Threats, Attacks & Defense Concepts
The shared vocabulary of attacks and defense: classic attack classes, malware families, social engineering, and the ATT&CK/kill-chain frameworks used to reason about them. Security interviewers use this area the way generalist loops use system design — to test whether you can name, classify, and counter what an adversary actually does.
on this pageshowhide
explore
- Core Concepts and Threat Actors36 questions
- Naming a Flaw8 questions
- From Flaw to Weapon16 questions
- Who Runs the Attack12 questions
- Network and Protocol Attacks44 questions
- Claimed Names and Addresses20 questions
- Riding an Established Session12 questions
- Paying for Unproven Requests12 questions
- Identity and Credential Attacks50 questions
- The First Way In13 questions
- Collecting Reusable Secrets12 questions
- Authenticating as Someone Else13 questions
- From One Account Outward12 questions
- Malware Families and Behavior58 questions
- Spreading and Staging8 questions
- Getting Code to Run17 questions
- Staying Resident and Reachable8 questions
- Endgame of Quiet Access25 questions
- Social Engineering38 questions
- ATT&CK, Kill Chain and TTPs43 questions
- Narrating with a Model16 questions
- Inside the Technique Catalogue17 questions
- What the Models Buy10 questions
- Defense in Depth and Hardening32 questions
- Matching Control to Technique11 questions
- Taking the Option Away13 questions
- Removal on Paper8 questions
questions
301 · 7 sectionsA flaw requires a valid account to exploit. Why is that not a reason to call it low risk?
basics
~10 sA precondition says where in an intrusion a flaw becomes usable, not how hard the attack is. Accounts are widely held and cheap to obtain, so "authenticated only" excludes almost no adversary.
Why can a missing server-side permission check be attacked with no exploit code at all?
basics
~20 sBecause the attack is an ordinary, well-formed request. If the server never checks who owns the record, any account holder simply asks for someone else's identifier and is served it. Nothing is malformed, so nothing needs exploiting.
A public proof of concept for a vulnerability only crashes the service - what has changed about your exposure?
basics
~20 sA crash proves the flaw is reachable, not that anyone can control your system. Vulnerability, working exploit and packaged tooling are three separate states with three separate dates, and only the last two widen who can attack you.
What does calling a vulnerability a 'zero-day' actually assert about it?
basics
~20 sZero-day is a patch state, not a quality grade. It asserts only that no vendor fix existed at the moment the flaw was used. It says nothing about the bug's elegance, the attacker's skill, or whether the attack was unstoppable.
What does a published CVE record assert about a product, and what does it never assert?
basics
~20 sA CVE record says a named authority described one flaw and listed the product versions it believes affected, under a permanent identifier. It never asserts exploitability where you run it, real-world attack, vendor agreement, or that a fix exists.
On a flat office VLAN, why does becoming a host's gateway need no account or exploit?
basics
~20 sNothing authenticates the answers. A host takes its gateway and resolver from whichever lease answer arrives first, and locates that gateway from whoever replies for its address. Adjacency to the segment is the only prerequisite: no credential, no software flaw.
In an IP packet, what does the source address field actually prove about the sender?
basics
~20 sNothing on its own. The source address is chosen by whoever builds the packet, and nothing along the path verifies it, because routers forward on the destination. It proves a value was written, not who wrote it.
Why can't an off-path attacker just send a forged DNS reply to a recursive resolver?
basics
~20 sThe resolver only accepts a reply that matches its outstanding query: same server address and port, same ephemeral port it asked from, same 16-bit message ID, same question. And it must arrive before the genuine answer.
What is a dangling DNS record, and how does it hand your subdomain to a stranger?
basics
~20 sA dangling DNS record still resolves to a target that is no longer yours: a released storage bucket, app slot or cancelled vendor tenant. Whoever re-registers that target name is then served under your subdomain.
What does the amplification factor measure in a reflection attack, and how do you compute it?
basics
~20 sThe amplification factor is the ratio of response bytes reaching the victim to request bytes the attacker spent. A 62-byte request drawing a 3,000-byte answer runs at roughly 48x, so a small uplink delivers a large flood.
What separates horizontal from vertical privilege movement, and what does neither measure?
basics
~20 sVertical movement acquires rights an identity lacks; horizontal movement takes over a peer identity holding different rights. Both describe the route, not the damage. A sideways step onto an identity that already owns production ends the intrusion.
Why can an operator with a domain admin credential run code on another host over the ADMIN$ share or WMI with no exploit?
basics
~20 sThe administrative share and WMI are built-in remote-administration channels. They authenticate with the credential and run if the account has admin rights on the target, so no vulnerability is needed — the credential itself is the key.
In Active Directory, why can any authenticated account read group memberships and permissions?
basics
~10 sActive Directory is a shared authorisation database, and Authenticated Users can read most attributes by default: memberships, owners, permission entries, service principal names. Any valid account can map who controls whom without touching anything.
What separates credential stuffing from password spraying, and what does each operator already know?
basics
~10 sStuffing replays real username-and-password pairs stolen from other sites and bets on reuse. Spraying knows no password at all: it tries one likely guess, such as Autumn2026!, against every account in a directory.
With every user MFA-enrolled, how can one valid password still open a mailbox?
basics
~20 sEnrolment is counted per user; enforcement is a property of each authentication path. A legacy mail protocol endpoint using basic authentication has no step in which a factor can be demanded, so the password alone succeeds there while the browser sign-in still challenges.
Why does an implant pick HTTPS to a permitted destination over a hard-coded IP on a custom port?
basics
~20 sBecause the path already exists. In a fully proxied estate an arbitrary address on an odd port has no route outward at all, while port 443 to a destination the organisation already permits needs no new opening and looks like ordinary browsing.
What does calling malware 'fileless' actually claim about it, and what does it not claim?
basics
~20 sFileless claims only that the code which ran was never a normal executable file launched from disk; it arrived as data and became code in memory. It does not claim that nothing was written to disk.
Why does an operator already running as a user inject into that user's browser instead of opening its own connection?
basics
~20 sThe operator's own process has no business reaching the internet, and its traffic carries no user identity. Running inside the user's browser borrows that person's session, proxy settings and usual destinations, so the outbound traffic looks like their ordinary browsing rather than a strange new program phoning out.
Why does an operator run their payload through a signed Windows system binary rather than dropping an EXE?
basics
~20 sBecause the binary already carries the vendor's trust and is already installed. Nothing attacker-authored arrives as an executable, no install rights are needed, and the run collides with the administration the estate performs every day.
Does installing a rootkit give an adversary the privilege level it hides at?
basics
~20 sNo. A rootkit conceals activity at a level the adversary already controls. Loading a kernel driver or writing firmware needs administrative privilege first, so concealment is something an intrusion buys after it has won, never a route to winning.
Why does ATT&CK number ICS techniques T0### instead of extending the Enterprise T1### range?
basics
~20 sBecause ICS is a separate matrix, not a branch of Enterprise. It has its own tactic columns and its own technique list, so its identifiers live in their own space and never nest under an Enterprise number.
In MITRE ATT&CK, what does a tactic column name, and why does one technique sit in several?
basics
~20 sA tactic names the adversary's goal for an action, not the action. The same technique can serve several goals, so ATT&CK lists it under every tactic it achieves: T1078 Valid Accounts sits in four columns.
In MITRE ATT&CK, what does a T#### identifier name, and why does an observed command line have none?
basics
~20 sA T#### identifier names a technique, a class of adversary behaviour, and T####.### a sub-technique of it. The exact command line you saw is a procedure: one implementation of that class, and ATT&CK gives procedures no identifier at all.
Are MITRE ATT&CK's tactic columns an ordered sequence an intrusion moves through?
basics
~20 sNo. ATT&CK's tactic columns are goal categories, not stages. An intrusion can re-enter one column repeatedly, never touch several of them, and hit them in any order. The Cyber Kill Chain is the model that asserts order; ATT&CK's columns do not.
What does the Cyber Kill Chain's break-one-link claim actually assert?
basics
~20 sThat an intrusion succeeds only if it completes all seven stages in order, so removing any one stage defeats the whole attempt. It inverts the usual asymmetry: the intruder must win every link, not just one.
With non-executable memory enabled, why can a memory-corruption bug still hand an attacker execution?
basics
~20 sNon-executable memory only stops injected bytes from running. It does not stop hijacked control flow, so the attacker reuses code already mapped in the process - library functions and instruction fragments that are already executable and already legitimate jump targets.
Why is the protocol an attacker used usually a convenience rather than a precondition?
basics
~20 sA precondition is something the technique cannot run without. A protocol is normally one of several interchangeable routes to the same thing, so blocking it moves the operator to another route instead of ending the technique.
What is the difference between disabling SMBv1 with a policy setting and uninstalling the feature?
basics
~20 sDisabling writes a configuration value while the SMBv1 code stays installed, so one administrative write turns it back on. Uninstalling removes the component itself, so there is nothing to re-enable until someone installs software again.
What does an application-control rule naming a path, publisher or hash actually evaluate?
basics
~20 sIt evaluates the identity of a file at the moment something tries to load and run it: where the file sits, who signed it, or its exact bytes. It says nothing about what an already-permitted program is later handed.