Knowledge Base
Threat Encyclopedia
99 researched entries covering vulnerabilities, attack techniques, malware, tools and glossary terms — written so you can understand a finding, not just see a red flag.
- Entries
- 99
- Threat guides
- 70
- Attack flows
- 7
- Categories
- 5
How to read an entry
-
1
Start with the summary
The card and severity badge tell you what it is and how badly it ends when it lands.
-
2
Follow the attack steps
Each entry walks the chain in order — foothold, escalation, objective — so you can see where you sit.
-
3
Work the fix list
The green checklist is ordered: complete it top to bottom and the exposure is closed.
Apple Multiple Products Out-of-Bounds Write Vulnerability
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
Read entry →Banking Malware
Intercepts online banking sessions and adds fake fields to steal credentials and transfer funds.
Read entry →Botnet Client
An infected machine that takes orders from a command-and-control server and joins a wider swarm.
Read entry →Broken Access Control
Users can reach records, routes or functions that belong to someone else.
Read entry →Browser Hijacker
Rewrites the homepage, search engine and new-tab behaviour, then tracks everything typed.
Read entry →Brute Force
Every candidate password is tried systematically until one works.
Read entry →Burp Suite
Intercepting proxy for testing web applications, with repeater, intruder and scanner modules.
Read entry →Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
Read entry →Citrix NetScaler Improper Input Validation Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
Read entry →Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service
Read entry →Cobalt Strike
A legitimate penetration-testing tool that became the most common post-exploitation framework in crime.
Read entry →Command Injection
Shell metacharacters in user input reach an OS command, giving direct code execution.
Read entry →Attack Flows
Step-by-step chains showing how individual weaknesses connect into a full breach.
-
API Abuse Chain
- An API is discovered whose endpoints are documented in a public JavaScript bundle.
- A GraphQL introspection query or a verbose error message reveals the full schema.
- Object-level authorization is tested by substituting another user's identifier in the request.
8 steps
View the full chain → -
Credential Stuffing Campaign
- A breach dump from an unrelated service is obtained, containing hundreds of millions of pairs.
- Known-invalid entries are filtered out so only plausible credentials remain.
- Those pairs are sprayed against the target login endpoint at low volume to evade rate limits.
8 steps
View the full chain → -
Exposed Endpoint to Web Shell
- An exposed admin endpoint or file-upload feature is discovered during enumeration.
- Weak validation is tested and found to accept a file with a server-side extension.
- The uploaded file is requested directly, returning execution output and confirming code execution.
8 steps
View the full chain → -
Man-in-the-Middle Session Theft
- The attacker joins the same wireless network as the target, or poisons the local gateway.
- Unencrypted traffic is observed, revealing which sites the victim visits without TLS.
- SSL stripping is applied to downgrade the first visit from HTTPS to HTTP.
8 steps
View the full chain → -
Phishing to Ransomware
- A spear-phishing email arrives referencing a real invoice, with a link to a convincing document portal.
- The victim enters their password on the look-alike page, handing over a valid credential.
- The credential is replayed against VPN or webmail that has no MFA, giving the attacker a legitimate foothold.
8 steps
View the full chain → -
SQL Injection to Full Breach
- Reconnaissance finds a search page that echoes a URL parameter back into the response.
- A single quote produces a database error, confirming that input reaches the query unparameterised.
- Boolean-based probing determines the injection point and the backend DBMS flavour.
8 steps
View the full chain → -
Supply Chain Compromise
- The attacker identifies a widely trusted software vendor with a large customer base.
- Access to the vendor's build environment or update server is obtained, often via a phishing email.
- The build process is modified so the injected code runs during normal compilation.
8 steps
View the full chain →