Skip to content
Getting Digital

Cybersecurity

Threats and attacks

Knowing how attacks work is a defender's reference library, not an attacker's hobby. Malware families, phishing lures, social engineering scripts and ransomware playbooks change their wrapping every season while the underlying moves repeat, and a defender who recognises a move early can stop it cheaply. This topic catalogues those moves roughly in the order an intrusion tends to use them.

Why this topic exists: The second-largest Security+ domain (Threats, Vulnerabilities and Mitigations, 22 %; only Security Operations weighs more): malware, phishing, social engineering, ransomware and the attack techniques defenders must recognise.

A catalogue of moves, not a list of villains

This part of the field studies how intrusions really unfold so that defenders can spot them early. The subject is broad but patterned. An attacker needs a way in, a way to stay, a way to reach what they want and a way to profit, and most techniques serve one of those needs. Learning the patterns matters more than memorising malware family names, which change constantly while the underlying behaviour barely moves. The NICE Workforce Framework turns this knowledge into jobs: threat analysis and insider threat analysis are named work roles in its Protection and Defense category.

  • Getting in. Phishing by email, text or voice, stolen or guessed passwords, default credentials, open service ports, unsupported software and compromised suppliers.
  • Persuading people. Social engineering that impersonates a manager, a supplier or IT support, including business email compromise, and leans on urgency to cut thinking short.
  • Staying and spreading. Malware that survives a reboot, accounts created quietly, and movement from the first machine towards the servers that hold credentials.
  • Taking or holding hostage. Data copied out, and ransomware that encrypts systems and demands payment, sometimes paired with a threat to publish what was taken.
  • Attacking the application. Injection, cross-site scripting and similar flaws, covered from the builder's side in application security.

How the exams frame it, and the beginner's trap

CompTIA weights Threats, Vulnerabilities and Mitigations at 22 per cent of the SY0-701 blueprint, second only to Security Operations, so nobody passes Security+ without this material. The domain moves in a sensible order: who attacks and why, the vectors and attack surfaces they use, the classes of weakness, the indicators that give an attack away, and the mitigations that answer it. Those indicators are worth learning early, because they are what defenders actually see: an account locked out without explanation, two sessions from places no traveller could reach in the time, logs that stop without a reason. CySA+ moves the subject into analysis, asking what a piece of threat intelligence means for a particular organisation. The CEH examines the same techniques from the attacker's side, which suits people heading for penetration testing. Threat modelling is the design-time use of all this knowledge: asking which of these moves a new system invites before it is built.

The trap for newcomers is fascination with sophistication. Nation-state tooling fills the headlines, yet the ordinary moves in the list above are the ones a typical team meets week after week, and they are where early recognition pays off. A defender who knows the plain techniques thoroughly, and knows how each one shows up in their own logs, stops more than one who can describe exotic malware in detail. From here, incident response covers what to do once a move is spotted, vulnerability management closes the openings attackers look for, and security awareness speaks to the people those lures are aimed at.

Next to this topic

Concepts to know

Glossary entries with the reason each one matters here.

  • Phishing

    The most common initial access technique.

  • Ransomware

    The attack with the highest business impact per incident.

  • Threat Modelling

    Thinking like the attacker, before the attacker does.

Certifications that test it

Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.

Frequently asked

Is it legal to learn attack techniques?
Studying them is legal and expected of defenders. Using them against systems you do not own, or have no written permission to test, is not, in most jurisdictions. Practise in your own lab or on platforms built for the purpose.
What separates a threat, a vulnerability and a risk?
A threat is a source of possible harm, such as a criminal group or a careless insider; a vulnerability is a weakness it could exploit, and a risk combines the two with the likely impact on your organisation. A weakness no threat can reach carries little risk; a modest weakness on an exposed system can carry a great deal.
Which attack should a beginner study first?
Phishing, because it opens so many intrusions and because its variations teach social engineering, credential theft and malware delivery in one place.

Courses in the directory

39 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.

Browse the directory shelf

Last reviewed 26 September 2026 · Getting Digital