Attack vectors

Attack vectors

Manage all your company's Attack Vectors


Attack Vectors execute simulation events — the offensive actions. They are deployed on your information system to carry out the events within the campaign scope and per the configured settings. To install one, see  Deploy an Attack Vector .


Attack Vectors list


The list shows, for each Attack Vector: its alias, identifier, the campaign using it, creation date, IP address, version, and status. You can order by identifier or creation date, filter (type, in use or not within a campaign), and search.
If an Attack Vector's system clock is not synchronized, the platform calculates a Time offset against the reference clock (requires Attack Vector version 1.4.0 or above). It appears in the Attack Vector's details.


Attack Vector statuses

Status
Color
Description
Operational
On and connected to the BlackNoise platform; ready to run a simulation.
Non operational
Cannot run a simulation. Check that the Attack Vector is started (host machine, and Docker for the software version) and that the required flows to the platform are open — see  Deploy an Attack Vector .
Working
Currently used in a simulation, running that campaign's events; it cannot be used by another campaign at the same time.
Deploying
Setup in progress; ready in a few minutes.
Upgrading
Updating its main code and modules.
A red star next to the version number indicates an available update.


Create and update an Attack Vector

Create and install an Attack Vector, then update it when a new version is available, from Resources > Attack Vectors (the Create attack vector button, and the Update version button in an Attack Vector's details). The full procedure — prerequisites, installation, updating and troubleshooting — is in  Deploy an Attack Vector .
The update method depends on the version currently installed: from version 1.3.10 the update runs from the web app, while older Attack Vectors are updated by running a docker command on the host.
Keeping an Attack Vector up to date is not optional: creating a campaign, launching a new simulation and testing the connection to a System Target require the latest available version, and the web app blocks the action and points to the update until it is applied.