XML

Cyber Attack Vectors - XML

Cyber attack vectors refer to the paths and methods used by attackers to infiltrate systems and networks, steal sensitive information, or disrupt operations. These are systematically classified in frameworks such as OWASP Top 10 and MITRE ATT&CK, encompassing various techniques including injection attacks, malware, phishing, DDoS, and authentication failures. Understanding these attack vectors is essential for building effective security countermeasures.

cybersecurity attack methods OWASP MITRE ATT&CK vulnerabilities information security
<?xml version="1.0" encoding="UTF-8"?>
<items>
  <item>
    <code>A01</code>
    <slug>broken-access-control</slug>
    <name>Broken Access Control</name>
    <description>Vulnerability where restrictions on authenticated users are not properly enforced.</description>
    <category>OWASP Top 10</category>
    <mitreTechnique>T1078</mitreTechnique>
  </item>
  <item>
    <code>A02</code>
    <slug>security-misconfiguration</slug>
    <name>Security Misconfiguration</name>
    <description>Security settings are defined, implemented, or maintained improperly.</description>
    <category>OWASP Top 10</category>
    <mitreTechnique>T1562</mitreTechnique>
  </item>
  <item>
    <code>A03</code>
    <slug>software-supply-chain-failures</slug>
    <name>Software Supply Chain Failures</name>
    <description>Vulnerabilities from third-party components and build processes.</description>
    <category>OWASP Top 10</category>
    <mitreTechnique>T1195</mitreTechnique>
  </item>
  <item>
    <code>A04</code>
    <slug>cryptographic-failures</slug>
    <name>Cryptographic Failures</name>
    <description>Failures related to cryptography leading to sensitive data exposure.</description>
    <category>OWASP Top 10</category>
    <mitreTechnique>T1552</mitreTechnique>
  </item>
  <item>
    <code>A05</code>
    <slug>injection</slug>
    <name>Injection</name>
    <description>Untrusted data sent to interpreters as part of commands or queries.</description>
    <category>OWASP Top 10</category>
    <mitreTechnique>T1059</mitreTechnique>
  </item>
  <item>
    <code>A06</code>
    <slug>insecure-design</slug>
    <name>Insecure Design</name>
    <description>Security issues from errors or omissions in application design and architecture.</description>
    <category>OWASP Top 10</category>
    <mitreTechnique>T1071</mitreTechnique>
  </item>
  <item>
    <code>A07</code>
    <slug>authentication-failures</slug>
    <name>Authentication Failures</name>
    <description>Identity and authentication mechanisms implemented incorrectly.</description>
    <category>OWASP Top 10</category>
    <mitreTechnique>T1078</mitreTechnique>
  </item>
  <item>
    <code>A08</code>
    <slug>software-data-integrity-failures</slug>
    <name>Software or Data Integrity Failures</name>
    <description>Code and infrastructure that fails to protect against integrity violations.</description>
    <category>OWASP Top 10</category>
    <mitreTechnique>T1554</mitreTechnique>
  </item>
  <item>
    <code>A09</code>
    <slug>logging-alerting-failures</slug>
    <name>Security Logging and Alerting Failures</name>
    <description>Insufficient logging, detection, monitoring, and incident response.</description>
    <category>OWASP Top 10</category>
    <mitreTechnique>T1562</mitreTechnique>
  </item>
  <item>
    <code>A10</code>
    <slug>mishandling-exceptional-conditions</slug>
    <name>Mishandling of Exceptional Conditions</name>
    <description>Errors, exceptions, and edge cases not handled securely.</description>
    <category>OWASP Top 10</category>
    <mitreTechnique>T1499</mitreTechnique>
  </item>
  <item>
    <code>M01</code>
    <slug>malware</slug>
    <name>Malware</name>
    <description>System compromise through malicious software.</description>
    <category>Malware</category>
    <mitreTechnique>T1055</mitreTechnique>
  </item>
  <item>
    <code>M02</code>
    <slug>ransomware</slug>
    <name>Ransomware</name>
    <description>Malware that encrypts data and demands ransom.</description>
    <category>Malware</category>
    <mitreTechnique>T1486</mitreTechnique>
  </item>
  <item>
    <code>P01</code>
    <slug>phishing</slug>
    <name>Phishing</name>
    <description>Attack using deceptive communications to steal sensitive information.</description>
    <category>Social Engineering</category>
    <mitreTechnique>T1566</mitreTechnique>
  </item>
  <item>
    <code>D01</code>
    <slug>ddos</slug>
    <name>DDoS Attack</name>
    <description>Distributed Denial of Service attack that cripples systems.</description>
    <category>Network Attack</category>
    <mitreTechnique>T1498</mitreTechnique>
  </item>
  <item>
    <code>I01</code>
    <slug>sql-injection</slug>
    <name>SQL Injection</name>
    <description>Attack that injects malicious SQL into database queries.</description>
    <category>Injection Attack</category>
    <mitreTechnique>T1190</mitreTechnique>
  </item>
  <item>
    <code>I02</code>
    <slug>xss</slug>
    <name>Cross-Site Scripting (XSS)</name>
    <description>Attack that injects malicious scripts into web applications.</description>
    <category>Injection Attack</category>
    <mitreTechnique>T1189</mitreTechnique>
  </item>
  <item>
    <code>I03</code>
    <slug>csrf</slug>
    <name>Cross-Site Request Forgery (CSRF)</name>
    <description>Attack that forces authenticated users&apos; browsers to send unintended requests.</description>
    <category>Injection Attack</category>
    <mitreTechnique>T1204</mitreTechnique>
  </item>
  <item>
    <code>N01</code>
    <slug>man-in-the-middle</slug>
    <name>Man-in-the-Middle (MitM)</name>
    <description>Attack that intercepts communications for eavesdropping or tampering.</description>
    <category>Network Attack</category>
    <mitreTechnique>T1557</mitreTechnique>
  </item>
  <item>
    <code>C01</code>
    <slug>credential-theft</slug>
    <name>Credential Theft</name>
    <description>Attack that steals passwords and authentication information.</description>
    <category>Authentication Attack</category>
    <mitreTechnique>T1555</mitreTechnique>
  </item>
  <item>
    <code>C02</code>
    <slug>privilege-escalation</slug>
    <name>Privilege Escalation</name>
    <description>Attack that escalates from low to high privileges.</description>
    <category>Authentication Attack</category>
    <mitreTechnique>T1068</mitreTechnique>
  </item>
</items>