Attack Steps
An Attack Step is a single discrete action an attacker takes as part of an Attack Path. Breaking attack paths into steps enables granular feasibility analysis and reuse across multiple paths.
List View
Open Risk Manager → Libraries → Threat Library. Attack Steps is the tab the Threat Library opens on.
The table shows each step’s ID (its auto-generated AS-xxx reference), Name, Attack Paths (reference chips), and an Actions column. Only the ID cell is a link — click it to open the detail page.
- Create — click New in the toolbar. The New Attack Step dialog has a required Name plus optional ATM ID, Example, the five attack-potential factors, and Keywords (multi-select). The reference is auto-generated — there is no reference input.
- Delete — click the delete icon in the Actions column; a confirmation dialog appears before permanent removal.
Detail Page
Click a step’s ID in the list to open its detail page. A Return to Attack Steps link navigates back to the list.
Details
| Field | Description |
|---|---|
| Reference | Auto-generated identifier (e.g. AS-001) |
| Name | Descriptive title of the attack action (required) |
| ATM ID | Optional reference to an Attack Tree Model entry |
| Example | Illustrative example of the step |
| Feasibility | The five attack-potential values, shown as raw numbers (e.g. ET 4 · SE 3 · KoIC 7 · WoO 1 · Eq 4) |
There is no Description field. Keywords can be set in the create/edit dialog but are not displayed on the detail page.
Attack Potential Factors
Each step carries five ISO/SAE 21434 attack-potential factors, entered as point values (higher points = harder for the attacker):
| Factor | What it measures | Point values |
|---|---|---|
| ET — Elapsed Time | Time required for this step | 0 / 1 / 4 / 17 / 19 |
| SE — Specialist Expertise | Skill level needed | 0 / 3 / 6 / 8 |
| KoIC — Knowledge of Item/Component | Familiarity with the target component | 0 / 3 / 7 / 11 |
| WoO — Window of Opportunity | Accessibility of the target | 0 / 1 / 4 / 10 |
| Eq — Equipment | Tools required | 0 / 4 / 7 / 9 |
Values are displayed as raw numbers — there is no Very Low/Low/Medium/High labeling and no stored per-step aggregate. Feasibility is aggregated per attack path at scoring time (see How feasibility works).
Attack Paths
Tab listing the Attack Paths that include this step. Click a path’s ID to navigate to the Attack Path detail page.
Editing
Click Edit on the detail page to open the step in a modal form dialog. Click Save Changes to persist or Cancel to discard.