ATK

Threats & attacks

The attacks and attacker techniques a small firm is actually likely to face.

19 terms

The attack types and attacker techniques most likely to actually reach a small firm — not a theoretical catalogue, but the ones worth planning for.

Showing 19 of 19
Advanced persistent threat (APT) A patient, well-resourced attacker that stays hidden in a network over time. Brute force attack Systematically guessing passwords or keys until one works. Business email compromise (BEC) An attacker impersonates an executive or vendor's email to redirect a payment. Credential stuffing Trying leaked username/password pairs against other sites, betting on reuse. Cross-site scripting (XSS) Injecting malicious script into a site so it runs in another visitor's browser. Deepfake fraud Using AI-generated audio or video to convincingly impersonate someone. Distributed denial-of-service (DDoS) Flooding a system with traffic until it can't serve real users. Insider threat Harm caused by someone with legitimate access, malicious or careless. Malware Software built to damage, disrupt, or gain unauthorized access to a system. Man-in-the-middle attack (MITM) An attacker secretly intercepts communication between two parties. Phishing A fake message designed to trick someone into handing over credentials or money. Ransomware Malware that encrypts your files and demands payment to unlock them. Session hijacking Stealing a valid login session to act as an already-authenticated user. Smishing & vishing Phishing delivered by text message or phone call instead of email. Social engineering Manipulating a person, not a system, into breaking security procedure. Spear phishing Phishing aimed at one specific person using details that make it believable. SQL injection (SQLi) Sneaking database commands into a web form to run them against the database. Supply chain attack Compromising a trusted vendor to reach their downstream customers. Zero-day A vulnerability being exploited before the vendor has released a fix.