CYBER THREATS
Common attack techniques
Each guide explains the threat, warning signs and practical protections. You can export it as a PDF for awareness training.
Human manipulation
9 guidesA fake paper letter impersonates the French tax authority and demands an urgent cryptocurrency declaration through a QR code leading to a fraudulent site.
Manipulating someone into revealing information, granting access or taking an unsafe action.
A fake message or website designed to steal credentials or bank details, or make you open a file.
A phishing message tailored using real information about a person or organisation.
A fraudulent text that urges you to click, call or share information.
A fraudulent phone call impersonating a bank, public authority or technical support.
A QR code that leads to a fake website or triggers an unsafe action on a phone.
Impersonating a manager or partner to obtain a bank transfer or confidential information.
A fake technician claims to have found a problem and tries to take control of a device.
Malware
26 guidesMalware that encrypts or blocks data and then demands a ransom, often after stealing it.
Malware that attaches to a file and replicates when that file is run.
A program that looks legitimate while installing a hidden malicious function.
Standalone malware capable of spreading automatically from one device to another.
Software that secretly observes activity and collects personal or business information.
Software or hardware that records typed keys, potentially capturing passwords.
Stealth software that hides its presence and grants deep access to a system.
A network of infected devices remotely controlled by an attacker.
Software that displays intrusive ads and may track a user's activity.
A hidden access path that lets an attacker return without normal authentication.
Malware that secretly uses a device's resources to mine cryptocurrency.
Software designed to steal passwords, cookies, bank details and other sensitive data.
Malicious software or behaviour associated with malware downloader that can compromise devices, data, credentials or access.
Malicious software or behaviour associated with malware dropper that can compromise devices, data, credentials or access.
Malicious software or behaviour associated with remote access trojan that can compromise devices, data, credentials or access.
Malicious software or behaviour associated with wiper malware that can compromise devices, data, credentials or access.
Malicious software or behaviour associated with scareware that can compromise devices, data, credentials or access.
Malicious software or behaviour associated with banking trojan that can compromise devices, data, credentials or access.
Malicious software or behaviour associated with mobile malware that can compromise devices, data, credentials or access.
Malicious software or behaviour associated with fileless malware that can compromise devices, data, credentials or access.
Malicious software or behaviour associated with exploit kit that can compromise devices, data, credentials or access.
Malicious software or behaviour associated with web shell that can compromise devices, data, credentials or access.
Malicious code injected into an online store to capture card details entered at checkout.
Malicious software or behaviour associated with malvertising that can compromise devices, data, credentials or access.
Malicious software or behaviour associated with browser hijacker that can compromise devices, data, credentials or access.
Malicious software or behaviour associated with logic bomb that can compromise devices, data, credentials or access.
Accounts & identity
24 guidesAn identity and access attack involving credential phishing that can compromise an online account or authenticated session.
An identity and access attack involving password spraying that can compromise an online account or authenticated session.
An identity and access attack involving session hijacking that can compromise an online account or authenticated session.
An identity and access attack involving cookie theft that can compromise an online account or authenticated session.
An identity and access attack involving account takeover that can compromise an online account or authenticated session.
An identity and access attack involving mfa bypass that can compromise an online account or authenticated session.
An identity and access attack involving adversary-in-the-middle phishing that can compromise an online account or authenticated session.
An identity and access attack involving consent phishing that can compromise an online account or authenticated session.
An identity and access attack involving oauth token theft that can compromise an online account or authenticated session.
An identity and access attack involving account recovery abuse that can compromise an online account or authenticated session.
An identity and access attack involving security question attack that can compromise an online account or authenticated session.
An identity and access attack involving pass-the-cookie that can compromise an online account or authenticated session.
An identity and access attack involving pass-the-token that can compromise an online account or authenticated session.
An identity and access attack involving fake account creation that can compromise an online account or authenticated session.
An identity and access attack involving email compromise that can compromise an online account or authenticated session.
An identity and access attack involving password reset bombing that can compromise an online account or authenticated session.
An identity and access attack involving targeted push fatigue that can compromise an online account or authenticated session.
An identity and access attack involving impossible travel that can compromise an online account or authenticated session.
An identity and access attack involving dormant account abuse that can compromise an online account or authenticated session.
An identity and access attack involving privilege escalation that can compromise an online account or authenticated session.
An identity and access attack involving brute-force attack that can compromise an online account or authenticated session.
An identity and access attack involving credential stuffing that can compromise an online account or authenticated session.
An identity and access attack involving mfa fatigue that can compromise an online account or authenticated session.
An attacker transfers a phone number to another SIM or eSIM to intercept calls and security codes.
Web & network
26 guidesA web or network attack involving arp spoofing that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving evil twin wi-fi that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving packet sniffing that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving ssl stripping that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving dns cache poisoning that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving domain hijacking that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving dns tunneling that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving malicious http redirect that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving cross-site scripting that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving sql injection that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving cross-site request forgery that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving path traversal that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving file inclusion that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving server-side request forgery that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving http request smuggling that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving web cache poisoning that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving clickjacking that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving port scanning that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving bgp hijacking that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving dns rebinding that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving subdomain takeover that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving websocket attack that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving http flood that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving man-in-the-middle attack that can intercept, redirect, manipulate or disrupt traffic.
A web or network attack involving drive-by download that can intercept, redirect, manipulate or disrupt traffic.
Manipulation of name resolution that sends users to an unintended destination.
Infrastructure
32 guidesAn infrastructure attack involving distributed denial of service that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving server compromise that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving infrastructure privilege escalation that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving cloud misconfiguration that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving public cloud storage exposure that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving cloud account takeover that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving api key theft that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving secret leakage that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving ci/cd compromise that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving dependency compromise that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving package typosquatting that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving dependency confusion that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving backup compromise that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving snapshot deletion that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving hyperjacking that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving virtual machine escape that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving container escape that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving kubernetes compromise that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving cloud cryptojacking that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving exposed service that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving rdp attack that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving ssh attack that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving vpn compromise that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving active directory attack that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving golden ticket attack that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving pass-the-hash that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving pass-the-ticket that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving lateral movement that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving infrastructure persistence that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving data exfiltration that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving data destruction that can expose, disrupt or compromise systems, services or data.
An infrastructure attack involving supply chain attack that can expose, disrupt or compromise systems, services or data.