TechKnowSurge
NIST NICE K0825 NIST NICE K0831 ISC2 CC 1.2 Cisco CCST Cybersecurity 1.2 NIST NICE K0820 NIST CSF GV.SC-07 NIST 800-53 SR-3 NIST NICE K0803
VideoSecurityFree

Threats - Common Attack Vectors

Attack surfaces represent the total sum of potential entry points into an organization, while attack vectors are the specific methods threat actors use to exploit them. This content covers physical, digital, and human attack categories, along with supply chain risks and cloud service models.

Complete this video to capture a CTF flag worth 1 point.

About this video

Every organization presents a combination of potential entry points that, taken together, form its attack surface. A threat actor surveys this surface to identify weaknesses before selecting a specific attack vector — the precise method used to gain unauthorized access. The distinction matters because reducing the attack surface limits the options available to an attacker, while understanding individual vectors informs how defenses are prioritized and deployed. Attack vectors fall into three broad categories. Physical vectors involve direct access to facilities or equipment, whether through unlocked doors, tailgating, or tampering with hardware on-site. Digital vectors include unsecured wireless and wired networks, open firewall ports, software vulnerabilities, malicious files, default credentials left on networked devices, and removable media introduced by users. Human vectors leverage predictable behavioral patterns through social engineering, delivered via email, text, phone, or in-person contact, to manipulate individuals into actions that grant an attacker a foothold in the environment. The supply chain represents a fourth dimension of risk that cuts across all three categories. Organizations depend on external vendors for hardware, software, cloud infrastructure, and managed services, and any weakness in those relationships can become an exploitable vector. A compromised hardware shipment, a vulnerable third-party application, or a managed service provider with poor internal security practices can all introduce risk that the organization itself has limited ability to detect or control. Cloud service models — including Software as a Service, Infrastructure as a Service, and Platform as a Service — each carry different security implications under the shared responsibility model, where some controls belong to the provider and others remain with the customer. Knowing where those boundaries fall is essential to ensuring that neither party assumes the other has covered a critical area of exposure.

What you'll learn

What's covered

Attack Surfaces & Vectors

Aligned to

NIST NICE
K0825 Knowledge of threat vector characteristics
K0831 Knowledge of network attack vectors
K0820 Knowledge of supply chain risks
K0803 Knowledge of supply chain risk management principles and practices
ISC2 CC
1.2 Understand risk management concepts
Cisco CCST Cybersecurity
1.2 Explain common threats and vulnerabilities
NIST CSF
GV.SC-07 The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship
NIST 800-53
SR-3 Supply Chain Controls and Processes

Key terms

Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Attack Vector
The specific path or method a threat actor uses to gain unauthorized access to a system or network, such as a phishing email, an unpatched vulnerability, or a misconfigured network port.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
Phishing
A social engineering attack that uses deceptive emails or messages to trick users into revealing sensitive information.
Infrastructure as a Service
IaaS
A cloud service model that provides virtualized computing infrastructure over the internet.
Platform as a Service
PaaS
A cloud service model that provides a platform for developing, running, and managing applications without managing infrastructure.
Software as a Service
SaaS
A cloud service model that delivers software applications over the internet on a subscription basis.
Managed Service Provider
MSP
A third-party company that remotely manages a customer's IT infrastructure or end-user systems. MSPs can introduce shared security risks; a compromised MSP can serve as a launchpad for attacks against all of its clients simultaneously.
Supply Chain
The network of vendors, suppliers, and service providers whose hardware, software, or services an organization depends on, each representing a potential source of security vulnerability.
Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.

Topics

Attack Vectors Attack Surface Supply Chain Security Social Engineering Cloud Security Cybersecurity Threats Physical Security

Transcript

When a threat actor targets an organization, they're going to start looking for the way into the organization. What can they leverage to get into the organization? They're going to look at the attack surface and they're going to look for attack vectors to get in.

Attack Surface and Attack Vector

We can think of the attack surface as all of the different ways combined of how we can get into an organization. I'm going to use this building as an example. Let's say we are trying to break into this building. We may be able to get through the front door, or perhaps we can tunnel into the building. Perhaps we can get through one of the windows. Maybe there's a rooftop access, or maybe we're going to break through a wall. The attack surface of this building would be all of this together, all of the different ways that we could actually break into this building.

The attack vector would be the specific way that we chose to break into it. So if we were to access this building through a window, then that would be our attack vector. If it's through the door, that would be the attack vector. Rooftop access, then that would be it.

Since we're talking about cyber security, let's apply this attack surface to our network and see what that looks like. We have a firewall right here and that guards our network, and so what we have is an attack surface that looks a little like this. However, we also have this wireless signal that's right here. This is a wireless access point and it broadcasts out a big signal, and so anything that's within that signal also has access to this network to a certain degree. So that extends our attack surface.

Physical, Digital and Human

To better understand the concept, I've broken down the attack surfaces into three different categories. We have the physical attack surface, we have the digital, and we have the human.

The physical is what we've already talked about: physically being able to access into the building, or perhaps it's into the network closet, or access to the equipment wherever that equipment might be. And the problem is that if we have access into the building and break into the building, then what we could do is unplug somebody's computer and plug our own equipment into it, and now we have access to the resources on that network.

We also have to consider the digital attack surface. There is information that's flowing in and out of this network, and since information flows in and out of this network, there might be a way to leverage some of that to get into this network. As an example, this wireless network just gets broadcasted out, and there's no way to really secure the waves from being able to reach anyone. And so if we were sitting out here, we'd be able to access, at least from a layer 1 and two standpoint, some of the information that's flowing. And so that's why it's really important to secure our wireless networks.

Then there's the human side of this. People are physically walking in and out of that building and sitting down at these different machines. They're doing things like accessing their email. So if we can send them an email and leverage some social engineering to trick them into installing something on this machine, we now have access to the rest of the network and the resources on that network. And leveraging social engineering by sending an email and tricking somebody into downloading some sort of software onto that computer is an example of an attack vector.

Physical Vectors

Within each of these attack surfaces, there are many different ways that we can trick, or we can manipulate or change things, as an attack vector to get into this network.

Physically gaining access could be as simple as walking in the front door. Although what I've seen is that buildings have been more secure and more locked down than they ever have been before, so it may require some sort of social engineering, something like tailgating, to be able to gain access into the physical building.

Network and Hardware Vectors

From a digital standpoint, we could leverage the network. One example might be that we could sit outside the building and gain access to the wireless access points in the wireless network to try to leverage it to get into the rest of the network. Or perhaps we leverage some sort of hardware. Laptops might be brought in and out of that network, and when it's outside of the network, something malicious could happen to it that would be brought back into the network. For instance, we could install some sort of software on it. Software also gets installed and people want that on their machines, and so they'll do that. Or perhaps it's some sort of files that are being transferred back and forth.

An attacker may use unsecured networks as a vector to get into the network. Perhaps it's the wireless network or the wired network, or perhaps it's something like a Bluetooth device that is connecting. Or there could be some open service ports. There are times when we open up holes in the firewall so that they can gain access to things like maybe a web server. Well, those are open ports on the firewall to gain access to the server, and there is a level of access to that server that might be able to be leveraged to gain access to the rest of the network.

There's also hardware that gets installed on your network, whether it's a computer or a switch or server or some other device. And are you getting those from the proper vendor? So that could be a problem as well. Or just removable media: people taking flash drives, random flash drives or other flash drives, and then putting it onto their computer, which could carry a virus.

Software and File Vectors

An attacker may use software and files as a vector to gain access into an organization. Perhaps they're using some sort of vulnerability in already existing software, or perhaps there is some malicious software that they're tricking somebody into installing. A client-based would mean that it gets installed on the machine and runs on the machine, and the agent-based doesn't need to be installed for it to be up and running on the machine. We can also take some of this malicious software and embed it into files, whether it's some sort of image or some sort of document. We can embed it so that we can more easily trick somebody into installing that software.

There's also unsupported systems and applications that get set up on a network. I've had people set up equipment. I've had people install software that cause problems on the network, because they think that they want these extra services and don't want to go through it, so they just install it and then that will cause problems. One of the problems is when this stuff gets installed, a lot of people will leave the default credentials. Well, that can mean that anybody can get onto that device and easily look up these default credentials to be able to gain access, therefore gaining access to the rest of the network and other resources.

The Human Vector

Then we have the human aspect of it, or the social engineering. Humans behave in certain patterns, and attackers know how to leverage those patterns to get what they want. Of course, to carry out a social engineering attack, there's got to be some sort of contact. And that contact could come in the form of some sort of message-based contact like email or text messages or instant messaging, or it could be over the phone, some sort of voice conversation, or it could actually be in person.

The Supply Chain

Now, I've included supply chain as its own category, but it really has roots in all of the other categories. It's just one other aspect we need to keep in mind.

So what is a supply chain? A supply chain is all the goods and resources and everything that goes into creating a product. That's the general idea of what a supply chain is. But what does it look like when it comes to IT? When it comes to IT, supply chain is where we get our resources to provide our services. So we are buying hardware, we're buying software, we're buying cloud resources, we're buying services from other entities. We're buying this stuff so that we can provide resources to our users.

What we need to do is keep that in mind, because if we're buying hardware then there could actually be flaws in that hardware, vulnerabilities in that hardware, or even malicious stuff already installed in that hardware, or even the software, and utilizing the clouds. It's just one other aspect we need to consider because it can be a vector for the attackers.

Just a few things to call out. One of the things is a managed service provider. A managed service provider provides some sort of services for us. For instance, maybe that service is help desk, and so they're providing our help desk services for it. Well, if they have problems within their organization and they're not being secure in the way that they're providing those services, that could be devastating to the rest of our organization. So when we're talking about supply chains, we're talking about the vendors and suppliers and cloud providers that are providing services for us.

Cloud Service Models

There are many different types of cloud providers that are out there. One example would be if you have a Gmail account, or maybe some sort of web mail up in the cloud, then that is what's known as a software as a service, or SaaS. You really don't have to worry about managing hardly anything. It is really just your inbox that you're managing. The rest is all managed up in the cloud. And so that's considered software as a service.

But there are other models as well. There is the model where we have something that's on premise. Of course, that's not in the cloud. In that model right there, we're in charge of everything.

There are also other models in between those. One example is infrastructure as a service. Infrastructure as a service is that they take care of all of the infrastructure, but then you take care of all the virtual machines on top of that. So in this case right here, they are in charge of the data center, networking, storage, servers, all the virtualization, and then on top of that you would turn up a virtual machine, but from you it would just be like a regular machine that you're logging into. Then you would install all the applications and install everything on it to run as if you wanted to run it as if it was installed on your equipment, but it's running on somebody else's infrastructure.

You also have things like platform as a service, which is in between a software as a service and infrastructure as a service. This is an example where they pretty much manage most of it, but there are a few things that you need to manage, like the application and the data behind it. A good example of this is maybe some sort of web hosting where they don't provide just a plug-and-play where you create your web page, but maybe it's somewhere where you're not actually managing the machine itself. It's somewhere in between, where they provide the services but you turn up maybe WordPress on there, or maybe some sort of web instance on there, and you manage the back end of that.

So there are variations of this when it comes to cloud services and how you manage it. Of course, there's also hybrids as well, where we have hybrids in between these or using multiple. For instance, maybe we have some on-premise equipment but also some things like in an infrastructure as a service, and they do some collaborating, they do some communicating, they do some replication, they use some services. So that way we have both on premise and in the cloud. And so there's these hybrid models as well.

Shared Responsibility

Why this is important from a security perspective is that many times there's a shared responsibility when it comes to security. You don't have a lot of control with some of these models of the back-end systems, so you're relying on the other provider in order to make sure that they do security correctly. So there's this shared responsibility when it comes to security. In fact, this is called the shared responsibility model. And depending on which one you're choosing, there's going to be a variation of responsibilities and where those responsibilities fall into who's responsible for it.

So what an attacker is going to do is they're going to look for their attack vector to get into the organization, and all those attack vectors combined makes the attack surface of the different ways they could get in. We talked about some of those common attack vectors, and we categorized them into physical, digital, and human. And then we also talked about the supply chain, because we could have different vendors out there supplying different aspects that could be categorized in the physical, digital, or human as creating some sort of vulnerabilities for us. So it's one of those things that we need to make sure we keep in mind as we're analyzing our vendors and choosing our vendors.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →