or there's actually something called an advanced persistent threat. An advanced persistent threat is a threat — so this is an adversary, a threat agent, somebody that might be already inside of your network. They're advanced, so they're much more skilled. They know how to get along and escape: evasion. For that reason, once they get into your network, they can remain there for a long time. That's the persistent part of this. So advanced persistent threats are one of the worst threats to our network, because they go undetected and they're inside your network. This is one of the big things that we need to guard against, to make sure it doesn't happen.

Brokers

Even if an adversary doesn't have the capabilities to create new scripts and create new programs and create new viruses, that doesn't necessarily mean that they don't have access to that kind of stuff. So that's where brokers come in. Brokers is another shortcut, where an adversary can go to a broker — this would be the broker right here — and buy access, or buy some sort of viruses, or buy scripts, or buy some sort of malware, or buy some sort of programs, or buy whatever they need to carry out their attack. So there are brokers that are specifically out there doing exactly that.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →