About this interactive
What you're doing: a small medical clinic has lost access to every file on its network, and an investigator has written up what happened in four lines without naming anything. You take that report apart into the four stages this module has followed from its first lesson: the threat actor, the attack vector they used to get in, the vulnerability that let them through, and the technique that did the damage. Why it matters: an attack is not one event but a chain, and each link is a different place a defender could have broken it. Training the front desk addresses the vector. Replacing a system its maker no longer supports removes the vulnerability. Backups blunt the technique. Naming the stages is what turns "we got hacked" into a list of things to fix. How to use it: the palette holds three parts for every stage, so eight parts will be left over when you finish, and they were chosen to be close. Read each line of the report and ask what it is evidence of. A group that wants money is not a group that wants change. A system that will never get another update is not a flaw its maker has not found yet. Locking files and asking for a fee is not guessing one password across many accounts, and it is not sitting between two machines to read their traffic. When you meet an unlabeled breach story in a later module, on an exam or in the news, ask the same four questions in order: who, how in, through what weakness, and doing what.
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →