Adversary fingerprinting is the practice of identifying attackers by analyzing the consistent patterns and behaviors they exhibit during a network intrusion. Security teams use tools like MITRE ATT&CK and CAPEC to catalog these signatures and attribute attacks to known threat groups.
Adversary Signatures
Some of us have a very deliberate process of how we wake up and get our day started, while others of us are a little more loose in how we get started. But even those who don't have a strict routine probably have some sort of subconscious routine that they do: that they get out of bed in a certain way, that they turn off the alarm in a certain way, or they don't have an alarm at all most days, or that they brush their teeth in a certain order. There are certain patterns that we start coming up with, whether subconsciously or consciously.
The same thing is true when somebody's attacking a network. They have certain routines that they go through, and by going through these routines, we can start analyzing the traffic and what has happened and start identifying who's attacking our network based off of those routines. It's called fingerprinting, or signatures.
When I was growing up, I loved the Pink Panther movies. The Pink Panther movies starred somebody who was a detective trying to figure out who the Pink Panther was. The Pink Panther stole things like diamonds, and he'd always leave a calling card, a white glove. This was just kind of something that said, "Hey, I was here."
When somebody's breaking into your network, they don't really leave a calling card. There's no white glove to leave. But there is kind of still a calling card: their approach, and how they've broken into your network, and what they've done, leaves a certain signature, a certain footprint. We can discover that footprint to try to figure out who is breaking into our network.
When you're using some sort of biometrics like fingerprints in order to authenticate, what's happening is that the system is analyzing any kind of inconsistencies or any variations within your fingerprint. It's not mapping everything out necessarily, but mapping out certain parts of your fingerprint that are unique, and then it's logging the difference or the correlation between all of these. Now every time you use your fingerprint to authenticate, you need to have that same pattern in order for that authentication piece to work.
We can do the same thing with attack patterns. There are certain patterns that develop depending on who the adversary is — an adversary is going to have certain attack patterns. When we do our diamond model of intrusion analysis, we essentially come up with a pattern that can be placed amongst other records and other historical information to figure out who the adversary was.
In fact, we have a whole database of that. The Common Attack Pattern Enumeration and Classification, or CAPEC, identifies what the different attack patterns are that are out there. Here's the CAPEC website, and right from the get-go it says understanding how the adversary operates is essential to the effect of cyber security. So it tells us how adversaries operate. On the left here we can start searching by mechanism of attack, by domains of attack, or by other criteria. We can search this database, or I'm going to take you to another site which gives us a little more information if you're new to CAPEC. This just explains a little more about CAPEC. Essentially what it does is it analyzes these attack patterns and discovers what the different attack patterns are. We can then use this information to figure out who is the adversary behind the attack.
That's not the only information that we have to identify these adversaries. Another thing that identifies an adversary is maybe who they're targeting. Also, their motivations give us a hint as to what they're trying to do and who they are. Really, just any information that goes behind who the adversary is helps identify that adversary.
We may not know an exact name of who this adversary is, but we can create our own naming conventions on these adversaries. Think of it like a fingerprint: if we find a fingerprint at a crime scene, we still have evidence. Maybe we don't have the direct name or know whose fingerprint that is, but we can tie them maybe to other crime scenes and identify all the crimes that they committed and start identifying a specific group, and then give that group a name.
One reason why I say groups is because, remember, a threat agent or actor is either an individual or an entity, which means it could be a group of people that are actually carrying out these attacks that are all trained to kind of do the same approach.
At the MITRE ATT&CK site, which has all of our tactics and techniques and tracks all of that, I mentioned in another lesson that we also have this CTI group. I'm going to click on CTI groups, and here are a bunch of different groups that they've identified. We can track who these groups are and what they're doing and who they're trying to attack and all sorts of information about them. You can see that there's a lot of these groups here.
Let's just take a look at one of them. I want to take a look at Mustang Panda. As you can see, Mustang Panda is a China based cyber espionage threat actor that was first observed in 2017. We can find out information about this, and the name like Panda usually identifies China based cyber attacks, and then they give some other name to this as well. This is all tracked through the MITRE ATT&CK database that we have here. They actually give these groups numbers and all sorts of information about techniques that they've used and campaigns that they've carried out. We can find a wealth of information about these different adversaries and what they've used in the past.
MITRE is not the only one that tracks these. There are a lot of private companies that are tracking different adversary groups as well, and they do a little different method of doing this tracking and figuring out who's who. This is CrowdStrike's website, and we can scroll through here and see that the last name Spider means that it's eCrime. We have activist, so the Jackal means that it's activist. Panda, which is China. We've got North Korea. We've got Russian Federation. So you can see the different attack groups.
The reason why we can track these, once again, is because we created a sort of signature of a pattern that they do as they carry out these different attacks.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →