APT
Advanced Persistent Threat
Fortgeschrittene, andauernde Bedrohung
An APT is a well-resourced, targeted adversary that establishes itself persistently and as undetected as possible in a network, rather than seeking quick damage. Characteristic are patience, tailored procedures and often state or criminal resources in the background. The term describes less a single technique than a threat profile.
History & facts. The term arose in the military and intelligence environment and describes actors that pursue a clear objective — espionage, sabotage or long-term access — and have the time and means for it. Such groups are given identifiers in the professional community and characterised by their recurring procedures (tactics, techniques, procedures), as systematised for instance by Adversarial Tactics, Techniques & Common Knowledge (ATT&CK).
Outlook & recommendation. Against a patient, well-resourced attacker, no single tool helps — only end-to-end visibility and a rehearsed response: whoever sits undetected in the network for weeks or months leaves traces — if someone sees them. This very gap between compromise and discovery is addressed by operated detection and response (Digital Forensics and Incident Response (DFIR)/Managed Detection and Response (MDR)), a core field of NEOSEC.