π Day 91 β Enterprise Attack Surface and Exploitation Points
π Topic
Mapping where exploitation can happen across an enterprise network.
π― Goal
Understand the major weak points attackers target and connect them to defensive responsibilities.
π What I Did
Today I extended the enterprise network model by focusing on attack surface.
The question was:
Where can exploitation happen?
The answer is almost everywhere if controls are weak.
Common exploitation points include:
- user endpoint
- browser
- email inbox
- identity provider
- VPN
- exposed remote access
- DNS
- web application
- API
- database
- cloud account
- misconfigured storage bucket
- firewall rule
- third-party integration
- backup system
- administrator workstation
- IoT device
- supply chain dependency
A simplified attack surface map:
user
β
phishing / social engineering
β
endpoint compromise
β
credential theft
β
VPN or cloud login
β
lateral movement
β
server or database access
β
data theft or impact
This helped me understand why cybersecurity has many specializations.
Different people defend different parts of the same system.
π Key Cybersecurity Connections
Attackers do not need to attack everything.
They only need one weak point that leads somewhere useful.
Examples:
- phishing targets the user
- malware targets the endpoint
- SQL injection targets the web application
- password spraying targets identity
- exposed RDP targets remote access
- misconfigured cloud storage targets data
- vulnerable VPN targets perimeter access
- weak segmentation enables lateral movement
- poor backups increase ransomware impact
A SOC analyst needs broad awareness.
Even if I am not a cloud engineer, web app tester, or network architect, I still need to understand where alerts come from and why they matter.
π Investigation Questions
- What asset was targeted?
- Was the target internet-facing?
- Was a user tricked?
- Were credentials abused?
- Was there a vulnerable service?
- Was MFA enabled?
- Did the attacker move laterally?
- Was data accessed or exfiltrated?
- Which control failed?
- Which control detected the activity?
- Which team owns the affected system?
- Is this an endpoint, identity, network, cloud, or application issue?
π¨ Detection Opportunities
Possible detection ideas:
- phishing email with suspicious link
- endpoint spawning unusual process
- browser downloading executable content
- login from impossible travel
- VPN login from rare geography
- repeated authentication failures
- public-facing web exploit attempt
- cloud storage access from unusual account
- database query spike
- internal scanning from workstation
- backup deletion
- firewall rule change
- new OAuth app consent
Example attack chain:
phishing_email
β
user_clicks_link
β
credential_capture
β
VPN_login
β
internal_discovery
β
data_access
This shows how different weak points connect into one intrusion.
π§ MITRE ATT&CK Techniques
- T1566 β Phishing
- T1078 β Valid Accounts
- T1190 β Exploit Public-Facing Application
- T1046 β Network Service Discovery
- T1021 β Remote Services
- T1041 β Exfiltration Over C2 Channel
πΊ Visual Investigation Diagram
User Layer
β
Endpoint Layer
β
Identity Layer
β
Network Layer
β
Application Layer
β
Cloud / Data Layer
β
Business Impact
β Challenges
The main challenge is that βattack surfaceβ is a huge concept.
It is not one thing.
It is the total set of places an attacker can try to enter, abuse, or exploit.
Another challenge is not getting overwhelmed.
The answer is not to memorize every possible weakness immediately.
The practical approach is to group them by area:
- user
- endpoint
- identity
- network
- application
- cloud
- data
- third party
π What I Learned
I learned that exploitation is not only about technical vulnerabilities.
Attackers exploit:
- software bugs
- human trust
- weak passwords
- poor configuration
- excessive permissions
- missing monitoring
- weak processes
- exposed services
This makes cybersecurity broader than I first imagined.
A SOC analyst needs to understand enough of each area to triage alerts and escalate properly.
β‘ Next Steps
- Build an attack surface checklist
- Map common attacks to each layer
- Learn which logs exist at each layer
- Study how SOC, AppSec, CloudSec, and GRC responsibilities differ
- Create a visual weak-point diagram for portfolio use
- Practice describing attack chains end to end
π§ Reflection
This topic helped me see cybersecurity as a system of connected defenses.
A single alert may belong to one layer.
A real attack usually crosses several layers.
That is why context matters.
π§© Lessons Learned
What worked
Grouping weak points by layer.
What broke
Trying to think of exploitation as only βhacking a serverβ.
Why it broke
Attackers exploit people, identities, cloud settings, and processes too.
Fix / takeaway
Attack surface means every reachable weakness, not just vulnerable software.
π Skill Progression Context
This supports SOC readiness because real investigations often require cross-domain thinking.
The analyst must understand whether an alert belongs to endpoint, network, identity, cloud, application, or data security.
π TL;DR
Attackers do not need the strongest door.
They need the forgotten window.
