Understand the attack. Build the defense.
Every attack is presented separately with its layer, mechanism, indicators, prevention controls, a visual attack-flow diagram, and an administrator-managed defense-tool slot. Tool packages remain visible to everyone; premium packages can only be downloaded or opened by entitled users.
Layer 7 – Application Layer
Brute-Force Attack
A brute-force attack repeatedly guesses credentials or secrets until a valid value is found.
Command Injection
Command injection occurs when application input is incorporated into an operating-system command in a way that lets data alter command execution.
Credential Stuffing
Credential stuffing uses previously exposed username/password pairs against other services, relying on password reuse.
Cross-Site Request Forgery (CSRF)
CSRF tricks an authenticated browser into sending an unwanted state-changing request to a site where the victim is already signed in.
Cross-Site Scripting (XSS)
XSS is a client-side injection weakness in which attacker-controlled content is interpreted as active script in another user’s browser context.
Directory Traversal
Directory traversal is unauthorized access to files outside an application’s intended directory by manipulating path input.
DNS Attacks
DNS attacks abuse naming infrastructure to redirect traffic, exhaust resources, poison caches, or hide malicious infrastructure.
HTTP Flood / Web DDoS
An HTTP flood is an application-layer denial-of-service pattern that overwhelms web resources with large volumes of seemingly valid requests.
Phishing
Phishing is a social-engineering attack that uses deceptive messages or pages to make a person reveal information, execute an action, or deliver an attacker-controlled payload.
SQL Injection (SQLi)
SQL injection occurs when untrusted input changes the meaning of a database query instead of being treated strictly as data.
Layer 6 – Presentation Layer
Certificate Attacks
Certificate attacks involve misuse, theft, spoofing, or validation failures around digital certificates and trust chains.
Encoding-Based Filter Evasion
Encoding-based filter evasion changes the representation of input so that a weak filter misses content that is later decoded by the application.
SSL/TLS Downgrade Attack
A TLS downgrade attack attempts to force a connection to use an older or weaker protocol or cipher so that protections are reduced.
Weak Encryption Attacks
Weak-encryption attacks exploit obsolete algorithms, short keys, poor randomness, or insecure protocol configurations.
Layer 5 – Session Layer
Replay Attack
A replay attack reuses a previously captured valid message, token, or transaction in a context where freshness should have been required.
Session Fixation
Session fixation occurs when an attacker causes a victim to authenticate using a session identifier that the attacker already knows.
Session Hijacking
Session hijacking is unauthorized use of a valid session identifier or token to impersonate the authenticated user.
Layer 4 – Transport Layer
Connection Exhaustion
Connection exhaustion consumes server resources by creating more concurrent transport/application connections than the service can handle.
Port Scanning
Port scanning probes services to discover which network ports are reachable and what responses they produce.
TCP Reset Injection
TCP reset injection attempts to disrupt a connection by causing endpoints to accept forged or unauthorized TCP RST packets.
TCP SYN Flood
A SYN flood exhausts connection-handling resources by creating many TCP connection attempts that do not complete normally.
UDP Flood
A UDP flood overwhelms network, host, or application resources with large volumes of UDP traffic.
Layer 3 – Network Layer
ICMP Flood
An ICMP flood sends excessive ICMP traffic that consumes bandwidth or processing resources.
IP Fragmentation Attacks
IP fragmentation attacks exploit how fragmented packets are reassembled, filtered, or processed to evade controls or exhaust resources.
IP Spoofing
IP spoofing forges the source IP address of packets so that traffic appears to originate from another address.
Routing Attacks
Routing attacks manipulate or abuse routing information to redirect, blackhole, or intercept traffic.
Smurf Attack
A Smurf attack historically used spoofed ICMP requests directed at broadcast networks so many hosts replied to the victim.
Layer 2 – Data Link Layer
ARP Spoofing / ARP Poisoning
ARP spoofing sends misleading IP-to-MAC mappings on a local network so traffic can be redirected or intercepted.
DHCP Starvation
DHCP starvation exhausts available addresses in a DHCP scope by causing the server to see many apparently unique clients.
MAC Flooding
MAC flooding attempts to overflow a switch’s MAC address table so forwarding behavior becomes less selective.
Rogue DHCP Server
A rogue DHCP server provides unauthorized network configuration, potentially directing clients to malicious gateways or DNS resolvers.
VLAN Hopping
VLAN hopping abuses trunk/access-port configuration or negotiation behavior to reach traffic in another VLAN.
Wireless Deauthentication
Wireless deauthentication abuse forces clients to leave an access point by sending management frames that appear to terminate sessions.
Layer 1 – Physical Layer
Cable Tapping
Cable tapping is unauthorized physical access to a network or communications cable to observe or alter signals.
Device Theft
Device theft removes a computer, network device, storage medium, or mobile endpoint from authorized custody.
Hardware Tampering
Hardware tampering changes, adds, or removes physical components to alter behavior or capture information.
Physical Port Access
Physical port access occurs when an unauthorized person connects equipment to an exposed Ethernet, console, USB, or other interface.
Signal Jamming
Signal jamming deliberately interferes with a wireless or radio signal to reduce or deny availability.