Acquire
- Intercept or recover ciphertext
- Collect related artifacts and context
- Capture protocol and traffic metadata
Understand
- Identify the cipher and protocol
- Map the operational context
- Find the weakest link to attack
Model
- Build a statistical model of the system
- Map relationships in the data
- Predict where structure leaks
Cipher Classes
- Separate substitution from transposition
- Distinguish symmetric from asymmetric keys
- Tell block ciphers from stream ciphers
Integrity Types
- Recognize hashes and MACs for integrity
- Identify signatures for authenticity
- Note modes like CTR and GCM
Attack Toolkit
- Exploit frequency and statistical bias
- Leverage known or chosen plaintext
- Exhaust small keyspaces by brute force
Side Channels
- Extract leaks from timing and power
- Exploit cache and EM emissions
- Attack flawed handshakes and key exchange
Decrypt & Exploit
- Recover key material with confidence
- Reconstruct plaintext reliably
- Translate plaintext into intelligence