TechKnowSurge
CompTIA Security+ 2.2 CompTIA Security+ 2.1 Cisco CCST Cybersecurity 1.2 ISC2 CC 1.1 CompTIA Security+ 2.4 CompTIA Security+ 2.3
InteractiveSecurityFree

Anatomy of a Breach

Read an incident report about a clinic hit by ransomware and build the breach's anatomy: who attacked, how they got in, what weakness they used, and what they did.

⚑ Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

What you're doing: a small medical clinic has lost access to every file on its network, and an investigator has written up what happened in four lines without naming anything. You take that report apart into the four stages this module has followed from its first lesson: the threat actor, the attack vector they used to get in, the vulnerability that let them through, and the technique that did the damage. Why it matters: an attack is not one event but a chain, and each link is a different place a defender could have broken it. Training the front desk addresses the vector. Replacing a system its maker no longer supports removes the vulnerability. Backups blunt the technique. Naming the stages is what turns "we got hacked" into a list of things to fix. How to use it: the palette holds three parts for every stage, so eight parts will be left over when you finish, and they were chosen to be close. Read each line of the report and ask what it is evidence of. A group that wants money is not a group that wants change. A system that will never get another update is not a flaw its maker has not found yet. Locking files and asking for a fee is not guessing one password across many accounts, and it is not sitting between two machines to read their traffic. When you meet an unlabeled breach story in a later module, on an exam or in the news, ask the same four questions in order: who, how in, through what weakness, and doing what.

What you'll learn

Aligned to

CompTIA Security+
2.2 Explain common threat vectors and attack surfaces.
2.1 Compare and contrast common threat actors and motivations.
2.4 Given a scenario, analyze indicators of malicious activity.
2.3 Explain various types of vulnerabilities.
Cisco CCST Cybersecurity
1.2 Explain common threats and vulnerabilities
ISC2 CC
1.1 Understand cybersecurity concepts

Key terms

Threat Actor
An individual or group responsible for a security incident or attack.
Attack Vector
The specific path or method a threat actor uses to gain unauthorized access to a system or network, such as a phishing email, an unpatched vulnerability, or a misconfigured network port.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Organized Crime
Structured criminal enterprises that sponsor or conduct cybercriminal activities for financial gain, operating similarly to legitimate businesses.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
End of Life
EOL
End of Life designates the point at which a vendor stops providing security patches, updates, and support for a product; systems running EOL software present elevated risk because newly discovered vulnerabilities will remain unpatched indefinitely.
Ransomware
A type of malware that encrypts a victim's files and demands payment in exchange for the decryption key.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Malware
Software specifically designed to disrupt, damage, or gain unauthorized access to a system.
Hacktivist
A threat actor who conducts hacking activities to promote political, ideological, or social change.
Script Kiddie
An unskilled threat actor who uses pre-written scripts or tools to attempt unauthorized access without deep technical knowledge.
Removable Media
Portable storage devices such as USB flash drives, SD cards, and optical discs that can be detached from a computer and used to transport, distribute, or back up data.
Supply Chain
The network of vendors, suppliers, and service providers whose hardware, software, or services an organization depends on, each representing a potential source of security vulnerability.
Zero-Day
A vulnerability that is unknown to the vendor and has no available patch at the time of exploitation.
Default Credentials
Factory-set usernames and passwords that ship with network devices, applications, and services. Default credentials must be changed immediately upon deployment because they are publicly documented and frequently targeted by automated attackers.
Password Spraying
An attack that attempts a single commonly used password against many different user accounts before moving to the next password, deliberately staying below account lockout thresholds to avoid detection.
On-Path Attack
An attack in which the adversary positions themselves between two communicating devices to intercept, relay, or alter traffic; also called a man-in-the-middle attack.

Topics

Interactive Build

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →