Learn the threats
we look for.
Plain-English explanations of every issue Horus Secure Analyst flags, with reference videos from OWASP, PortSwigger, Computerphile, and IBM Technology, plus links for deeper reading.
Phishing
Tricking users into revealing passwords or sensitive info via fake emails, sites, or messages.
Password attacks
Guessing, leaked-credential reuse, and credential stuffing.
Malware
Malicious software — ransomware, trojans, spyware.
Social engineering
Manipulating people to bypass technical security controls.
SQL injection
Abusing poorly-validated input to run arbitrary SQL.
Cross-site scripting (XSS)
Injecting malicious scripts into web pages.
Man-in-the-middle attacks
Intercepting communications on insecure networks.
Denial-of-service attacks
Overwhelming systems so they stop working.
Privilege escalation
Gaining higher access than intended.
Unpatched software
Attacking known vulnerabilities in outdated dependencies.
Misconfigured cloud / server access
Exposed storage, weak permissions, open admin panels.
Insider threats
Misuse of access by employees or contractors.