MEET THE TEAM AT BLACK HAT - DEF CON 2026 Learn More

SANS Institute: Inside the Minds & Methods of Modern Adversaries

This inaugural report, in partnership with Bishop Fox, surveyed 280 ethical hackers to understand how adversaries think about the attack surfaces that they seek to exploit.

Cover page of the SANS Report Hacker Survey 2022

Unlike other surveys, which take a defender’s point of view and leverage past trends to predict the future, our report flips the script to explore how adversaries view environments and to uncover insights into where they find the most success. By better understanding the minds and methods of attackers, defenders can improve their security posture and refine offensive and defensive strategies.


Key Highlights From the Report


Which Exploitable Exposures Are Most Often Found on the Perimeter?

Attackers take the path of least resistance to exploit their targets. Our research indicates they frequently have lots of options to choose from. Respondents reported all of the exposure types we surveyed on were quite common, except for abandoned domains/subdomains. Vulnerable configurations topped the list, with exposed web services and vulnerable software right behind.

How Quickly Can Your Data Be Exfiltrated?

Nearly 64% of ethical hackers reported being able to collect and potentially exfiltrate data in five hours or less once they had gained access to an environment, and an astonishing 41% were successful in two hours or less. As adversaries get “further along” in their attacks, they often either gain speed advantages (due to lack of detection), or become so familiar with the environment that exfiltration is radically simplified.

Bar graph showing how quickly data can be exfiltrated by hackers.

How Do Detection & Response Capabilities Stack Up?

Shockingly, 74% of survey respondents indicated that only few or some organizations have sufficient detection and response capabilities to effectively stop an attack. Adversaries realize that the ability to detect and respond is still significantly inadequate and use it to their advantage. Get the complete report to see if defenders did any better when it comes to preventing, detecting, and responding to cloud- and application-specific attacks.

SANS Survey - Organizations Ability to Detect and Respond

Continue your journey into the minds and methods of modern adversaries and see how you can improve proactive defenses against common attacks. Get the full report now.


Matt Bromiley SANS Headshot

About the author, Matt Bromiley

Certified Instructor at SANS Institute

Matt Bromiley is a principal incident response consultant at a top digital forensics and incident response (DFIR) firm. In the DFIR firm Matt assists clients with incident response, digital forensics, and litigation support. He also serves as a GIAC Advisory Board member, a subject-matter expert for the SANS Security Awareness, and a technical writer for the SANS Analyst Program. Matt brings his passion for digital forensics to the classroom as a SANS Instructor for FOR508: Advanced Incident Response, Threat Hunting and Digital Forensics, and FOR572: Advanced Network Forensics, where he focuses on providing students with implementable tools and concepts.