1.3 The Cybersecurity Landscape

Understanding who attacks, why they attack, and how we defend

Threat Actors: Who Attacks?

Understanding who poses a threat is the first step in building effective defenses. Threat actors vary widely in their skills, resources, and motivations. Let's explore the different types:

Entry Level

Script Kiddies

Inexperienced attackers who use pre-made tools and scripts without understanding how they work. Often motivated by curiosity, fame, or just causing mischief.

Low Skill Curiosity Low Threat
Ideology

Hacktivists

Attackers motivated by political or social causes. Use hacking to promote their ideology, expose information, or disrupt organizations they oppose.

Low-Medium Skill Ideology Medium Threat
Financial

Cybercriminals

Attackers motivated by financial gain. Operate like businesses, with specialized roles. Deploy ransomware, steal data for sale, conduct fraud and extortion.

Medium-High Skill Financial High Threat
Insider

Insider Threats

Current or former employees, contractors, or partners with legitimate access. Can be malicious (intentional) or negligent (accidental). Very difficult to detect.

Varies Revenge/Money Very High Threat
State

Nation-State Actors / APT Groups

State-sponsored hackers with virtually unlimited resources, advanced capabilities, and patience. Conduct espionage, sabotage, and cyber warfare operations.

Elite Skill Espionage Critical Threat
Business

Competitors

Business rivals engaging in corporate espionage to steal trade secrets, customer lists, pricing strategies, or proprietary technology for competitive advantage.

Medium Skill Business Intel High Threat

Notable APT Groups

  • APT29 (Cozy Bear): Russian group behind the SolarWinds attack
  • APT41: Chinese group conducting espionage and financial crimes
  • Lazarus Group: North Korean group linked to the Sony hack and WannaCry ransomware
  • APT28 (Fancy Bear): Russian military intelligence group (GRU)

Motivations: Why They Attack

Understanding why attackers target systems helps predict their behavior and prioritize defenses. Different motivations lead to different attack patterns.

Motivation Description Typical Targets Attack Methods
Financial Gain Direct monetary profit through theft, extortion, or fraud Banks, healthcare, retail, any organization with valuable data Ransomware, credit card theft, business email compromise
Espionage Stealing state secrets, military intel, or intellectual property Government, defense contractors, research institutions, tech companies APT campaigns, spear phishing, supply chain attacks
Ideology Promoting political/social causes, making statements Governments, corporations, controversial organizations Website defacement, DDoS, data leaks
Revenge Retaliation for perceived wrongs, often by insiders Former employers, specific individuals Data destruction, sabotage, data leaks
Challenge/Fame Proving technical skills, gaining recognition in hacker communities "High-value" targets for bragging rights Varies, often public disclosure of exploits
Key Insight: Most attacks are financially motivated. According to Verizon's 2023 Data Breach Investigation Report (DBIR), 86% of breaches are financially motivated. This is why ransomware has become so prevalent: it is simply very profitable for criminals.

Attack Vectors: How Attacks Happen

An attack vector is the path or method an attacker uses to gain access to a target system. Understanding these vectors helps organizations build layered defenses.

Vector How It Works Real Examples
Email Phishing emails with malicious attachments (PDFs, Office docs with macros) or links to credential harvesting sites 91% of cyberattacks start with phishing email
Web Drive-by downloads from compromised/malicious websites, browser exploits, malvertising Watering hole attacks targeting specific industries
Removable Media Infected USB drives, external hard drives left in public places or sent as "gifts" Stuxnet spread via USB to air-gapped Iranian nuclear facilities
Social Engineering Manipulating humans through phone calls, in-person interactions, pretexting 2020 Twitter hack, where employees were tricked into providing credentials
Supply Chain Compromising software vendors to distribute malware through legitimate updates SolarWinds attack compromised 18,000+ organizations
Physical Access Direct access to facilities, servers, or devices through tailgating, social engineering, or breaking in Installing hardware keyloggers, evil maid attacks
The Human Factor: People are often called the "weakest link" in security. Technical controls can be bypassed when employees are tricked. This is why security awareness training is essential: even the best technical defenses can be circumvented by social engineering.

Security Frameworks Introduction

Cyber Kill Chain

Developed by Lockheed Martin, the Cyber Kill Chain describes the stages of a cyberattack from initial reconnaissance to achieving objectives. Understanding this framework helps defenders identify and disrupt attacks at any stage.

1
Recon
2
Weaponize
3
Delivery
4
Exploit
5
Install
6
C2
7
Actions
Stage Attacker Activity Defender Response
1. Reconnaissance Research target: OSINT, port scanning, identifying vulnerabilities Minimize public info, web scraping detection, log analysis
2. Weaponization Create malicious payload (malware + exploit) Threat intelligence, vulnerability management
3. Delivery Send weapon to target (email, web, USB) Email filtering, web proxy, endpoint protection
4. Exploitation Trigger vulnerability to execute code Patch management, DEP, ASLR, application whitelisting
5. Installation Install persistent backdoor/malware EDR, AV, file integrity monitoring, HIDS
6. Command & Control Establish communication with attacker infrastructure Network monitoring, DNS filtering, firewall egress rules
7. Actions on Objectives Achieve goal: data theft, destruction, ransomware Data loss prevention, network segmentation, incident response

MITRE ATT&CK Framework

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) is a comprehensive knowledge base of adversary tactics and techniques based on real-world observations. It's used for threat modeling, detection engineering, and red team exercises.

ATT&CK Structure

  • Tactics: The "why", or the adversary's goal (e.g., Initial Access, Persistence, Exfiltration)
  • Techniques: The "how", or specific methods to achieve tactics (e.g., Phishing, Registry Run Keys)
  • Sub-techniques: More granular variations of techniques
  • Procedures: Specific implementations by threat actors
Why ATT&CK Matters: ATT&CK provides a common language for security teams to describe adversary behavior. It helps organizations:
  • Identify gaps in detection capabilities
  • Prioritize security investments based on real threats
  • Map threat intelligence to specific techniques
  • Conduct realistic red team exercises

Explore the full framework at: attack.mitre.org

Defense in Depth

Defense in Depth is a security strategy that employs multiple layers of defense so that if one layer fails, others are in place. Think of it like a medieval castle: you don't rely on just the outer wall; you have moats, inner walls, towers, and guards.

Core Principle: No single security control is perfect. By layering multiple defenses, you create redundancy: an attacker must bypass multiple barriers to succeed. Each layer increases the time, effort, and likelihood of detection.

Security Layers

Physical

Physical Security

The outermost layer protects physical access to facilities and hardware.

Access badges Security guards CCTV cameras Locked server rooms Biometric access
Network

Network Security

Protecting the network infrastructure and controlling traffic flow.

Firewalls IDS/IPS VPNs Network segmentation DMZ
Endpoint

Endpoint Security

Protecting individual devices (laptops, desktops, servers, mobile).

Antivirus/EDR Host firewall Disk encryption Patch management USB controls
App

Application Security

Securing software and applications from vulnerabilities.

WAF Code review Input validation SAST/DAST Penetration testing
Data

Data Security

Protecting the data itself, regardless of where it resides.

Encryption at rest Encryption in transit DLP Data classification Backups
People

User Security

The human layer covers training and policies for people.

Security awareness Phishing simulations Password policies MFA Least privilege

Castle Analogy in Action

Imagine an attacker trying to breach a medieval castle:

  1. Moat (Network Perimeter): Firewall blocks the initial attack
  2. Outer Wall (IDS/IPS): Detects the attacker climbing over
  3. Inner Wall (Segmentation): Limits the attacker's movement
  4. Guards (EDR/SOC): Actively hunt and respond
  5. Vault (Encryption): Even if reached, the data is protected

Each layer makes the attack harder and increases the chance of detection!

Security Teams

Modern security organizations often structure their teams by function. The color-coded team model helps define roles and responsibilities in offensive and defensive security operations.

Red

Red Team

Offensive Security: Simulates real-world attackers to test defenses. Tries to breach security controls using any means necessary, just like actual adversaries.

Key Activities:
  • Penetration testing
  • Social engineering assessments
  • Physical security testing
  • Adversary emulation
  • Vulnerability exploitation
Common Tools:
Metasploit Cobalt Strike Burp Suite Nmap BloodHound Kali Linux
Blue

Blue Team

Defensive Security: Monitors, detects, and responds to security threats. Builds and maintains security infrastructure and processes.

Key Activities:
  • Security monitoring (SIEM)
  • Incident response
  • Threat hunting
  • Log analysis
  • Vulnerability management
Common Tools:
Splunk QRadar CrowdStrike Wireshark YARA Velociraptor
Purple

Purple Team

Collaborative Security: Bridges the gap between Red and Blue teams. Facilitates knowledge sharing to improve both offensive and defensive capabilities.

Key Activities:
  • Joint exercises
  • Detection engineering
  • Testing detection rules
  • Sharing TTPs
  • Continuous improvement
Focus Areas:
MITRE ATT&CK mapping Detection coverage Tabletop exercises Playbook development

Team Comparison

Aspect Red Team Blue Team Purple Team
Primary Goal Find weaknesses Detect & defend Improve both
Mindset Attacker Defender Collaborator
Approach Break things Fix things Test & validate
Output Penetration test reports Detection alerts, IR reports Detection improvements
Success Metric Vulnerabilities found Threats detected/stopped Detection coverage %
Career Tip: Early in your career, most people start on the Blue Team (SOC Analyst) because organizations need more defenders. As you gain experience and skills, you can specialize in Red Team (offensive) or move into Purple Team roles that require understanding of both sides.