Skip to content

Adversary Classes

cpx May 28, 2025 1 min read Advanced Incident Response Cybersecurity
Image 9
Image 9
Adversary ClassCategoryDetails
Cyber VandalismGoalsPersonal motives (e.g., attention, malice), Financial gain (fraud)
ScopeOrganizational subset (e.g., public-facing service or Web site)
Timeframe, Persistence, and StealthHacker revisits specific venues sporadically, but is not persistent, nor stealthy
Examples of EffectsWeb site defacement, DoS attack, falsification of selected records
Capability ExamplesFreeware or purchased malware, purchased botnets, purchased or stolen credentials
Cyber IncursionGoalsPersonal motives (e.g., acquire personally identifiable information or PII about target individuals), Financial gain (fraud, salable information, extortion), Stepping-stone
ScopeOrganizational Operations; Organizational Associates
Timeframe, Persistence, and StealthTime-frame — and stealth: Sustained, persistent activities in selected stages of Cyber Attack Lifecycle (CAL): recon, deliver, exploit, control (limited), execute; limited concern for stealth
Examples of EffectsData breach, Ransomware, extended DoS
Capability ExamplesFreeware or purchased malware, purchased botnets, purchased or stolen credentials used to acquire more credentials and further escalate privileges
Cyber Breach & Organizational DisruptionGoalsFinancial gain (large-scale fraud or theft, salable information, extortion), Geopolitical advantage (economic), Stepping-stone
ScopeOrganizational Operations; Organizational Associates
Timeframe, Persistence, and StealthSustained with persistent, stealthy activities in most stages of CAL: recon, deliver, exploit, control, execute, maintain
Examples of EffectsExtensive data breach, Establish foothold for attacks on other organizations
Capability ExamplesAdversary-developed malware (0-day exploits)
Cyber Espionage & Extended DisruptionGoalsFinancial gain (fraud, salable information, extortion), Geopolitical advantage (all types)
ScopeOrganizational Operations; Sector
Timeframe, Persistence, and StealthSustained with persistent, stealthy activities in all stages of CAL
Examples of EffectsExtensive or repeated data breaches, Extensive or repeated DoS
Capability ExamplesMalware crafted to the target environment, to maintain long-term presence in systems
Cyber-Supported Strategic DisruptionGoalsGeopolitical advantage (all types)
ScopeOrganizational Operations for selected organizations; Sector; Nation
Timeframe, Persistence, and StealthStrategic with persistent, stealthy activities in all stages of CAL, covert activities against supply chains or supporting infrastructures, and covert intelligence-gathering
Examples of EffectsSubverted or degraded critical infrastructure
Capability ExamplesStealthy, destructive adversary-crafted malware, supply chain subversion, kinetic attacks
0 0 votes
Article Rating
guest

0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x