Attack library

Know your enemy.

A living reference of phishing techniques, evasion tactics, and BEC patterns, with plain-English explanations of how each attack works and how Cambrient's agents catch them.

6 attacks
01
Critical
Multi-Hop Redirect Chain
The threat is never in the first link.
02
Critical
Business Email Compromise (BEC)
No malware. No links. Just trust.
03
High
Credential Harvesting Page
A perfect copy of a login page you trust.
04
High
QR Code Phishing (Quishing)
The link is in the image. Scanners can't see it.
05
High
Lookalike Domain Attack
One character off. Impossible to spot at a glance.
06
Medium
Malware via Trusted Send Platform
Sent from a legitimate ESP. Delivered with full trust.
01 / 06EvasionCritical

Multi-Hop Redirect Chain

The threat is never in the first link.

Attackers route victims through 2 to 5 intermediate domains, often legitimate services like Bit.ly, Firebase, or Cloudflare Pages, before landing on the credential harvester. Each hop looks clean individually. URL reputation checkers never follow the chain.

How the attack works
01Victim receives email with a Bit.ly link (trusted domain, passes reputation check)
02Bit.ly redirects to a CDN-hosted tracking pixel on a legitimate-looking domain
03CDN redirects to a Firebase or Cloudflare Pages host
04Final destination: fake Microsoft 365 or Outlook login page
05Credentials harvested and forwarded to attacker in real time
How Cambrient catches this

Cambrient's agents follow every redirect hop, render each page, and evaluate content at each step. The chain terminates when the agent finds a login form that doesn't match the claimed sender.

Real-world example

A phishing campaign targeting HR departments used LinkedIn redirect parameters as the first hop, routing through a legitimate career portal before landing on a fake DocuSign credential harvester. Defender delivered it cleanly.

Run it live

See how Cambrient catches
all of these.

Book a demo and we'll run a live example of any attack in this library against your domain.