Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What is a web application attack?

A web application attack is unauthorised activity directed at a website, API or web-delivered service. Unusual requests are common and may be scanning, malformed input or blocked attempts rather than successful compromise.

Trace the request through the application

Identify the endpoint, exact request, authentication and session, application response and downstream activity. Reverse proxies, web servers, application logs, databases, cloud audits and endpoint processes may each describe one layer.

Where services are distributed, use request or trace identifiers and routing records to establish which instance handled the request and which component produced any effect.

Prove the intended effect separately

Attacks may seek authentication bypass, data access, command execution, upload, account takeover, logic abuse or disruption. A suspicious parameter or successful HTTP status does not establish any of those outcomes.

Show server-side process, database, account, file or data effects. The visible source address may be a CDN, gateway or proxy and should not be treated as the controller without the complete route.

Key takeaway

Reconstruct web attacks from request through application processing to a specific server-side effect, proving success independently of suspicious syntax or response status.

Reference: CIM-208Cyber Incidents & Offender Methods