Threat vectors: browsers, endpoints, people, IoT and OT, physical access and radio

This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.

Listen to this lesson

Episode 12 · 59:59

Every episode of this course is also a podcast: listen on Spotify.

This episode is a study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.

Objective 2.3 · Threats, Vulnerabilities, and Attacks · 24% of the exam

Objective 2.3 continues. The previous lesson took the routes that arrive over a wire — messages, attachments, network devices, remote access and the supply chain. This one takes the rest: the browser, the endpoint itself, people in the building, devices nobody thinks of as computers, physical entry, and radio. The verb is still describe: what each route is, what its use looks like, and what closes it.

Why this matters

Most of these vectors are new to the exam as named items, and most of them are places where an organisation's controls are thinnest. Email has twenty years of filtering behind it. The browser extension a user installed last week, the printer on the third floor and the door propped open for a delivery have almost none.

They also share a theme: in nearly every case the attacker uses something that is already trusted — a signed-in browser, a built-in admin tool, a contractor with a badge, a device on the internal network. Trust that nobody re-checks is the common weakness, and re-checking it is the common control.

The lesson

Browser extensions, scripts, cookies and session tokens, and the password manager as a target

The browser is where most work now happens, so it holds the keys to most systems.

  • Extensions often have permission to read and change every page the user visits. A malicious one can read data, capture form input and alter transactions. Legitimate extensions can turn malicious too, through a hijacked developer account or a sale to new owners who push a hostile update.
  • JavaScript runs from every site visited, including from the third-party scripts sites embed for adverts and analytics. A compromised script on a legitimate checkout page can skim card details from every customer while the site itself appears unchanged.
  • Cookies and session tokens prove a user has already signed in. Steal one and you skip the password and the MFA, because the authentication already happened. Information-stealing malware harvests them in bulk, and stolen sessions are traded.
  • Password managers are a deliberate concentration of credentials, which makes them a target: phishing for the master password, fake extensions imitating real ones, and autofill that can be lured onto the wrong page.

Indicators: an extension the organisation never approved; a session used from a new location while the user is still active elsewhere; checkout pages loading scripts from an unfamiliar domain. Controls: manage browsers centrally and allow only approved extensions; keep session lifetimes short and require re-authentication for sensitive actions; bind sessions to the device where the platform supports it; set cookies as secure and inaccessible to scripts; and protect the password manager with a long master passphrase and MFA. A password manager is still far safer than the alternative — the point is to defend it, not to avoid it.

Endpoints, and the built-in tools an intruder can live off without installing anything

Endpoint-based vectors are the devices themselves: mobile devices and tablets that leave the building and join untrusted networks; workstations where users browse, open files and run software; servers that hold data and run services others depend on; and trusted devices — machines the organisation has decided not to challenge, such as a laptop remembered so it skips MFA, or a host allowed through the firewall because of what it is rather than what it is doing. Each trusted device is a shortcut an attacker inherits if they compromise it.

The most important idea here is living off the land. Every operating system ships with powerful built-in tools — scripting shells, remote management interfaces, task schedulers, file transfer and certificate utilities. An intruder who uses them installs nothing new, so there is no foreign file for antivirus to find, and the activity looks like administration.

What gives it away is behaviour and context: an office document starting a scripting shell, an administrative tool run by an account that never uses it, remote management traffic between two workstations, a utility downloading a file from the internet. The controls are endpoint detection and response that watches process chains, detailed logging of scripts and command lines, application control that limits which built-in tools ordinary users can run, and removing local administrator rights. The malware lesson covers fileless techniques as indicators.

People as the vector: impersonation, contractors, visitors and the watering hole

Human-based vectors use people's access, presence or habits:

  • Impersonation — claiming to be someone with a reason to be there or to be asking: an engineer, an auditor, a new starter, a senior manager. In person it gets an attacker through doors; by phone or message it gets resets and payments. The social engineering lesson covers it as a technique.
  • Contractors hold real access with less vetting, less training, their own devices, and offboarding that is easy to forget when the contract ends.
  • Visitors are inside the building by invitation. Without sign-in, a visible badge and an escort, a visitor is indistinguishable from an intruder.
  • Biometric data is a vector because it identifies people and cannot be changed. A face, fingerprint or voice can be copied or synthesised to fool a weak sensor, and a leaked biometric template stays leaked for life. Liveness detection and pairing biometrics with another factor are the controls.
  • A watering hole attack compromises a site the target group is known to visit — an industry forum, a supplier portal — and waits. The attacker never contacts the victims. The exam tell is "a site staff commonly use was compromised".

Controls: visitor management and escorts, contractor accounts with end dates and least privilege, a culture where challenging an unfamiliar person is expected, and for watering holes, patched browsers, script and web filtering, and endpoint detection.

Cameras, sensors, printers and OT: devices nobody thinks of as computers

IoT-based vectors are network-connected devices with weak defaults and long, unmanaged lives:

  • Cameras are frequently exposed to the internet with factory credentials and old firmware. Large botnets have been built almost entirely from them.
  • Sensors — environmental, occupancy, building management — report to platforms on the network and are rarely monitored for compromise.
  • Printers store copies of documents, run network services, and are often configured with directory or email credentials so they can scan to a user. Nobody patches them.

OT-based vectors are the industrial control systems that run physical processes — controllers on a factory line, building systems, utilities. OT is designed for availability and safety over decades, runs protocols built without authentication, and often cannot be patched without stopping production. A compromise there has physical consequences.

Controls for both: an inventory that includes them, changing default credentials, disabling unused services, putting them on segmented networks with only the connections they need, monitoring their traffic (passively, for OT, so monitoring cannot disturb the process), and replacing devices the vendor no longer supports.

Locks, vestibules and access passes, and Bluetooth, RF and NFC as the signal-based way in

Physical-based vectors are about getting into the space where the systems are:

  • Lock and key — locks can be picked or bypassed, and keys copied, lent or never returned. A key cannot be revoked; only the lock can be changed.
  • Access vestibule — two doors where only one opens at a time, so a single authorised person passes through. It is the control that defeats following someone in; it becomes a vector when it is propped, bypassed or set to let everyone through for convenience.
  • Access passes — badges can be lost, shared, or, for older low-frequency proximity cards, copied by reading them at close range. Encrypted smart-card credentials, a PIN at sensitive doors, and reviewing logs for one badge used in two places close the gap.

Signal-based vectors attack the radio link:

  • Bluetooth — pairing is the weak point. Unsolicited messages to discoverable devices (bluejacking) are a nuisance; reading data from a device without permission (bluesnarfing) is a breach. Turn it off where not needed, keep devices non-discoverable, and patch.
  • RF — any radio link can be jammed, which is a denial of service, and simple fixed-code remotes can be recorded and replayed. Wireless keyboard receivers are input devices on the machine. Rolling codes, encrypted links and jamming detection are the answers.
  • NFC — very short range, but contactless cards and phones can have their exchange relayed to a distant reader, and readers can be tampered with. Transaction limits, cardholder verification, and tamper-evident readers help.

What to take into the exam

  • A stolen session token skips the password and the MFA, because the sign-in already happened. Short sessions and re-authentication limit it.
  • Manage extensions centrally; a legitimate extension can become malicious through an update.
  • Living off the land uses built-in tools, so detection is behavioural — process chains and command lines — not signatures.
  • Contractors, visitors and impersonators use trust and presence; watering holes compromise the site, not the victim.
  • IoT and OT: inventory, change defaults, segment, monitor. OT puts safety and availability first.
  • A key cannot be revoked; a vestibule stops followers; NFC can be relayed.

Practise what you just read

1. Information-stealing malware copies a user's browser session cookies. Why does the user's MFA not protect the account?

Select one

  1. MFA applies only to accounts with admin rights
  2. The sign-in, MFA included, has already happened
  3. Session cookies contain the plain-text password
  4. The cookie lets the attacker reset the MFA device
Show answer

B. A session cookie is issued after authentication succeeds, so presenting it proves a sign-in that already included the second factor. Short session lifetimes, re-authentication for sensitive actions, binding sessions to a device and cookies inaccessible to scripts are what limit the theft.

2. An intruder uses only the operating system's own scripting shell and task scheduler, installing nothing new. What is most likely to detect this?

Select one

  1. Signature antivirus with daily definition updates
  2. A file integrity check on program directories
  3. Behavioural detection of unusual process chains
  4. Blocking every executable not signed by its vendor
Show answer

C. Living off the land uses trusted built-in tools, so there is no foreign file for antivirus or integrity checks to find, and the binaries are vendor-signed. What gives it away is behaviour and context, such as an office document starting a shell, which EDR and command-line logging capture.

3. Staff from one industry regularly visit a trade forum. Attackers compromise the forum and wait for those visitors. What is this?

Select one

  1. A typosquatting campaign
  2. A pretexting phone call
  3. A brand impersonation site
  4. A watering hole attack
Show answer

D. A watering hole attack compromises a site the target group is known to visit and waits; the attacker never contacts the victims directly. The exam tell is 'a site staff commonly use was compromised'. Patched browsers, script and web filtering and endpoint detection are the controls.

Hands-on labs

All hands-on labs

This is an independent study companion for CompTIA Security+ SY0-801 and is not produced by or endorsed by CompTIA.