Cybersecurity
Threats and attacks
Knowing how attacks work is a defender's reference library, not an attacker's hobby. Malware families, phishing lures, social engineering scripts and ransomware playbooks change their wrapping every season while the underlying moves repeat, and a defender who recognises a move early can stop it cheaply. This topic catalogues those moves roughly in the order an intrusion tends to use them.
Why this topic exists: The second-largest Security+ domain (Threats, Vulnerabilities and Mitigations, 22 %; only Security Operations weighs more): malware, phishing, social engineering, ransomware and the attack techniques defenders must recognise.
A catalogue of moves, not a list of villains
This part of the field studies how intrusions really unfold so that defenders can spot them early. The subject is broad but patterned. An attacker needs a way in, a way to stay, a way to reach what they want and a way to profit, and most techniques serve one of those needs. Learning the patterns matters more than memorising malware family names, which change constantly while the underlying behaviour barely moves. The NICE Workforce Framework turns this knowledge into jobs: threat analysis and insider threat analysis are named work roles in its Protection and Defense category.
- Getting in. Phishing by email, text or voice, stolen or guessed passwords, default credentials, open service ports, unsupported software and compromised suppliers.
- Persuading people. Social engineering that impersonates a manager, a supplier or IT support, including business email compromise, and leans on urgency to cut thinking short.
- Staying and spreading. Malware that survives a reboot, accounts created quietly, and movement from the first machine towards the servers that hold credentials.
- Taking or holding hostage. Data copied out, and ransomware that encrypts systems and demands payment, sometimes paired with a threat to publish what was taken.
- Attacking the application. Injection, cross-site scripting and similar flaws, covered from the builder's side in application security.
How the exams frame it, and the beginner's trap
CompTIA weights Threats, Vulnerabilities and Mitigations at 22 per cent of the SY0-701 blueprint, second only to Security Operations, so nobody passes Security+ without this material. The domain moves in a sensible order: who attacks and why, the vectors and attack surfaces they use, the classes of weakness, the indicators that give an attack away, and the mitigations that answer it. Those indicators are worth learning early, because they are what defenders actually see: an account locked out without explanation, two sessions from places no traveller could reach in the time, logs that stop without a reason. CySA+ moves the subject into analysis, asking what a piece of threat intelligence means for a particular organisation. The CEH examines the same techniques from the attacker's side, which suits people heading for penetration testing. Threat modelling is the design-time use of all this knowledge: asking which of these moves a new system invites before it is built.
The trap for newcomers is fascination with sophistication. Nation-state tooling fills the headlines, yet the ordinary moves in the list above are the ones a typical team meets week after week, and they are where early recognition pays off. A defender who knows the plain techniques thoroughly, and knows how each one shows up in their own logs, stops more than one who can describe exotic malware in detail. From here, incident response covers what to do once a move is spotted, vulnerability management closes the openings attackers look for, and security awareness speaks to the people those lures are aimed at.
Next to this topic
- Security fundamentalsEvery blueprint opens here: the CIA triad, control types and the threat, vulnerability and risk vocabulary (SY0-701 General Security Concepts, 12 %; CISSP domain 1).
- Network securityFirewalls, segmentation, IDS/IPS, VPNs and zero trust are where most defensive work starts (CISSP Communication and Network Security, 13 %; Network+ and CCNA security domains).
- Identity and access managementWho may do what is its own discipline with its own exam (SC-300) and a full CISSP domain (13 %): authentication, MFA, SSO, directories and least privilege.
- CryptographyEncryption, hashing, keys and PKI underlie every other topic; the exams test them as applied choices, not maths (CISSP Security Architecture and Engineering; SY0-701 domain 1).
- Security operationsMonitoring, detection and the SOC are the largest Security+ domain (28 %) and the whole of SC-200 and CySA+: SIEM, logging, alert triage, threat hunting.
- Penetration testing and ethical hackingAuthorised attack as a profession: scoping, reconnaissance, exploitation, reporting (PTES; PenTest+ and CEH). Also the most-searched security topic on the course side.
- Governance, risk and compliancePolicies, risk assessment, frameworks (NIST CSF, ISO 27001) and audit are the management half of the field: CISSP domain 1 (16 %), CISM, CISA, Security+ Program Management (20 %).
- Application securityA large share of breaches begins in software: secure design, secure build, security testing and the OWASP Top 10 (OWASP SAMM; CISSP Software Development Security, 10 %).
- Cloud securityShared responsibility, cloud identity and posture management are tested in every cloud exam (SAA-C03 Design Secure Architectures, 30 %) and in SC-900; the cloud silo owns the platforms, this topic owns the defence.
- Security awareness for everyoneMost incidents start with a person, not a port: what every employee and freelancer must know about phishing, passwords, MFA, backups and updates (NICE Oversight and Governance; the management side of every blueprint).
Concepts to know
Glossary entries with the reason each one matters here.
- Phishing
The most common initial access technique.
- Ransomware
The attack with the highest business impact per incident.
- Threat Modelling
Thinking like the attacker, before the attacker does.
Certifications that test it
Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.
Frequently asked
- Is it legal to learn attack techniques?
- Studying them is legal and expected of defenders. Using them against systems you do not own, or have no written permission to test, is not, in most jurisdictions. Practise in your own lab or on platforms built for the purpose.
- What separates a threat, a vulnerability and a risk?
- A threat is a source of possible harm, such as a criminal group or a careless insider; a vulnerability is a weakness it could exploit, and a risk combines the two with the likely impact on your organisation. A weakness no threat can reach carries little risk; a modest weakness on an exposed system can carry a great deal.
- Which attack should a beginner study first?
- Phishing, because it opens so many intrusions and because its variations teach social engineering, credential theft and malware delivery in one place.
Courses in the directory
39 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.
Last reviewed 26 September 2026 · Getting Digital
