Definition · External Attack Surface Management

What is Attack Vector?

An attack vector is the route in. Where the attack surface is the total set of points an attacker could interact with, a vector is one concrete way of getting from outside to inside — a particular service on a particular host, or a particular person’s inbox.

Common external attack vectors

  • Exposed services reachable on open ports, including management protocols never meant to face the internet
  • Vulnerable web applications and their APIs
  • Exposed admin panels and login interfaces
  • Email, used for phishing and business email compromise
  • Valid credentials, obtained by credential stuffing, phishing, or left at their defaults
  • Third parties and supply chain, where the vector is someone else’s system that has access to yours

Vector versus vulnerability versus exploit

These are often conflated. The vulnerability is the flaw, the exploit is the technique that abuses it, and the vector is the channel over which it arrives. CVSS captures this distinction in its own Attack Vector metric, whose values — network, adjacent network, local, and physical — describe how remote an attacker can be.

Why enumerating vectors matters

Controls map to vectors, not to threats in the abstract. Listing the ways into your estate is what makes it possible to say which of them are monitored, which are authenticated, and which exist only because someone forgot to decommission a host. Vectors you have not enumerated are the ones nobody is watching.

Attack vectors are what a threat actor looks for during reconnaissance, and mapping them from the outside in is the purpose of external attack surface management.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.