The attack surface is all possible points where attackers can try to enter or exploit a system.

It is usually divided into:

  1. Digital Attack Surface (online & network systems)
  2. Physical Attack Surface (devices & hardware)
  3. Human Attack Surface (people & behaviors)

1. Digital Attack Surface

All network-connected and software-based assets that could be exploited.

This includes web apps, APIs, cloud services, email servers, and operating systems.

Common Threats


Web Applications & APIs & Mobile

Cloud Attack Surface