skip to content

Threats, Attacks & Defense Concepts

The shared vocabulary of attacks and defense: classic attack classes, malware families, social engineering, and the ATT&CK/kill-chain frameworks used to reason about them. Security interviewers use this area the way generalist loops use system design — to test whether you can name, classify, and counter what an adversary actually does.

on this pageshow

explore

questions

301 · 7 sections

A flaw requires a valid account to exploit. Why is that not a reason to call it low risk?

level: juniorimportance: must knowfreq 62%
basics
~10 s

A precondition says where in an intrusion a flaw becomes usable, not how hard the attack is. Accounts are widely held and cheap to obtain, so "authenticated only" excludes almost no adversary.

open as a page

Why can a missing server-side permission check be attacked with no exploit code at all?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Because the attack is an ordinary, well-formed request. If the server never checks who owns the record, any account holder simply asks for someone else's identifier and is served it. Nothing is malformed, so nothing needs exploiting.

open as a page

A public proof of concept for a vulnerability only crashes the service - what has changed about your exposure?

level: juniorimportance: must knowfreq 78%
basics
~20 s

A crash proves the flaw is reachable, not that anyone can control your system. Vulnerability, working exploit and packaged tooling are three separate states with three separate dates, and only the last two widen who can attack you.

open as a page

What does calling a vulnerability a 'zero-day' actually assert about it?

level: juniorimportance: must knowfreq 76%
basics
~20 s

Zero-day is a patch state, not a quality grade. It asserts only that no vendor fix existed at the moment the flaw was used. It says nothing about the bug's elegance, the attacker's skill, or whether the attack was unstoppable.

open as a page

What does a published CVE record assert about a product, and what does it never assert?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A CVE record says a named authority described one flaw and listed the product versions it believes affected, under a permanent identifier. It never asserts exploitability where you run it, real-world attack, vendor agreement, or that a fix exists.

open as a page

On a flat office VLAN, why does becoming a host's gateway need no account or exploit?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Nothing authenticates the answers. A host takes its gateway and resolver from whichever lease answer arrives first, and locates that gateway from whoever replies for its address. Adjacency to the segment is the only prerequisite: no credential, no software flaw.

open as a page

In an IP packet, what does the source address field actually prove about the sender?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Nothing on its own. The source address is chosen by whoever builds the packet, and nothing along the path verifies it, because routers forward on the destination. It proves a value was written, not who wrote it.

open as a page

Why can't an off-path attacker just send a forged DNS reply to a recursive resolver?

level: juniorimportance: must knowfreq 64%
basics
~20 s

The resolver only accepts a reply that matches its outstanding query: same server address and port, same ephemeral port it asked from, same 16-bit message ID, same question. And it must arrive before the genuine answer.

open as a page

What is a dangling DNS record, and how does it hand your subdomain to a stranger?

level: juniorimportance: must knowfreq 55%
basics
~20 s

A dangling DNS record still resolves to a target that is no longer yours: a released storage bucket, app slot or cancelled vendor tenant. Whoever re-registers that target name is then served under your subdomain.

open as a page

What does the amplification factor measure in a reflection attack, and how do you compute it?

level: juniorimportance: must knowfreq 65%
basics
~20 s

The amplification factor is the ratio of response bytes reaching the victim to request bytes the attacker spent. A 62-byte request drawing a 3,000-byte answer runs at roughly 48x, so a small uplink delivers a large flood.

open as a page

What separates horizontal from vertical privilege movement, and what does neither measure?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Vertical movement acquires rights an identity lacks; horizontal movement takes over a peer identity holding different rights. Both describe the route, not the damage. A sideways step onto an identity that already owns production ends the intrusion.

open as a page

Why can an operator with a domain admin credential run code on another host over the ADMIN$ share or WMI with no exploit?

level: juniorimportance: must knowfreq 70%
basics
~20 s

The administrative share and WMI are built-in remote-administration channels. They authenticate with the credential and run if the account has admin rights on the target, so no vulnerability is needed — the credential itself is the key.

open as a page

In Active Directory, why can any authenticated account read group memberships and permissions?

level: juniorimportance: must knowfreq 65%
basics
~10 s

Active Directory is a shared authorisation database, and Authenticated Users can read most attributes by default: memberships, owners, permission entries, service principal names. Any valid account can map who controls whom without touching anything.

open as a page

What separates credential stuffing from password spraying, and what does each operator already know?

level: juniorimportance: must knowfreq 78%
basics
~10 s

Stuffing replays real username-and-password pairs stolen from other sites and bets on reuse. Spraying knows no password at all: it tries one likely guess, such as Autumn2026!, against every account in a directory.

open as a page

With every user MFA-enrolled, how can one valid password still open a mailbox?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Enrolment is counted per user; enforcement is a property of each authentication path. A legacy mail protocol endpoint using basic authentication has no step in which a factor can be demanded, so the password alone succeeds there while the browser sign-in still challenges.

open as a page

Why does an implant pick HTTPS to a permitted destination over a hard-coded IP on a custom port?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Because the path already exists. In a fully proxied estate an arbitrary address on an odd port has no route outward at all, while port 443 to a destination the organisation already permits needs no new opening and looks like ordinary browsing.

open as a page

What does calling malware 'fileless' actually claim about it, and what does it not claim?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Fileless claims only that the code which ran was never a normal executable file launched from disk; it arrived as data and became code in memory. It does not claim that nothing was written to disk.

open as a page

Why does an operator already running as a user inject into that user's browser instead of opening its own connection?

level: juniorimportance: must knowfreq 70%
basics
~20 s

The operator's own process has no business reaching the internet, and its traffic carries no user identity. Running inside the user's browser borrows that person's session, proxy settings and usual destinations, so the outbound traffic looks like their ordinary browsing rather than a strange new program phoning out.

open as a page

Why does an operator run their payload through a signed Windows system binary rather than dropping an EXE?

level: juniorimportance: must knowfreq 78%
basics
~20 s

Because the binary already carries the vendor's trust and is already installed. Nothing attacker-authored arrives as an executable, no install rights are needed, and the run collides with the administration the estate performs every day.

open as a page

Does installing a rootkit give an adversary the privilege level it hides at?

level: juniorimportance: must knowfreq 68%
basics
~20 s

No. A rootkit conceals activity at a level the adversary already controls. Loading a kernel driver or writing firmware needs administrative privilege first, so concealment is something an intrusion buys after it has won, never a route to winning.

open as a page

Why does an OAuth consent grant to a mailbox survive the user's password reset?

level: juniorimportance: must knowfreq 60%
basics
~20 s

A consent grant is an authorization the user gave to an application, not a credential the user holds. It is a separate record with its own refresh token, so rotating the password changes nothing the application depends on.

open as a page

What does a credential harvest page actually hand its operator, and what kills that product?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Only the strings the victim typed, usually an account name and a password. The genuine site never saw the attempt, so nothing confirms the password is correct, and it stops being worth anything the moment the victim changes it.

open as a page

A supplier emails new bank details for a real, unpaid invoice - what attack is this and why doesn't patching help?

level: juniorimportance: must knowfreq 72%
basics
~10 s

Payment diversion: the operator changes where a genuine, already-owed payment lands. No link, attachment or malware appears anywhere in the chain, so patching, attachment scanning and endpoint controls have nothing to act on.

open as a page

An SMS lure carries only a phone number — which anti-phishing controls still apply?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Almost none. SPF, DKIM, DMARC and attachment detonation all live on the mail hop, and an SMS-plus-callback lure never crosses it. What survives is account-side: the identity controls, and whatever the service desk demands before it acts.

open as a page

In a watering-hole attack, how does the attacker target a specific group without sending anything?

level: juniorimportance: must knowfreq 66%
basics
~20 s

A watering hole works by poisoning a site only the target group reads, so the readership performs the selection. No message is sent, no recipient is ever chosen, and no mail path exists anywhere on the route.

open as a page

Why does ATT&CK number ICS techniques T0### instead of extending the Enterprise T1### range?

level: juniorimportance: must knowfreq 55%
basics
~20 s

Because ICS is a separate matrix, not a branch of Enterprise. It has its own tactic columns and its own technique list, so its identifiers live in their own space and never nest under an Enterprise number.

open as a page

In MITRE ATT&CK, what does a tactic column name, and why does one technique sit in several?

level: juniorimportance: must knowfreq 74%
basics
~20 s

A tactic names the adversary's goal for an action, not the action. The same technique can serve several goals, so ATT&CK lists it under every tactic it achieves: T1078 Valid Accounts sits in four columns.

open as a page

In MITRE ATT&CK, what does a T#### identifier name, and why does an observed command line have none?

level: juniorimportance: must knowfreq 65%
basics
~20 s

A T#### identifier names a technique, a class of adversary behaviour, and T####.### a sub-technique of it. The exact command line you saw is a procedure: one implementation of that class, and ATT&CK gives procedures no identifier at all.

open as a page

Are MITRE ATT&CK's tactic columns an ordered sequence an intrusion moves through?

level: juniorimportance: must knowfreq 72%
basics
~20 s

No. ATT&CK's tactic columns are goal categories, not stages. An intrusion can re-enter one column repeatedly, never touch several of them, and hit them in any order. The Cyber Kill Chain is the model that asserts order; ATT&CK's columns do not.

open as a page

With non-executable memory enabled, why can a memory-corruption bug still hand an attacker execution?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Non-executable memory only stops injected bytes from running. It does not stop hijacked control flow, so the attacker reuses code already mapped in the process - library functions and instruction fragments that are already executable and already legitimate jump targets.

open as a page

Why is the protocol an attacker used usually a convenience rather than a precondition?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A precondition is something the technique cannot run without. A protocol is normally one of several interchangeable routes to the same thing, so blocking it moves the operator to another route instead of ending the technique.

open as a page

In defense in depth, what makes two controls count as two layers rather than one?

level: juniorimportance: must knowfreq 58%
basics
~20 s

Two controls are two layers only if getting past them means satisfying two independent preconditions. If both are satisfied by the same fact, such as one approved job identity, whatever supplies that fact clears both at once.

open as a page

What is the difference between disabling SMBv1 with a policy setting and uninstalling the feature?

level: juniorimportance: must knowfreq 65%
basics
~20 s

Disabling writes a configuration value while the SMBv1 code stays installed, so one administrative write turns it back on. Uninstalling removes the component itself, so there is nothing to re-enable until someone installs software again.

open as a page

What does an application-control rule naming a path, publisher or hash actually evaluate?

level: juniorimportance: must knowfreq 62%
basics
~20 s

It evaluates the identity of a file at the moment something tries to load and run it: where the file sits, who signed it, or its exact bytes. It says nothing about what an already-permitted program is later handed.

open as a page