1/46
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Threat Vector
The method or path an attacker uses to reach or compromise a target.
Messaging Threat Vector
Using email, SMS, instant messaging, or similar communication to deliver malicious content or social engineering.
Malicious File
A file designed to execute malicious code, exploit a vulnerability, or deceive a user.
Executable File Risk
An executable can directly run malicious code when opened.
PDF Attack Vector
PDF files can contain scripts or objects that may be used maliciously.
Archive File Risk
ZIP and RAR files can conceal or package malicious content.
Office Document Attack Vector
Office documents may contain malicious macros or other active content.
SVG
Scalable Vector Graphics, an XML-based image format that can contain HTML or JavaScript and may be used maliciously.
Browser Extension Risk
A malicious browser extension can add unwanted or harmful capabilities to a browser.
Drive-by Download
Malware downloaded from a malicious or compromised website without the user intentionally downloading the malware.
Voice Threat Vector
Using telephone or voice communication as part of an attack or social engineering attempt.
Removable Media
Portable storage such as USB devices that can introduce malware or remove sensitive information.
Malicious USB Device
A modified USB device may impersonate another device such as a keyboard and automatically enter commands.
Air Gap
Physical or logical separation that prevents direct network communication between systems or networks.
Removable Media and Air Gaps
USB devices can transfer malware or information into or out of systems that do not have direct network connectivity.
Vulnerable Software
Software containing weaknesses that attackers may exploit.
Unsupported Software
Software for which the manufacturer no longer provides updates or security patches.
Asset Inventory
A record of organizational systems and software that helps identify assets requiring updates or replacement.
Network Scan
A method of identifying systems, services, or vulnerabilities on a network.
802.1X
Network authentication technology used to authenticate devices or users before allowing wired or wireless network access.
Wireless Threat Vector
Attack path involving wireless networks, including rogue access points, open networks, or weak security protocols.
Rogue Access Point
An unauthorized wireless access point that can create an untrusted path into or through a network.
Open Port
A network port accepting connections for a service, potentially increasing the attack surface.
Open Port Risk
More unnecessary exposed services and ports create additional opportunities for attack.
Default Credentials
Manufacturer-provided usernames and passwords that may be publicly known and should be changed.
Supply Chain Attack
An attack that compromises a trusted vendor, product, service provider, hardware component, or software component to reach the intended target.
MSP
Managed Service Provider, a third-party organization that manages services for customers and can become part of the supply-chain attack surface.
Target Supply Chain Breach
Attackers compromised an HVAC vendor and used its access to reach Target systems and ultimately point-of-sale systems.
Phishing
Fraudulent communication designed to trick a victim into revealing information, opening malicious content, or performing an attacker-desired action.
Phishing Warning Signs
Unexpected messages, suspicious senders or domains, unusual links, urgency, formatting problems, or credential requests.
Vishing
Voice-based phishing conducted through phone or voice communication.
Smishing
Phishing conducted through SMS or text messages.
Pretexting
Social engineering using a fabricated story or scenario to convince a victim to provide information or perform an action.
Pretext
The fabricated story or scenario used during a social engineering attack.
Impersonation
Pretending to be another person or trusted organization to manipulate a victim.
Typosquatting
Registering or using a misspelled or look-alike domain to deceive users who mistype or misread a legitimate address.
Watering Hole Attack
Compromising a website frequently visited by the intended targets and waiting for them to visit it.
Watering Hole Process
Research the target, identify a frequently visited site, compromise the site, wait for the victim, then attack when the victim visits.
Misinformation
False or inaccurate information that may be spread regardless of intent.
Disinformation
False information deliberately created or distributed to deceive.
False Information Amplification
Fake accounts can create posts and artificial engagement that algorithms amplify before real users begin sharing the content.
Brand Impersonation
Using the identity or appearance of a trusted brand to make malicious communications or websites appear legitimate.
Phishing vs Vishing
Phishing is the broader fraudulent communication attack, while vishing specifically uses voice.
Vishing vs Smishing
Vishing uses voice calls, while smishing uses SMS or text messages.
Pretexting vs Impersonation
Pretexting creates the fake story or scenario, while impersonation involves pretending to be a trusted person or organization.
Typosquatting vs Impersonation
Typosquatting relies on a similar or misspelled domain, while impersonation relies on pretending to be a trusted identity.
Threat Actor vs Threat Vector
Threat actor is who attacks, while threat vector is how the attack is delivered.