Precursor Security
Glossary

APT (Advanced Persistent Threat)

An advanced persistent threat (APT) is a sophisticated, well-resourced adversary, often state-sponsored, that gains and maintains long-term access to a target’s network to pursue strategic objectives such as espionage or disruption. APTs are characterised by patience, stealth and advanced techniques, and they prioritise remaining undetected over quick gains.

An advanced persistent threat is a category of adversary defined less by a single technique than by its nature: sophisticated, well-resourced, patient and goal-driven. APTs are typically state-sponsored groups or highly organised criminal operations that target specific organisations to achieve strategic objectives, and they are willing to invest months or years to do so. The term is often used loosely, but properly it describes the actor, not merely an advanced piece of malware.

The three words of the name each carry meaning. Advanced refers to the capability and resources available: custom tooling, zero-day exploits, and skilled operators. Persistent refers to the intent to maintain long-term access and pursue an objective over time, rather than smash and grab. Threat emphasises that this is a coordinated human adversary with goals, not an automated or opportunistic attack. Together they describe an adversary that is deliberate and hard to remove.

APT operations typically follow a patient lifecycle. They begin with careful reconnaissance of the target, gain initial access through a tailored phishing campaign or a targeted exploit, then establish persistence and quietly expand their foothold through privilege escalation and lateral movement. Crucially, they prioritise stealth, blending in with normal activity, using legitimate tools, and moving slowly to avoid the volume-based alarms that would catch a noisier attacker. Their goal is usually long-term espionage or positioning, so remaining undetected is the priority.

Because APTs are stealthy and patient, they often achieve long dwell times, remaining in an environment for months before discovery, if they are discovered at all. This is what makes them so dangerous: they have time to locate and exfiltrate exactly the data they want, or to position for future disruption, all while evading defences tuned to catch faster, louder attacks. Detecting them requires looking for subtle behavioural anomalies rather than obvious indicators.

Defending against APTs is demanding and rests on depth rather than any single control. Strong detection focused on behaviour and adversary techniques, mapped to frameworks like MITRE ATT&CK, gives the best chance of spotting a careful intruder. Threat intelligence about specific groups and their techniques helps defenders anticipate and recognise them. Assume-breach thinking, robust segmentation, and proactive threat hunting all improve the odds of finding an adversary who is deliberately trying not to be found.

Detecting an APT depends on assuming one may already be present and hunting for the subtle signs, rather than waiting for an obvious alarm. Because these adversaries deliberately blend in, use legitimate tools and move slowly, behavioural detection mapped to adversary techniques, proactive threat hunting, and strong segmentation offer the best chance of finding them. The goal is to compress the dwell time during which a patient intruder would otherwise operate undetected.

Precursor tracks threat actors and their techniques through its threat intelligence, and hunts for the subtle behavioural signs of a determined intruder in its managed SOC, on the assumption that a sophisticated adversary aims to blend in rather than trigger obvious alerts.