Mastodon Mastodon Mastodon Mastodon

Attack Vector

Updated: · CyberSecureFox Editorial Team

An attack vector is the path or method an attacker uses to get into a system or network, such as a phishing email, an unpatched internet-facing service or stolen credentials.

Attack vector vs. attack surface

The attack surface is the sum of all points where an attacker could try to get in; an attack vector is one concrete route through it. A company with hundreds of exposed services, employees and suppliers has a large surface, and each of those elements offers one or more vectors.

Common attack vectors

  • Exploitation of public-facing applications – VPN gateways, firewalls, mail and file-transfer servers with known or zero-day vulnerabilities.
  • Phishing – malicious attachments, links to fake login pages, and phishing over SMS, phone or messengers.
  • Valid credentials – passwords bought from infostealer logs, reused or guessed.
  • Supply chain – compromised software updates, libraries or IT service providers, see supply chain attack.
  • Physical and removable media – USB drives, access to unlocked devices.

In MITRE ATT&CK these routes are grouped under the Initial Access tactic (TA0001). Annual breach reports such as the Verizon DBIR consistently rank stolen credentials, phishing and vulnerability exploitation as the top vectors.

Attack vector in CVSS

The CVSS metric “Attack Vector” (AV) describes how remote an attacker can be: Network, Adjacent, Local or Physical. A flaw rated AV:N can be exploited over the internet and usually gets a higher score.

How to reduce attack vectors

Patch internet-facing systems first, enforce phishing-resistant MFA, remove unused services and accounts, and vet suppliers’ access.

Synonyms:
infection vector, initial access vector