← Back to home

Free Resources

Free knowledge

90+ free cybersecurity infographics for the entire community. No forms to download. Just shared knowledge.

Sort

98 of 98 resources

Browser Fingerprinting
🕵️Methodologies, Attack Anatomy

Browser Fingerprinting

How websites identify users using browser fingerprinting techniques.

#Privacy#Tracking#Fingerprinting
Active Directory Attack
🔓Attack Anatomy, Attack Types

Active Directory Attack

Full anatomy of an attack against Active Directory environments, from reconnaissance to exfiltration.

#Kerberos#AD#RedTeam
Adversary-in-the-Middle Attack
🎭Attack Anatomy, Attack Types

Adversary-in-the-Middle Attack

How attackers intercept sessions and credentials using AITM attacks.

#AITM#SessionHijacking
API Attack
Attack Anatomy, Web Attacks, Attack Types

API Attack

Common attack vectors targeting modern APIs and REST services.

#OWASPAPI#REST
Web Application Attack
🌐Attack Anatomy, Web Attacks, Attack Types

Web Application Attack

Anatomy of common attacks against modern web applications.

#OWASP#WebSecurity
APT Attack
🎯Attack Anatomy, Attack Types

APT Attack

How advanced persistent threats operate inside organizations.

#APT#CyberThreat#NationState
BOLA Attack
Attack Anatomy, Web Attacks, Attack Types

BOLA Attack

How attackers exploit Broken Object Level Authorization vulnerabilities in APIs.

#OWASPAPI#BOLA#Authorization
Kubernetes Attack
Attack Anatomy, Attack Types

Kubernetes Attack

Threats and attack vectors against Kubernetes containers and clusters.

#Kubernetes#Containers#Cloud
Cloud Infrastructure Attack
☁️Attack Anatomy, Attack Types

Cloud Infrastructure Attack

Common attack vectors against AWS, Azure and GCP infrastructure.

#AWS#Azure#Cloud
IoT Attack
📡Attack Anatomy, Attack Types

IoT Attack

How attackers compromise IoT devices and exploit connected networks.

#IoT#Embedded#Botnets
Obfuscated JavaScript Attack
Attack Anatomy, Attack Types

Obfuscated JavaScript Attack

Evasion and concealment techniques using obfuscated JavaScript.

#JavaScript#Malware#Obfuscation
JWT Attack
Attack Anatomy

JWT Attack

How attackers exploit JSON Web Token vulnerabilities to escalate privileges.

#OWASP#API#JWT
Reverse Proxy Phishing Attack
🎭Attack Anatomy, Attack Types, phishing

Reverse Proxy Phishing Attack

How attackers use reverse proxies to capture credentials and MFA sessions.

#Phishing#ReverseProxy#MFA
Supply Chain Attack
📦Attack Anatomy, Attack Types

Supply Chain Attack

How attackers compromise vendors, libraries and CI/CD pipelines to distribute malware.

#SupplyChain#CI/CD#DevSecOps
Anatomy of a CVE
🪲Attack Anatomy

Anatomy of a CVE

How CVE vulnerabilities are discovered, registered and exploited.

#CVE#Vulnerabilities#Exploit
Microservices Attack
Attack Anatomy, Attack Types

Microservices Attack

Common attack vectors against microservices-based architectures.

#Microservices#API#Cloud
EDR/XDR Bypass
Attack Types

EDR/XDR Bypass

Techniques used to evade modern EDR and XDR solutions.

#EDR#XDR#Evasion
Command and Control Attack
🖥Attack Types

Command and Control Attack

How C2 channels used by malware and threat actors operate.

#C2#Malware#Botnet
MFA Fatigue Attack
Attack Types

MFA Fatigue Attack

How attackers abuse MFA notifications to trick users into granting access.

#MFA#Identity#PushBombing
Social Engineering Attack
🧠Attack Types

Social Engineering Attack

Psychological manipulation techniques used to gain unauthorized access.

#SocialEngineering#HumanHacking#Phishing
Password Cracking
🔑Attack Types

Password Cracking

Methods used to crack passwords using brute force, dictionaries and hybrid attacks.

#Passwords#BruteForce#Hashcat
Phishing Through Fraudulent Domains
🌐Attack Types

Phishing Through Fraudulent Domains

How attackers use fake domains to impersonate brands and steal credentials.

#Phishing#Domains#Typosquatting
Phishing Attack
🎣Attack Types

Phishing Attack

How phishing attacks work and the most common techniques used to deceive users.

#Phishing#CredentialTheft#EmailSecurity
Prompt Injection
🤖Attack Types, AI & Emerging

Prompt Injection

How attackers manipulate prompts to alter the behavior of AI-based systems.

#AISecurity#LLM#PromptInjection
BGP Hijacking Attack
🌍Network Attacks, Attack Types

BGP Hijacking Attack

How attackers manipulate BGP routes to redirect or intercept internet traffic.

#BGP#Routing#NetworkSecurity
NTP Amplification DDoS
Network Attacks, Attack Types

NTP Amplification DDoS

How DDoS attacks using amplification through NTP servers work.

#DDoS#NTP#Amplification
Reflection Amplification DDoS
🔁Network Attacks, Attack Types

Reflection Amplification DDoS

DDoS attacks based on reflection and amplification using exposed services.

#DDoS#Reflection#Amplification
Botnet DDoS Attack
🕸️Network Attacks, Attack Types

Botnet DDoS Attack

How botnets are used to perform distributed denial-of-service attacks.

#Botnet#DDoS#Malware
HTTP Flood DDoS Attack
🌐Network Attacks, Attack Types

HTTP Flood DDoS Attack

How DDoS attacks targeting applications and HTTP servers work.

#HTTPFlood#Layer7#DDoS
DNS Flood DDoS Attack
📡network, Attack Types, ddos

DNS Flood DDoS Attack

How attackers overwhelm DNS services using flood-based attacks.

#DNS#DDoS#Flood
Memcached DDoS Attack
💥Network Attacks, Attack Types

Memcached DDoS Attack

DDoS amplification attacks using exposed Memcached servers.

#Memcached#Amplification#DDoS
Slowloris Attack
🐢Network Attacks, Attack Types

Slowloris Attack

How Slowloris exhausts HTTP connections by keeping them open as long as possible.

#Slowloris#HTTP#DDoS
SSDP Amplification Attack
Network Attacks, Attack Types

SSDP Amplification Attack

How attackers use UPnP/SSDP devices to amplify DDoS traffic.

#SSDP#UPnP#Amplification
TCP SYN Flood Attack
Network Attacks, Attack Types

TCP SYN Flood Attack

How SYN Flood attacks exhaust resources by overwhelming TCP connections.

#TCP#SYNFlood#DDoS
Volumetric DDoS Attack
🌐Network Attacks, Attack Types

Volumetric DDoS Attack

DDoS attacks designed to saturate bandwidth and network capacity.

#Volumetric#Bandwidth#DDoS
DNS Cache Poisoning Attack
Network Attacks, Attack Types

DNS Cache Poisoning Attack

How attackers manipulate DNS responses to redirect users to malicious websites.

#DNS#Poisoning#Spoofing
Evil Twin Attack
Network Attacks, Attack Types

Evil Twin Attack

How attackers create fake WiFi hotspots to intercept traffic and credentials.

#WiFi#EvilTwin#MITM
MAC Flooding Attack
🖧Network Attacks, Attack Types

MAC Flooding Attack

How attackers overflow switch CAM tables to capture network traffic.

#Switching#LAN#MACFlooding
Man-in-the-Middle Attack
🎭network attacks , Attack Types

Man-in-the-Middle Attack

How attackers intercept and manipulate communications between two parties.

#MITM#Interception#Network
Sniffing Attack
👂Network Attacks, Attack Types

Sniffing Attack

How attackers capture and analyze network traffic to obtain sensitive information.

#Sniffing#Packets#TrafficAnalysis
Signs of a Phishing Email
🚨Attack Types

Signs of a Phishing Email

Common indicators used to identify phishing emails.

#Phishing#EmailSecurity#Awareness
MFA Synchronization Attack
Attack Types

MFA Synchronization Attack

How attackers exploit MFA synchronization mechanisms to gain unauthorized access.

#MFA#Identity#Authentication
Watering Hole Attack
🕳️Attack Types

Watering Hole Attack

How attackers compromise websites frequented by targets to distribute malware.

#WateringHole#Compromise
Cross-Site Scripting (XSS)
💉Web Attacks, Attack Types

Cross-Site Scripting (XSS)

How attackers inject malicious scripts into vulnerable web applications.

#XSS#JavaScript#OWASP
Reflected XSS Attack
🪞Web Attacks, Attack Types

Reflected XSS Attack

How reflected Cross-Site Scripting works and its most common vectors.

#ReflectedXSS#OWASP#Injection
Drive-By Attack
Web Attacks, Attack Types

Drive-By Attack

How compromised websites automatically infect users upon visiting them.

#Drive-By#BrowserExploit#WebSecurity
HTTP Request Smuggling
Web Attacks, Attack Types

HTTP Request Smuggling

How HTTP inconsistencies allow attackers to manipulate proxies and backend servers.

#HTTP#Smuggling#OWASP
IDOR Attack
Web Attacks, Attack Types

IDOR Attack

How attackers exploit insecure direct object references in web applications.

#IDOR#OWASP#Authorization
SQL Injection Attack
Web Attacks, Attack Types

SQL Injection Attack

How attackers inject malicious SQL queries to compromise databases.

#SQLInjection#Databases#OWASP
Access Token Manipulation
🎟️Web Attacks, Attack Types

Access Token Manipulation

How attackers manipulate access tokens to escalate privileges or impersonate users.

#OAuth#Tokens#Authentication
Server-Side Request Forgery
Web Attacks, Attack Types

Server-Side Request Forgery

How attackers force servers to make malicious internal or external requests.

#SSRF#Cloud#OWASP
Subdomain Takeover Attack
Web Attacks, Attack Types

Subdomain Takeover Attack

How misconfigured subdomains can be hijacked by attackers.

#SubdomainTakeover#DNS#WebSecurity
 Real-Time Payment Systems BRE-B
💳AI & Emerging

Real-Time Payment Systems BRE-B

How real-time payment systems work and the associated security risks.

#Fintech#Payments#Banking
Blue Team
🔵Red/Blue/Purple

Blue Team

Roles and responsibilities of Blue Team cybersecurity professionals.

#BlueTeam#SOC#Defense
Purple Team
🟣Red/Blue/Purple

Purple Team

How Purple Teams integrate offensive and defensive cybersecurity capabilities.

#PurpleTeam#Collaboration#SecurityTesting
Red Team
🔴Red/Blue/Purple

Red Team

Functions and methodologies used by Red Teams to simulate real-world attacks.

#RedTeam#Pentesting#OffensiveSecurity
Fake Online Shopping Fraud
🛒Fraud

Fake Online Shopping Fraud

How online shopping frauds operate through fake stores and deceptive offers.

#Fraud#E-commerce#Scams
Family Emergency Scam
📞Fraud

Family Emergency Scam

How scammers manipulate victims by pretending to be in family emergencies.

#Fraud#Scam#SocialEngineering
Wangiri Scam
☎️Fraud

Wangiri Scam

How fraudulent missed-call scams known as Wangiri operate.

#Wangiri#PhoneScam#Fraud
Fast Loan App Fraud
💸Fraud

Fast Loan App Fraud

How fraudulent quick-loan apps extort users and steal personal information.

#Fraud#MobileApps#Scam
AI-Powered Cybercrime
🤖AI & Emerging, Attack Types, Fraud

AI-Powered Cybercrime

How cybercriminals use artificial intelligence to automate attacks and fraud.

#AI#Cybercrime#Automation
Model Context Protocol (MCP)
🧠AI & Emerging

Model Context Protocol (MCP)

What MCP is and how it enables AI models to integrate with external tools and systems.

#AI#MCP#LLM
AI Systems
🧠AI & Emerging

AI Systems

Architecture and operation of modern artificial intelligence systems.

#AI#MachineLearning#LLM
Fileless Malware
👻Malware & Endpoints

Fileless Malware

How fileless malware operates in memory to evade traditional detection mechanisms.

#Fileless#Malware#Evasion
Computer Worms
🪱Malware & Endpoints

Computer Worms

How worms automatically spread across networks and vulnerable systems.

#Worm#Propagation#Malware
Living Off The Land
🛠️Malware & Endpoints

Living Off The Land

How attackers use legitimate system tools to avoid detection.

#LOTL#Evasion#Windows
Ransomware
💰Malware & Endpoints

Ransomware

How ransomware attacks operate through encryption and extortion phases.

#Ransomware#Extortion#Encryption
Rootkit
🕳️Malware & Endpoints

Rootkit

How rootkits hide malicious processes and maintain persistence on compromised systems.

#Rootkit#Persistence#Kernel
Spyware
🕵️Malware & Endpoints

Spyware

How spyware collects sensitive information and monitors user activity.

#Spyware#Surveillance#Privacy
Trojan
🐴Malware & Endpoints

Trojan

How trojans trick users into installing malicious software disguised as legitimate.

#Trojan#Malware#SocialEngineering
Macro Virus
📄Malware & Endpoints

Macro Virus

How Office documents with malicious macros are used to distribute malware.

#Macros#Office#Malware
Computer Virus
🦠Malware & Endpoints

Computer Virus

How computer viruses operate and spread across systems.

#Virus#Malware#Propagation
Malware Analysis
🔬Methodologies, Malware & Endpoints

Malware Analysis

Methodologies and techniques used to analyze malware samples.

#MalwareAnalysis#ReverseEngineering#ThreatIntelligence
Wireshark Traffic Analysis
🦈Methodologies, Network Attacks

Wireshark Traffic Analysis

How to use Wireshark to capture and analyze network traffic.

#Wireshark#Packets#TrafficAnalysis
Network Traffic Analysis
📡Methodologies, Network Attacks

Network Traffic Analysis

How to analyze network traffic to detect threats and anomalies.

#TrafficAnalysis#NetworkMonitoring#Detection
Brute Force Attack
🔨Methodologies, Attack Types

Brute Force Attack

How brute force attacks against credentials and systems operate.

#BruteForce#Passwords#Authentication
Bug Bounty Hunting
🐞Methodologies, Attack Types

Bug Bounty Hunting

Methodologies used to find vulnerabilities in Bug Bounty programs.

#BugBounty#Hacking#Vulnerabilities
Exploitation Cycle
♻️Methodologies, Attack Types

Exploitation Cycle

Common phases attackers use to compromise systems and maintain access.

#Exploitation#KillChain#Attacks
MITRE ATT&CK
🎯Methodologies

MITRE ATT&CK

MITRE ATT&CK framework for classifying adversary tactics and techniques.

#MITRE#ATT&CK#ThreatIntelligence
Incident Triage
🚑Methodologies

Incident Triage

How to prioritize and classify security incidents effectively.

#IncidentResponse#SOC#Triage
DevSecOps Process
⚙️Methodologies, Process

DevSecOps Process

How to integrate security into CI/CD pipelines and DevOps processes.

#DevSecOps#CI/CD#ShiftLeft
Google Dorking
🔎Methodologies

Google Dorking

How to use advanced search operators for OSINT investigations.

#GoogleDorking#OSINT#Reconnaissance
Digital Forensics
Methodologies

Digital Forensics

Methodologies used to collect and analyze digital evidence.

#Forensics#IncidentResponse#Evidence
OSINT
🕵️Methodologies

OSINT

How to gather intelligence using open-source intelligence techniques.

#OSINT#Recon#Intelligence
Pentesting
🧑‍💻Methodologies

Pentesting

Methodologies and phases used in offensive penetration testing.

#Pentesting#RedTeam#OffensiveSecurity
Linux Privilege Escalation
🐧Methodologies, Attack Types

Linux Privilege Escalation

How attackers escalate privileges on Linux systems using insecure configurations and vulnerabilities.

#Linux#PrivilegeEscalation#PostExploitation
Firewall Rule Management
🔥Process

Firewall Rule Management

Process for securely managing, auditing, and optimizing firewall rules.

#Firewall#NetworkSecurity#Governance
Incident Response
🚨Process

Incident Response

Phases and procedures used to respond to cybersecurity incidents.

#IncidentResponse#SOC#Containment
Threat Hunting
🎯Process

Threat Hunting

How analysts proactively search for advanced threats inside organizations.

#ThreatHunting#Detection#SOC
Continuous Zero Trust Verification
🔐Process

Continuous Zero Trust Verification

How Zero Trust continuously validates identities, devices, and access.

#ZeroTrust#Identity#AccessControl
Almost Impossible Password
🔑Digital Security

Almost Impossible Password

Best practices for creating strong passwords resistant to attacks.

#Passwords#Authentication#SecurityAwareness
DKIM
📧Digital Security

DKIM

How DKIM protects emails using cryptographic signatures.

#DKIM#EmailSecurity#Authentication
DMARC
🛡️Digital Security

DMARC

How DMARC helps prevent email spoofing and phishing.

#DMARC#Phishing#EmailSecurity
SPF
✉️Digital Security

SPF

How SPF validates authorized email sending servers.

#SPF#EmailSecurity#DNS
Multi-Factor Authentication
🔐Digital Security

Multi-Factor Authentication

How MFA strengthens authentication using multiple verification factors.

#MFA#Authentication#Identity
SSO and SAML
🔑Digital Security

SSO and SAML

How SSO and SAML work to centralize authentication and access management.

#SSO#SAML#Identity
VPN
🌐Digital Security

VPN

How VPNs protect communications and privacy over public networks.

#VPN#Privacy#Encryption
Firewall Evasion Methodology
Methodologies

Firewall Evasion Methodology

Methodologies and techniques used to evade firewall controls and network restrictions.

#Firewall#Evasion#NetworkSecurity

Newsletter

Get new infographics every month

We send one email per month with new infographics and cybersecurity trends. No spam, unsubscribe anytime.

Want to learn more?

Visit our academy for specialized cybersecurity training.

Go to AcademyRead the Blog

Need help with your cybersecurity? 💬