Knowledge Base

Threat Encyclopedia

99 researched entries covering vulnerabilities, attack techniques, malware, tools and glossary terms — written so you can understand a finding, not just see a red flag.

Entries
99
Threat guides
70
Attack flows
7
Categories
5

How to read an entry

  1. 1

    Start with the summary

    The card and severity badge tell you what it is and how badly it ends when it lands.

  2. 2

    Follow the attack steps

    Each entry walks the chain in order — foothold, escalation, objective — so you can see where you sit.

  3. 3

    Work the fix list

    The green checklist is ordered: complete it top to bottom and the exposure is closed.

Attack Technique Critical

Credential Dumping

Stored or cached credentials are extracted from a host so they can be replayed elsewhere.

Read entry →
Attack Technique High

Credential Stuffing

Username and password pairs leaked from one breach are replayed against other services.

Read entry →
Vulnerability High

Cross-Site Request Forgery (CSRF)

A logged-in browser is tricked into submitting an action the user never intended.

Read entry →
Vulnerability High

Cross-Site Scripting (XSS)

Attacker-supplied script runs in another user's browser, stealing sessions and rewriting the page.

Read entry →
Malware Medium

Cryptocurrency Miner

Steals CPU and GPU cycles to mine currency for whoever deployed it.

Read entry →
Famous Malware Critical

DarkSide / Colonial Pipeline

The 2021 ransomware attack that shut 5,500 miles of US fuel pipeline for six days.

Read entry →
Vulnerability High

Directory Traversal

Path segments such as ../../ escape the intended folder and expose system files.

Read entry →
Attack Technique Medium

DNS Tunneling

Data is smuggled through DNS queries and responses, bypassing egress filters.

Read entry →
Famous Malware Critical

Emotet

A banking trojan turned modular botnet that sold access to other attackers.

Read entry →
Famous Malware Critical

Equifax Breach

A 2017 breach of 147 million records through one unpatched web framework.

Read entry →
Vulnerability High

Exposed Source Control Metadata

A reachable .git directory hands an attacker the entire repository history, including rotated secrets.

Read entry →
Vulnerability High

Exposed XML-RPC Endpoint

The WordPress xmlrpc.php endpoint is reachable, enabling brute force amplification and remote pingback abuse.

Read entry →

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used