Objectives can include stealing or exposing information, altering data, disrupting availability, abusing computing resources, or producing physical or operational effects through digitally enabled functions.
An attack does not have to succeed. Understanding one requires evidence about the actor’s actions, target, methods, intent, access, and effects, while clearly separating confirmed facts from analytic judgments and unresolved possibilities.
Key points
Common pathsAttackers may exploit software flaws, abuse valid credentials, deceive people, misuse exposed services, compromise suppliers, introduce malicious code, or act through authorized insider access.
Outcome descriptionRecord attempted and successful actions, affected assets, persistence, data access or change, service and safety effects, and the confidence and evidence supporting each conclusion.
Evidence-based responsePreserve relevant records, contain unsafe access, remove attacker persistence, correct exploited conditions, restore trustworthy operation, monitor for recurrence, and update defenses from lessons learned.
Important limitationAn alert, vulnerability, outage, or unusual event does not by itself establish a cyberattack. Attribution, malicious intent, initial access, and impact may remain uncertain, and different operational or legal frameworks define attack and incident differently.