Attack Methods — Election Security Glossary
24 election security terms in the Attack Methods category, with definitions sourced from NIST, CISA, EAC, and 30+ authoritative documents.
Browse all 24 terms in Attack Methods
Attack Mode
Attack Mode refers to the specific techniques, strategies, and methodologies adversaries use to exploit vulnerabilities and achieve malicious objectives, ranging from phishing and…
Attack Path
An attack path is a sequence of interconnected steps that attackers use to navigate an organization's IT environment to reach critical assets, moving from initial entry to a final…
Blended Attack
A type of attack that combines multiple attack methods against one or more vulnerabilities.
Distributed Denial Of Service
A denial of service technique that uses numerous systems to perform the attack simultaneously.
Escalation Of Privilege
An attack on a system where the attacker is using some means to bypass security controls in order to attain a higher privilege level on the target system.
Exploit Code
(or exploit) A program, a script or a line of code with which vulnerabilities in a computer system can be used to advantage.
Flooding
An attack that attempts to cause a failure in a system by providing more input than the system can process properly.
Jamming
An attack that attempts to interfere with the reception of broadcast communications.
Keylogger
Devices or programmes in operation between the computer and the keyboard to record keystrokes.
Replay Attacks
An attack that involves the capture of transmitted authentication or access control information and its subsequent retransmission with the intent of producing an unauthorized…
Vishing
vishing or 'voice phishing' is the use of voice technology (landline phones, mobile phones, voice email, etc) to trick individuals into revealing sensitive financial or personal…
Attack Pattern
Attack patterns are standardized descriptions of common methods used by adversaries to exploit software, hardware, or network vulnerabilities, often categorized by TTPs (Tactics,…
By ESG Editorial Team · Drawing on MITRE ATT&CK, CISA advisories, and 25+ sources on election-targeted threats
Attack methods are the techniques adversaries use against election infrastructure. They span the full range of cyber and physical activity: phishing, malware deployment, denial-of-service, supply chain compromise, insider threat, physical intrusion, influence operations, and disinformation. No single defense addresses all of them. Defending against the full range requires knowing what the threats are.
Why this category matters for election security is that defenders cannot prioritize what they do not understand. The threat intelligence community publishes indicators of compromise, advisories, and reports of observed activity. The most useful of these are election-specific: not just "ransomware is active" but "ransomware has been observed targeting county government networks that support elections."
The taxonomy of attack methods is not fixed. Adversaries develop new techniques as defenders close off old ones. Election infrastructure is a specific target with specific characteristics, and the threats to it are correspondingly specific. Phishing against a county election office is not the same as phishing against a bank. The vocabulary here reflects that specificity.
The terminology in this category covers the major categories of attacks that have been observed against election infrastructure. The concepts here are descriptive. They name the threats so they can be discussed and defended against.
Key Concepts
Phishing
Deceptive communications, typically email, crafted to trick election officials into revealing credentials or installing malicious software.
Ransomware
Malware that encrypts victim data and demands payment for the decryption key.
Denial Of Service
An attack that aims to make a system or network resource unavailable to its intended users.
Supply Chain Attack
A cyberattack that compromises less-secure elements of a supply chain (hardware, firmware, or software) to ultimately target the election system using those components.
Advanced Persistent Threat
A prolonged, sophisticated cyberattack in which an adversary gains long-term access to a network, often for espionage or future disruption.
How These Terms Relate
These concepts together describe the threat landscape that election infrastructure faces. The terminology here draws on the broader cybersecurity vocabulary, but applied to the election context. The unifying theme is that named threats are addressable threats. A jurisdiction that knows what it faces can plan for it. The category does not rank threats by likelihood: the threat a given election office faces depends on its size, its visibility, its connectedness, and the resources of its adversaries.
Related categories
1,851 terms
The wider cybersecurity context in which these methods operate.
Incident Response19 terms
The discipline of responding when an attack succeeds.
Network Security37 terms
The network-level concerns that several of these methods exploit.
Supply Chain13 terms
The trust assumptions that several of these methods attack.
Can't find the right category?
Search the full glossary, or browse every term alphabetically instead.