Backdoor

A hidden method of bypassing normal authentication to maintain access.

A backdoor bypasses normal authentication to give persistent, hidden access — left by malware, by an attacker after compromise, or occasionally by a developer. Hunt for the signs: unexpected listening ports, new local accounts, and scheduled tasks pointing to odd paths. The most dangerous variety is the supply-chain backdoor (e.g., the XZ Utils implant), which reaches victims through trusted, signed software updates.

Related terms

Back to Threats, Vulnerabilities, and Mitigations