Attack Vector
An attack vector is the path or method an attacker uses to gain unauthorised access to a system or network, such as a phishing email, an exposed service, stolen credentials or a software vulnerability. Understanding an organisation’s attack vectors is fundamental to reducing its attack surface and prioritising defences.
An attack vector is the route by which an attacker reaches and compromises a target: the specific method or pathway used to gain unauthorised access. Common vectors include phishing and other social engineering, exploitation of software vulnerabilities, stolen or weak credentials, exposed and misconfigured internet-facing services, malicious email attachments, and compromised third parties in the supply chain. Every breach begins with an attacker successfully using one of these vectors.
It helps to distinguish an attack vector from the attack surface. The attack surface is the sum of all points where an attacker could attempt entry, the whole exposed perimeter of systems, services, applications and people. An attack vector is a particular route across that surface. Reducing the attack surface, by removing unnecessary exposure, therefore reduces the number of vectors available to an attacker, which is the core logic of attack surface management.
Attack vectors can be grouped by the weakness they exploit. Technical vectors exploit software flaws or misconfigurations, such as an unpatched vulnerability in an exposed service. Credential-based vectors use stolen, guessed or reused passwords to log in as a legitimate user. Human vectors, chiefly phishing and social engineering, manipulate people into granting access or running malicious content. Supply-chain vectors reach a target indirectly through a trusted vendor or software component. Real intrusions frequently combine several.
Understanding the relative importance of different vectors guides where to invest. In practice, a large share of breaches begin with just a few vectors: phishing and stolen credentials account for a substantial proportion of real-world incidents, which is why controls such as multi-factor authentication, security awareness training and credential monitoring deliver outsized returns. Knowing which vectors most threaten a specific organisation lets it prioritise defences rather than spreading effort thinly.
Attackers continually probe for the easiest available vector, so the goal of defence is not to eliminate every possible route, which is impossible, but to close the most likely and most damaging ones and to detect attempts against the rest. Reducing exposure, hardening the human layer, patching promptly and monitoring for exploitation together shrink both the number of viable vectors and the chance that any one succeeds.
Because a small number of vectors account for a large share of real breaches, notably phishing and stolen credentials, controls that address those specific routes deliver outsized returns. Multi-factor authentication blunts credential theft, security awareness training and email authentication reduce phishing success, and prompt patching closes the exploitation of known vulnerabilities. Understanding which vectors most threaten a given organisation is what turns a generic security budget into a targeted one.
Precursor identifies the attack vectors that actually threaten an organisation through penetration testing and external attack surface monitoring, and prioritises them by real-world exploitability so defensive effort goes where attackers are most likely to strike.