# Attack Vector

The specific path or method an attacker uses to gain unauthorized access to a system or network, such as a phishing email or exploit.

An **attack vector[↗](/attack-vector)** is the specific path or method an attacker uses to gain unauthorized access to a system, network, or data. Common attack vectors include phishing[↗](/phishing) emails, unpatched software vulnerabilities, stolen credentials, malicious USB drives, and unsecured Wi-Fi networks.

Understanding an organization's possible attack vectors, collectively part of its attack surface[↗](/attack-surface), is central to prioritizing defenses, since resources are best spent closing off the paths attackers are most likely to actually use. Security teams regularly review new attack vectors as technology and attacker techniques evolve.
