During reconnaissance against the city's 911 CAD, analysts recover a commodity scanner sample. Who or what is the threat actor (adversary) in this incident?
Select an answer to reveal the explanation.
Short Explanation
The adversary is the burglar, not the crowbar. A hash, a C2 domain, and a CVE are tools or flaws — the threat actor is the person or group aiming at 911 CAD. Keep the human (or crew) in the subject line of the incident.
Full Explanation
Threat actor and adversary name the opposing human or group, not the malware sample, indicator, or vulnerability they used. A SHA-256, a C2 domain, and a CVE are technical artifacts that may support attribution later, but they are not the actor. Civic SOC language should keep that split so Incident Review, intel tickets, and leadership briefings do not treat a hash as if it had intent. Splunk ES can store those indicators; the actor label still belongs on the people behind the 911 CAD reconnaissance.