Knowledge Base

Threat Encyclopedia

99 researched entries covering vulnerabilities, attack techniques, malware, tools and glossary terms — written so you can understand a finding, not just see a red flag.

Entries
99
Threat guides
70
Attack flows
7
Categories
5

How to read an entry

  1. 1

    Start with the summary

    The card and severity badge tell you what it is and how badly it ends when it lands.

  2. 2

    Follow the attack steps

    Each entry walks the chain in order — foothold, escalation, objective — so you can see where you sit.

  3. 3

    Work the fix list

    The green checklist is ordered: complete it top to bottom and the exposure is closed.

Malware Critical

Ransomware

Files are encrypted and payment is demanded for the key, usually in cryptocurrency.

Read entry →
Malware Critical

Remote Access Trojan (RAT)

Gives an attacker an interactive shell, desktop view and file transfer on the victim machine.

Read entry →
Malware Critical

Rootkit

Hides its presence by subverting the operating system itself, often below user space.

Read entry →
Vulnerability Medium

Security Misconfiguration

Default credentials, verbose errors, open cloud buckets and unnecessary services widen the attack surface.

Read entry →
Vulnerability High

Sensitive Data Exposure

Passwords, keys or personal records travel unencrypted or sit in readable backups and logs.

Read entry →
Vulnerability Critical

Server-Side Request Forgery (SSRF)

The server is made to fetch a URL of the attacker's choosing, reaching internal services and cloud metadata.

Read entry →
Attack Technique High

Session Hijacking

A live session token is stolen or predicted, giving the attacker the victim's logged-in identity.

Read entry →
Famous Malware Critical

SolarWinds SUNBURST

A 2020 supply-chain compromise that inserted a backdoor into a trusted software update.

Read entry →
Attack Technique High

Spear Phishing

A researched, personalised message targets one specific person inside an organisation.

Read entry →
Malware High

Spyware

Covertly records location, messages, calls and browsing while appearing to be a normal app.

Read entry →
Vulnerability Critical

SQL Injection

User input is concatenated into a database query, letting an attacker read, modify or delete data.

Read entry →
Tool Info

sqlmap

Automates detection and exploitation of SQL injection, including database dumping.

Read entry →

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used