Missiora
Threat Actors & Threat Intelligence

Technology Fundamentals

Threat Actors & Threat Intelligence

1 min readPublished 22 Jul 2026

Track your progress. Sign in to mark this guide complete and build your Job Readiness Score.

Knowing who attacks and how helps you defend the right things.

Interactive explainer

Threat Actors

Who attacks, and why — from nation-states to insiders.

1Nation-state2Organised cybercrime3Hacktivist4Insider

Tap or hover a part to learn more.

Nation-state

Well-resourced, stealthy.

Government-backed groups (APTs) with significant resources, pursuing espionage or disruption. Patient, sophisticated and hard to detect — motivated by strategy, not money.

Check your understanding

1. Which actor is typically the most financially motivated?

2. Why are insiders especially dangerous?

Practise this in AI Interview™

Who and how

  • Threat actors: nation-state (well-resourced, stealthy), organised cybercrime (financially motivated, ransomware), hacktivists (ideological), insiders (malicious or negligent) and script kiddies.
  • Threat intelligence turns raw data into decisions — IOCs (indicators of compromise like malicious IPs/hashes) and TTPs (tactics, techniques and procedures).
  • MITRE ATT&CK is the shared language for adversary behaviour, complementing the cyber kill chain.

This feeds directly into Security Operations and threat hunting.

Interview Intelligence

How this topic actually shows up in interviews — and how to demonstrate you understand it.

Why employers ask about this

Contextualising attacks by actor and technique is core to modern detection and defence.

Technical questions
Compare a nation-state actor with organised cybercrime.+

Nation-state: stealthy, patient, strategic; cybercrime: financially driven, often ransomware, faster and noisier.

Behavioural questions
Describe how you'd keep up with emerging threats.+

Show using threat feeds, advisories and ATT&CK to stay current and prioritise.

Real-world scenarios
“A threat feed reports an actor targeting your sector.”+

Expected answer: Map their TTPs to ATT&CK, check for matching IOCs in your logs and prioritise relevant detections.

Employability Intelligence

Where this knowledge takes you — the jobs, skills and certifications it feeds into.

Relevant roles
SOC AnalystThreat Intelligence AnalystPenetration Tester
Skills you're proving
Threat actorsThreat intelligenceMITRE ATT&CK
Recommended certifications
CompTIA Security+CompTIA CySA+CompTIA PenTest+
Career progression

Cyber Fundamentals → Security+/CySA+ → SOC/Threat Intel.

What employers expect

That you understand core security principles and can apply them to real risks, controls and incidents.

Frequently asked questions

What is a threat actor?

Any individual or group that carries out or intends to carry out malicious activity — from nation-states to insiders.

What is the difference between an IOC and a TTP?

An IOC is evidence of a specific compromise (e.g. a bad IP); a TTP describes how an actor operates.

What is MITRE ATT&CK?

A knowledge base of real-world adversary tactics and techniques used to map detections and defences.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.