ATTACK / DEFENSE LAB // 38 ATTACK PROFILES

Understand the attack. Build the defense.

Every attack is presented separately with its layer, mechanism, indicators, prevention controls, a visual attack-flow diagram, and an administrator-managed defense-tool slot. Tool packages remain visible to everyone; premium packages can only be downloaded or opened by entitled users.

◉ 7→1 OSI layers◉ Detection indicators◉ Prevention controls◉ Defense tool: Build Soon / Available
OSI 7

Layer 7 – Application Layer

10 attacks
L7PREMIUM TOOL

Brute-Force Attack

A brute-force attack repeatedly guesses credentials or secrets until a valid value is found.

IndicatorsHigh failed-login rates, repeated attempts against one or many accounts, distributed source addresses, lockouts, and successful logins following bursts of failures.DefenseUse MFA, rate limiting, progressive delays, account protection, password policies, breached-password screening, bot detection, and centralized authentication monitoring.
Open full attack profile →
L7PREMIUM TOOL

Command Injection

Command injection occurs when application input is incorporated into an operating-system command in a way that lets data alter command execution.

IndicatorsUnexpected child processes, shell interpreters spawned by web services, unusual command-line arguments, abnormal process trees, and access to unexpected files or network destinations.DefenseAvoid shell invocation when possible, use fixed APIs and argument arrays, strict allow-lists, least privilege, sandboxing, EDR monitoring, and application isolation.
Open full attack profile →
L7PREMIUM TOOL

Credential Stuffing

Credential stuffing uses previously exposed username/password pairs against other services, relying on password reuse.

IndicatorsMany accounts targeted from distributed sources, login success after a low number of attempts per account, impossible-travel patterns, and authentication attempts using known breached passwords.DefenseRequire MFA, block known compromised passwords, use bot/risk-based controls, rate-limit authentication, monitor impossible travel, and encourage unique passwords with password managers.
Open full attack profile →
L7PREMIUM TOOL

Cross-Site Request Forgery (CSRF)

CSRF tricks an authenticated browser into sending an unwanted state-changing request to a site where the victim is already signed in.

IndicatorsUnexpected state changes, requests lacking valid CSRF tokens, unusual Origin/Referer values, and state-changing endpoints that accept cross-site requests are useful signals.DefenseUse anti-CSRF tokens, SameSite cookies, Origin/Referer validation where appropriate, re-authentication for sensitive actions, and avoid unsafe state changes through GET.
Open full attack profile →
L7PREMIUM TOOL

Cross-Site Scripting (XSS)

XSS is a client-side injection weakness in which attacker-controlled content is interpreted as active script in another user’s browser context.

IndicatorsCSP violations, unexpected script execution, modified DOM behavior, suspicious inline scripts, reflected parameters, and reports of altered page behavior can be indicators.DefenseUse contextual output encoding, safe templating, framework auto-escaping, strict Content Security Policy, input validation, secure cookie flags, and DOM-safe APIs.
Open full attack profile →
L7PREMIUM TOOL

Directory Traversal

Directory traversal is unauthorized access to files outside an application’s intended directory by manipulating path input.

IndicatorsRepeated path-normalization failures, requests containing suspicious path patterns, access to configuration files, and unexpected file-read errors.DefenseCanonicalize paths, use allow-listed file identifiers instead of raw paths, enforce filesystem permissions, isolate application data, and monitor file access.
Open full attack profile →
L7PREMIUM TOOL

DNS Attacks

DNS attacks abuse naming infrastructure to redirect traffic, exhaust resources, poison caches, or hide malicious infrastructure.

IndicatorsUnexpected resolver destinations, high NXDOMAIN rates, unusual record changes, long or high-entropy subdomains, abnormal query volume, and suspicious newly registered domains.DefenseUse validated DNSSEC where appropriate, secure resolver configuration, response-rate controls, logging, threat intelligence, egress monitoring, and segmentation of recursive resolvers.
Open full attack profile →
L7PREMIUM TOOL

HTTP Flood / Web DDoS

An HTTP flood is an application-layer denial-of-service pattern that overwhelms web resources with large volumes of seemingly valid requests.

IndicatorsSudden request-rate changes, endpoint concentration, high application latency, cache misses, elevated CPU/database load, and traffic patterns that differ from the normal client population.DefenseUse CDN/WAF protection, caching, rate limits, bot management, autoscaling, request budgets, circuit breakers, and capacity planning.
Open full attack profile →
L7PREMIUM TOOL

Phishing

Phishing is a social-engineering attack that uses deceptive messages or pages to make a person reveal information, execute an action, or deliver an attacker-controlled payload.

IndicatorsWatch for unusual sender domains, look-alike addresses, unexpected login pages, shortened or mismatched URLs, new inbox rules, impossible-travel sign-ins, suspicious OAuth consent, and reports from users.DefenseUse phishing-resistant MFA where possible, secure email gateways, SPF/DKIM/DMARC, URL and attachment analysis, user reporting, domain protection, browser isolation, and rapid credential/session revocation.
Open full attack profile →
L7PREMIUM TOOL

SQL Injection (SQLi)

SQL injection occurs when untrusted input changes the meaning of a database query instead of being treated strictly as data.

IndicatorsLook for database errors, unusual query patterns, repeated malformed requests, unexpected data access, abnormal response sizes, and application logs showing rejected or anomalous parameters.DefenseUse parameterized queries/prepared statements, safe ORM patterns, allow-list validation, least-privileged database accounts, secrets protection, WAF rules, and security testing in authorized environments.
Open full attack profile →
OSI 6

Layer 6 – Presentation Layer

4 attacks
L6PREMIUM TOOL

Certificate Attacks

Certificate attacks involve misuse, theft, spoofing, or validation failures around digital certificates and trust chains.

IndicatorsUnexpected certificate issuers, hostname mismatches, new certificates for sensitive domains, expired chains, and changes in certificate transparency records.DefenseProtect private keys, use managed certificate lifecycles, validate chains and hostnames, monitor certificate transparency, and remove obsolete trust anchors.
Open full attack profile →
L6PREMIUM TOOL

Encoding-Based Filter Evasion

Encoding-based filter evasion changes the representation of input so that a weak filter misses content that is later decoded by the application.

IndicatorsRequests that decode differently across layers, repeated normalization failures, double-encoding patterns, and WAF/application disagreement.DefenseNormalize before validation, validate after canonicalization, use context-aware parsing, and keep security controls aligned with application decoding behavior.
Open full attack profile →
L6PREMIUM TOOL

SSL/TLS Downgrade Attack

A TLS downgrade attack attempts to force a connection to use an older or weaker protocol or cipher so that protections are reduced.

IndicatorsConnections negotiating obsolete protocol versions or weak cipher suites, unexpected TLS alerts, handshake anomalies, and policy violations in TLS telemetry.DefenseDisable obsolete protocols/ciphers, enable modern TLS versions, use HSTS where appropriate, monitor TLS configuration, and keep cryptographic libraries patched.
Open full attack profile →
L6PREMIUM TOOL

Weak Encryption Attacks

Weak-encryption attacks exploit obsolete algorithms, short keys, poor randomness, or insecure protocol configurations.

IndicatorsUse of deprecated ciphers, short keys, legacy protocols, repeated nonce/IV issues, or cryptographic policy violations.DefenseAdopt modern standards, disable legacy algorithms, use strong key management, rotate secrets, and continuously audit cryptographic configuration.
Open full attack profile →
OSI 5

Layer 5 – Session Layer

3 attacks
OSI 4

Layer 4 – Transport Layer

5 attacks
L4PREMIUM TOOL

Connection Exhaustion

Connection exhaustion consumes server resources by creating more concurrent transport/application connections than the service can handle.

IndicatorsConnection counts near limits, long-lived incomplete sessions, queue saturation, and rising latency without proportional bandwidth growth.DefenseSet connection limits and timeouts, use reverse proxies, rate limits, load balancing, and resource isolation.
Open full attack profile →
L4PREMIUM TOOL

Port Scanning

Port scanning probes services to discover which network ports are reachable and what responses they produce.

IndicatorsMany destination ports or hosts from one source, short connection bursts, sequential port patterns, and repeated probes to closed services.DefenseMinimize exposed services, use firewalls, segment networks, monitor flow logs, and investigate scans in context.
Open full attack profile →
L4PREMIUM TOOL

TCP Reset Injection

TCP reset injection attempts to disrupt a connection by causing endpoints to accept forged or unauthorized TCP RST packets.

IndicatorsUnexpected RST spikes, repeated resets from an unexpected path, interrupted long-lived sessions, and sequence-number anomalies.DefenseUse authenticated/encrypted protocols, network path protection, monitoring, and modern transport/security mechanisms where appropriate.
Open full attack profile →
L4PREMIUM TOOL

TCP SYN Flood

A SYN flood exhausts connection-handling resources by creating many TCP connection attempts that do not complete normally.

IndicatorsHigh SYN rates, high SYN-to-established ratios, backlog pressure, retransmission anomalies, and service latency.DefenseUse SYN cookies, backlog tuning, upstream DDoS protection, rate controls, and network telemetry.
Open full attack profile →
L4PREMIUM TOOL

UDP Flood

A UDP flood overwhelms network, host, or application resources with large volumes of UDP traffic.

IndicatorsUnusual UDP packet rates, bandwidth saturation, spikes to closed ports, and elevated CPU or interrupt load.DefenseUse upstream filtering, rate limiting, ACLs, DDoS protection, service exposure minimization, and traffic baselines.
Open full attack profile →
OSI 3

Layer 3 – Network Layer

5 attacks
L3PREMIUM TOOL

ICMP Flood

An ICMP flood sends excessive ICMP traffic that consumes bandwidth or processing resources.

IndicatorsICMP packet-rate spikes, bandwidth consumption, elevated device CPU, and changes in echo request/reply ratios.DefenseRate-limit ICMP where appropriate, filter unnecessary traffic, use upstream DDoS controls, and maintain baseline telemetry.
Open full attack profile →
L3PREMIUM TOOL

IP Fragmentation Attacks

IP fragmentation attacks exploit how fragmented packets are reassembled, filtered, or processed to evade controls or exhaust resources.

IndicatorsMalformed fragments, overlapping offsets, unusual fragment rates, reassembly failures, and IDS/firewall discrepancies.DefenseNormalize or drop malformed fragments, patch network devices, tune inspection systems, and monitor fragmentation anomalies.
Open full attack profile →
L3PREMIUM TOOL

IP Spoofing

IP spoofing forges the source IP address of packets so that traffic appears to originate from another address.

IndicatorsTraffic with impossible source networks, internal addresses arriving from external interfaces, asymmetric routing anomalies, and inconsistent flow behavior.DefenseUse ingress/egress filtering, anti-spoofing ACLs, authenticated protocols, and network segmentation.
Open full attack profile →
L3PREMIUM TOOL

Routing Attacks

Routing attacks manipulate or abuse routing information to redirect, blackhole, or intercept traffic.

IndicatorsUnexpected route changes, new peers, prefix changes, route flaps, and traffic taking an abnormal path.DefenseAuthenticate routing sessions, filter prefixes, use route validation where available, segment routing domains, and monitor route changes.
Open full attack profile →
L3PREMIUM TOOL

Smurf Attack

A Smurf attack historically used spoofed ICMP requests directed at broadcast networks so many hosts replied to the victim.

IndicatorsUnexpected ICMP amplification, broadcast traffic anomalies, and replies concentrated on one victim address.DefenseDisable directed broadcasts, apply anti-spoofing controls, segment networks, and rate-limit broadcast/ICMP traffic.
Open full attack profile →
OSI 2

Layer 2 – Data Link Layer

6 attacks
L2PREMIUM TOOL

ARP Spoofing / ARP Poisoning

ARP spoofing sends misleading IP-to-MAC mappings on a local network so traffic can be redirected or intercepted.

IndicatorsFrequent ARP changes, duplicate IP/MAC mappings, gateway MAC changes, and unexpected ARP replies.DefenseUse DHCP snooping, Dynamic ARP Inspection, static bindings where practical, segmentation, secure management, and endpoint monitoring.
Open full attack profile →
L2PREMIUM TOOL

DHCP Starvation

DHCP starvation exhausts available addresses in a DHCP scope by causing the server to see many apparently unique clients.

IndicatorsRapid lease allocation, many short-lived client identifiers, scope exhaustion, and sudden DHCP request volume.DefenseUse DHCP snooping, port security, rate limits, appropriately sized scopes, and monitoring of lease churn.
Open full attack profile →
L2PREMIUM TOOL

MAC Flooding

MAC flooding attempts to overflow a switch’s MAC address table so forwarding behavior becomes less selective.

IndicatorsRapid growth in learned MAC addresses, table exhaustion alerts, unusual source-MAC churn, and increased unknown-unicast traffic.DefenseEnable port security, limit learned MAC addresses, segment networks, use storm controls, and monitor switch telemetry.
Open full attack profile →
L2PREMIUM TOOL

Rogue DHCP Server

A rogue DHCP server provides unauthorized network configuration, potentially directing clients to malicious gateways or DNS resolvers.

IndicatorsDHCP offers from unexpected ports, inconsistent gateway/DNS values, multiple DHCP responders, and sudden client configuration changes.DefenseEnable DHCP snooping/trusted ports, segment networks, monitor DHCP traffic, and investigate unexpected responders.
Open full attack profile →
L2PREMIUM TOOL

VLAN Hopping

VLAN hopping abuses trunk/access-port configuration or negotiation behavior to reach traffic in another VLAN.

IndicatorsUnexpected trunk formation, access ports carrying tagged traffic, native VLAN anomalies, and cross-VLAN traffic where it should not exist.DefenseDisable unnecessary trunk negotiation, explicitly configure trunks, avoid native VLAN exposure, use VLAN ACLs, and segment management traffic.
Open full attack profile →
L2PREMIUM TOOL

Wireless Deauthentication

Wireless deauthentication abuse forces clients to leave an access point by sending management frames that appear to terminate sessions.

IndicatorsBursts of deauthentication/disassociation frames, repeated reconnects, channel-specific spikes, and client roaming anomalies.DefenseEnable PMF where supported, use modern Wi-Fi security, monitor wireless IDS telemetry, and investigate abnormal management-frame rates.
Open full attack profile →
OSI 1

Layer 1 – Physical Layer

5 attacks
L1PREMIUM TOOL

Cable Tapping

Cable tapping is unauthorized physical access to a network or communications cable to observe or alter signals.

IndicatorsUnexpected physical access, cable-route changes, new inline hardware, optical anomalies, or unexplained link behavior.DefenseRestrict cable routes, lock cabinets, use tamper controls, protect conduits, inventory infrastructure, and encrypt sensitive traffic end-to-end.
Open full attack profile →
L1PREMIUM TOOL

Device Theft

Device theft removes a computer, network device, storage medium, or mobile endpoint from authorized custody.

IndicatorsMissing asset records, unexpected device check-in failures, last-seen telemetry without physical confirmation, and loss of network presence.DefenseUse full-disk encryption, asset tracking, secure storage, remote management, device lockout, and rapid credential/session revocation.
Open full attack profile →
L1PREMIUM TOOL

Hardware Tampering

Hardware tampering changes, adds, or removes physical components to alter behavior or capture information.

IndicatorsUnexpected hardware inventory changes, firmware differences, new USB/network devices, tamper alerts, or configuration drift.DefenseUse asset inventory, tamper-evident controls, secure boot, signed firmware, restricted access, and integrity monitoring.
Open full attack profile →
L1PREMIUM TOOL

Physical Port Access

Physical port access occurs when an unauthorized person connects equipment to an exposed Ethernet, console, USB, or other interface.

IndicatorsNew switch MAC addresses, link-up events at unused ports, console access logs, USB device events, and unexpected endpoint changes.DefenseDisable unused ports, lock equipment rooms, use port security/NAC, protect console ports, and monitor device connections.
Open full attack profile →
L1PREMIUM TOOL

Signal Jamming

Signal jamming deliberately interferes with a wireless or radio signal to reduce or deny availability.

IndicatorsSudden signal-to-noise degradation, retransmission spikes, channel-wide packet loss, and geographic/channel-specific interference.DefenseUse spectrum monitoring, resilient channel planning, wired fallback paths, redundancy, physical controls, and incident response procedures.
Open full attack profile →
PREMIUM FILE VISIBILITY POLICY

Everyone can see the resource. Only entitled users can download.

Premium access · ₹149