Web App Compromise (Attack Tree)
Paths to exfiltrate user data from a web app.
Make it your own.
title "Compromise the web app"
goal G "Exfiltrate user data"
OR G1 "Injection" parent G
OR G2 "Broken auth" parent G
OR G3 "Misconfiguration" parent G
leaf L1 "SQL injection" parent G1 cost 2 skill medium detect medium
leaf L2 "Stored XSS" parent G1 cost 2 skill medium detect medium
leaf L3 "Credential stuffing" parent G2 cost 1 skill low detect medium
leaf L4 "Session fixation" parent G2 cost 3 skill high detect high
leaf L5 "Exposed admin panel" parent G3 cost 1 skill low detect low