Nemstar Insights

What is hacking and how does it work?

By Sean Hanna, Founder & Director of Nemstar

January 14, 2025

What is a hacker?

According to Google and TechTarget.com, it is: anyone attempting to gain unauthorized access to a computer computing system or network with the intent of disabling, disrupting or destroying it.

Or using hacking techniques on computer systems to alter, block, delete, manipulate or steal the data held within these systems.

A cyber attack can be launched from anywhere by any individual or group.

It sounds boring when I look at the definition. I think:

“Geez, if I had read that, I don’t know if I would’ve actually started a career in this. It must be more interesting than that!”.

 

Types of hackers

There are many different types of hackers using threat intelligence to get past network security. White hat or ethical hackers are computer security experts or programmers who use technical skills to find cybersecurity vulnerabilities in order to fix them. And there are also black hat hackers who use methods like social engineering to find vulnerabilities and take advantage of them.

 

Hacking tools, how do hackers hack?

You see the definition of what a hacker is, is not actually that interesting. But how they accomplish a hack, the steps they take and the modus operandi of the hacker is incredibly interesting. As a security architect and security consultant, I am interested in two really important things: Tactics, techniques and procedures (TTPs) and Indicators of Compromise (IOCs).

 

What are Tactics, Techniques and Procedures (TTPs)?

The TTP of a hacker is their modus operandi. The tactics, the techniques, and the procedures they use even if it is for ethical hacking. Hackers deploy different ways of attacking networks. They all follow the same general principles, but each group of hackers, or APTs (Advanced Persistent Threat Groups) has a different modus operandi.

They’ve got signatures. Tell-tale things that one crew do that the other crew doesn’t. And if we understand the TTP: the tactics, the techniques, and the procedures that hackers deploy, we’re in a better position to defend ourselves.

 

What are Indicators of Compromise (IOCs)?

The other thing I’m interested in is the IOCs, the indicators of compromise. We need to watch out. We need to check. We need to continuously be vigilant to find out if someone’s attacking the network. And if they’ve been successful or not. Think of it as a burglar alarm for your network and your systems. If you were going to install a burglar alarm, a detective control, what would you look for?

 

Wrapping up….

If you understand TTPs, you already have a head start. You’re looking for the tactics, techniques, and procedures that are commonly deployed. When you deploy anti-virus, a firewall, IDS, IPS and XDR, these detective controls work on IOCs.

TTPs are what the hacker does. IOCs are little tell-tale signs that someone’s trying to get in or has successfully got into your network.

Coming Soon


About the Author:

Sean Hanna

Founder & Director

Sean Hanna founded Nemstar in 2009, leveraging 20+ years of cybersecurity expertise to deliver business-focused technical training. As EC Council’s Global Security Trainer of the Year, he has trained thousands globally, including at Microsoft, GCHQ, and the U.S. Navy. Sean led Microsoft Exchange 2000’s technical training launch and helps organizations strengthen their cybersecurity defenses.

Interested in Learning More?

If you are keen to progress your skills as an ethical hacker, check out our courses