Threat Vectors


A threat vector is a specific path by which a threat actor gains unauthorized access to a system or perform an attack.

  • can use multiple threat vectors
  • can develop novel threat vectors

Threat Vector vs. Attack Vector

  • The terms threat vector and attack vector are often taken to mean the same thing
    • Some distinguish
      • threat vector to refer to analysis of the potential attack surface
      • attack vector to analyze an exploit that has been successfully executed

Types of Threat Vectors