Threat Actor Trivia
Cyber Attack Methods
Tools/Roles
Consultant Recommendations
“Malware, Hacker Group, or Metal Band?”
100

This type of threat actor works for a government and often conducts espionage.

Nation-State Attackers

100

This attack tricks users into giving up passwords through fake emails.

Phishing

100

This website lets analysts check if a file hash is known malware.

VirusTotal

100

Employees keep getting phished — enable this second authentication factor.

MFA

100

Emotet

Malware

200

These attackers are often beginners who rely on pre-made tools and scripts rather than creating their own exploits.

Script Kiddies

200

Malware that locks files and demands payment.

Ransomware

200

This framework helps analysts map attacker behavior to known techniques.

MITRE ATT&CK

200

Your company hasn't patched servers in months. What should you improve?

Patch Management

200

DarkSide

Hacker Group

300

These attackers are often politically motivated and may deface websites to spread a message.

Hacktivists

300

An attack that floods a system with traffic to take it offline.

DDoS

300

This security team monitors alerts and responds to threats in real time.

SOC

300

Employees use the same password everywhere. What should you implement?

Password Manager

300

Behemoth

Metal Band

400

APT stands for this phrase used to describe highly skilled and persistent threat groups.

Advanced Persistent Threat

400

This attack attempts thousands of password combinations automatically.

Brute-Force Attack

400

These analysts proactively search for hidden threats that automated systems missed.

Threat Hunters

400

Your network lacks visibility into threats and alerts. What system should you deploy?

SIEM

400

TrickBot

Malware

500

This famous hacking group linked to North Korea has been connected to bank and crypto heists.

Lazarus Group

500

Attackers exploiting reused passwords across many websites are performing this attack.

Credential Stuffing

500

Ghidra is a free, open-source software reverse engineering (SRE) framework developed by the National Security Agency (NSA).

Ghidra

500

Executives want to know what threats target their industry. What service do you provide?

Threat Intelligence

500

Sandworm

Hacker Group