D8 · CySA+

What is threat actor profiling?

Threat actor profiling documents known threat groups — their TTPs, tools, infrastructure patterns, targeting preferences, and historical campaigns — enabling intelligence-driven defense.
Named groups: APT28/Fancy Bear (Russia, election interference), APT41 (China, espionage+cybercrime), Lazarus Group (North Korea, financial crime). Use MITRE ATT&CK Group pages for TTP details. Prioritize defenses against groups known to target your industry and geography.
← Back to Glossary Practice Questions →