glossary
Glossary
Definitions of terms from cybersecurity, penetration testing and red teaming, short and in depth.
- A
- ABAC
- Access ControlAC
- Access Control ListACL
- Account TakeoverATO
- ACME ProtocolACME
- Active DirectoryAD
- Active Directory Computer AccountComputer Account
- Active Directory DomainAD Domain
- Active Directory ForestForest
- Active Directory GroupAD Group
- Active Directory ObjectDirectory Object · Object
- Active Directory ReplicationAD Replication · Directory Replication
- Active Directory SchemaAD Schema · Schema
- Active Directory SiteAD Site · Site
- Active Directory TreeDomain Tree · Tree
- Active Directory TrustTrust
- Active Directory UserAD User · User Account
- Active Directory-Integrated DNSAD-Integrated DNS
- Adaptive AuthenticationAA
- Address Space Layout RandomizationASLR
- Advanced Persistent ThreatAPT
- Adversarial Machine LearningAML
- Adversary-in-the-MiddleAiTM · MITM
- AES-GCM
- Agentless Security
- Air Gap
- AllowlistingApplication Allowlisting · Whitelisting
- Anomaly Detection
- Anti-MalwareAM
- Anti-Phishing
- API Security
- Application SecurityAppSec
- ARP SpoofingARP Poisoning
- Asset Inventory
- Asset ManagementITAM
- Attack Method
- Attack Path
- Attack Surface
- Attack Vector
- Audit Evidence
- AuthenticationAuthN
- AuthorizationAuthZ
- AvailabilityA
- B
- Backdoor
- Backend
- Backup
- BACnet Security
- BadUSB
- Baseline ConfigurationBaseline
- Bastion HostJump Host
- BeaconingC2 Beaconing
- Behavioral AnalyticsBA · UEBA
- Binary Analysis
- Binary ExploitationPwn
- Biometric Authentication
- Black Box TestingBlack-Box Testing · BBT
- Block Cipher
- Blue Team
- Bootkit
- Botnet
- BreachData Breach
- Brute-Force AttackBrute Force
- Business Continuity ManagementBCM
- Business Impact AnalysisBIA
- C
- CAASM
- Cache Poisoning
- Canary Token
- CAPEC
- Centralized Management
- Certificate AuthorityCA
- Certificate PinningPinning
- Certificate Revocation ListCRL
- Chain of CustodyCoC
- Challenge-Response AuthenticationCRA
- Change ManagementCM
- Chief Information Security OfficerCISO
- Chroot Jailchroot
- Cipher
- Clickjacking
- Cloud Access Security BrokerCASB
- Cloud Infrastructure Entitlement ManagementCIEM
- Cloud Resource
- Cloud Security Posture ManagementCSPM
- Cloud-Native Application Protection PlatformCNAPP
- Code Signing
- Cold Boot Attack
- Command and ControlC2 · C&C
- Common Vulnerabilities and ExposuresCVE
- Common Vulnerability Scoring SystemCVSS
- Communication Plan
- Compensating Control
- Compromise Assessment
- Confidential ComputingCC
- ConfidentialityC
- Container Security
- Containment
- Content Security PolicyCSP
- Continuous AuthenticationCA
- Continuous Improvement
- Continuous MonitoringCM
- Continuous Optimization
- Credential Stuffing
- Cross-Site Request ForgeryCSRF · XSRF
- Cross-Site ScriptingXSS
- Cryptographic Algorithm
- Cryptography
- Cyber Kill ChainCKC
- Cyber Risk
- Cyber Threat IntelligenceCTI
- D
- Data at RestDAR
- Data Classification
- Data Encryption StandardDES
- Data Exfiltration
- Data in TransitDIT
- Data Lifecycle
- Data Loss PreventionDLP
- Data Masking
- Data Minimization
- Data Poisoning
- Data Retention
- Data Security Posture ManagementDSPM
- Data Source
- Data Sovereignty
- Data Wiping
- Dead Drop ResolverDDR
- Deception Technology
- Deep Packet InspectionDPI
- Defense in DepthDiD
- Demilitarized ZoneDMZ
- Denial of ServiceDoS
- Dependency Confusion
- Detection
- Detection Engineering
- Detection Logic
- Development Process
- DevSecOps
- Dictionary Attack
- Digital CertificateCert
- Digital ForensicsDFIR
- Digital Signature
- Directory TraversalPath Traversal
- Disaster RecoveryDR
- Disk EncryptionFDE
- Distributed Denial of ServiceDDoS
- Domain ControllerDC
- Domain Name System Security ExtensionsDNSSEC
- Dynamic Application Security TestingDAST
- E
- EASM DiscoveryEASM
- Elliptic Curve CryptographyECC
- Email AuthenticationSPF · DKIM · DMARC
- Email Security GatewayESG · SEG
- Enclave
- Encryption
- Endpoint
- Endpoint Detection and ResponseEDR
- Endpoint Protection PlatformEPP
- Enterprise Risk ManagementERM
- Entropy
- Enumeration
- Ephemeral Key
- Eric Zimmerman ToolsZimmerman Tools · EZ Tools
- Escalation Path
- Evaluation Criteria
- Evidence Preservation
- Evil Twin Attack
- EvilginxEvilnginx
- Exploit
- Exploit Kit
- Extended Detection and ResponseXDR
- External Attack Surface ManagementEASM
- F
- Fail-Safe Defaults
- False NegativeFN
- False PositiveFP
- Fast Flux
- Federated Identity
- Federated Learning SecurityFLS
- Feedback Loop
- File Integrity MonitoringFIM
- Fileless Malware
- FirewallFW
- Firmware Security
- Forensic Image
- Format String Vulnerability
- Forward SecrecyFS
- Fraud DetectionFD
- FSMO RolesFlexible Single Master Operations · FSMO
- Fuzzing
- G
- Gap Analysis
- Gartner CARTACARTA
- GatewayGW
- Global CatalogGC
- Governance, Risk and ComplianceGRC
- GRC Automation
- Grey Box TestingGrey-Box Testing · Gray-Box Testing · Gray Box Testing
- Group Policy ObjectGPO
- Guardrail
- GUID Security
- H
- Hacker
- Hardening
- Hardware Security ModuleHSM
- Hash Function
- Heap Spray
- Homomorphic EncryptionHE
- Honeypot
- Host Intrusion Prevention SystemHIPS
- Host-based Intrusion Detection SystemHIDS
- HTTP Strict Transport SecurityHSTS
- HTTPS InspectionSSL Inspection
- Human Risk ManagementHRM
- Hybrid Cloud Security
- I
- Identity and Access ManagementIAM
- Identity Control
- Identity Governance and AdministrationIGA
- Identity ProviderIdP
- Identity Threat Detection and ResponseITDR
- Immutable Backup
- Impact
- Implementation
- Incident Handler
- Incident Manager
- Incident ResponseIR
- Incident TriageTriage
- Indicator of AttackIoA
- Indicator of CompromiseIoC
- Information Rights ManagementIRM
- Information Security Management SystemISMS
- Information Sharing
- Infrastructure as Code SecurityIaC Security
- Initial Access BrokerIAB
- Injection AttackInjection
- Input Validation
- Insecure Direct Object ReferenceIDOR
- Insider Threat
- IntegrityI
- Interface
- Internet Key ExchangeIKE
- Internet ProtocolIP
- Intrusion Detection SystemIDS
- Intrusion Prevention SystemIPS
- IoT Security
- IPsec
- Isolation
- J
- Jailbreak Detection
- Java Deserialization Vulnerability
- Jitter EntropyJitter RNG
- JSON Web EncryptionJWE
- JSON Web TokenJWT
- Just Enough AdministrationJEA
- Just-in-Time AccessJIT Access
- K
- Kerberos
- Key Derivation FunctionKDF
- Key Escrow
- Key Lifecycle
- Key Management SystemKMS
- Key Rotation
- Key Stretching
- Key TransparencyKT
- Keystroke LoggingKeylogging
- Kill Switch
- Kubernetes Admission Controller
- L
- Lambda SecurityFaaS Security
- Lateral Movement
- LDAP Injection
- Least PrivilegePoLP
- Lightweight Directory Access ProtocolLDAP
- Likelihood
- Link Encryption
- Linux Security ModulesLSM
- Living off the LandLotL · LOLBins
- Local Administrator Password SolutionLAPS
- Lockheed Martin Diamond ModelDiamond Model
- Log Management
- Logging
- Logic Bomb
- M
- Machine Identity
- Malicious Component
- Malvertising
- Malware
- Man-in-the-BrowserMitB
- Managed Detection and ResponseMDR
- Mandatory Access ControlMAC
- Maturity Model
- Memory Corruption
- Memory Forensics
- Message Authentication CodeMAC
- Microsegmentation
- MITRE ATT&CKATT&CK
- Mobile Application Security TestingMAST
- Mobile Device ManagementMDM
- Monitoring
- Multi-Factor AuthenticationMFA
- N
- N-day VulnerabilityN-day
- Network Access
- Network Access ControlNAC
- Network Behavior AnalysisNBA · NTA
- Network Communication
- Network Detection and ResponseNDR
- Network FlowFlow
- Network ForensicsNF
- Network Function Virtualization SecurityNFV Security
- Network Security GroupNSG
- Network Segmentation
- Next-Generation FirewallNGFW
- NIST Cybersecurity FrameworkNIST CSF
- Non-Repudiation
- Nonce
- O
- OAuth 2.0OAuth
- Obfuscation
- OCSP Stapling
- Offensive SecurityOffSec
- One-Time PasswordOTP
- Onion Routing
- Open Redirect
- Open Source IntelligenceOSINT
- Open Web Application Security ProjectOWASP
- OpenID ConnectOIDC
- Operational ResilienceOR
- Operational TechnologyOT
- Operational Technology SecurityOT Security
- OPSECOperational Security · Operations Security
- Organizational UnitOU
- P
- Pass-the-HashPtH
- Pass-the-TicketPtT
- Password Spraying
- Passwordless Authentication
- Patch Management
- Payload
- Penetration TestPentest
- Penetration TestingPentest · Pen Test
- Perfect Forward SecrecyPFS
- Peripheral Component Interconnect SecurityPCIe Security
- Phishing
- Policy as CodePaC
- Post-Exploitation
- Post-Incident Review
- Post-Quantum CryptographyPQC
- Prevention
- Privacy by DesignPbD
- Privilege Escalation
- Privileged Access ManagementPAM
- Process Hollowing
- Proof of PossessionPoP
- Protection Requirement
- Public Key InfrastructurePKI
- Purple Team
- Q
- Quantum Key DistributionQKD
- Quantum-Safe CryptographyPQC · Post-Quantum Cryptography
- Quarantine
- Query Parameter PollutionQPP · HPP
- R
- Race ConditionTOCTOU
- Rainbow Table
- Ransomware
- Rate Limiting
- ReconnaissanceRecon
- Recovery
- Recovery Objective
- Recovery Point ObjectiveRPO
- Recovery Time ObjectiveRTO
- Red Team
- Red TeamingRed Team
- Remediation
- Remote Access TrojanRAT
- Remote Browser IsolationRBI
- Remote Code ExecutionRCE
- Replay Attack
- Repository
- Residual Risk
- Response Action
- Response Process
- Responsibility
- Reverse EngineeringRE
- Risk Appetite
- Risk Assessment
- Risk Mitigation
- Risk Register
- Risk Treatment
- Risk-Based Prioritization
- Rogue Access PointRAP
- Role-Based Access ControlRBAC
- Rootkit
- Rules of Engagement
- Runtime Protection
- S
- SAML
- SandboxingSandbox
- Scope
- Secret
- Secure Access Service EdgeSASE
- Secure Boot
- Secure Coding
- Secure Configuration
- Secure Design
- Secure Development LifecycleSDL · SSDLC
- Secure EnclaveSE
- Secure Multi-Party ComputationSMPC · MPC
- Security Alert
- Security Analyst
- Security Architecture
- Security Assertion Markup LanguageSAML
- Security Awareness
- Security Chaos EngineeringSCE
- Security Content Automation ProtocolSCAP
- Security Control
- Security Control ValidationSCV
- Security Information and Event ManagementSIEM
- Security Misconfiguration
- Security Objective
- Security Operations
- Security Operations CenterSOC
- Security Orchestration, Automation and ResponseSOAR
- Security Policy
- Security Principal
- Security Requirement
- Security Service EdgeSSE
- Security Technical Implementation GuideSTIG
- Security Testing
- Server
- Server-Side Request ForgerySSRF
- Session Hijacking
- Shadow IT
- Shared Responsibility ModelSRM
- Shoulder Surfing
- Side-Channel AttackSCA
- SIM SwappingSIM Swap
- Single Sign-OnSSO
- Smishing
- Social EngineeringSE
- Software Bill of MaterialsSBOM
- Software Dependency
- Source Code AnalysisSCA
- Source Evaluation
- Spear Phishing
- SQL InjectionSQLi
- Supply Chain Attack
- SYSVOLSystem Volume
- T
- Tabletop ExerciseTTX
- Tactics, Techniques and ProceduresTTPs
- Tamper Resistance
- Telemetry
- Test Data
- Threat ActorTA
- Threat Emulation
- Threat Hunting
- Threat Intelligence PlatformTIP
- Threat Modeling
- Threat Scenario
- Threat-Informed DefenseTID
- Time-Based One-Time PasswordTOTP
- Timing Attack
- Tokenization
- Traceability
- Transport Layer SecurityTLS
- Trojan HorseTrojaner
- Trust Chain
- Trusted Execution EnvironmentTEE
- Two-Factor Authentication2FA
- U
- Unidirectional GatewayData Diode
- Unified Threat ManagementUTM
- Universal Second FactorU2F
- Universal Serial Bus SecurityUSB Security
- URL Filtering
- User and Entity Behavior AnalyticsUEBA
- User Awareness TrainingSecurity Awareness
- User Provisioning
- V
- Verification
- Version Control SecurityVCS Security
- Virtual Machine EscapeVM Escape
- Virtual Patch
- Virtual Private NetworkVPN
- Vishing
- Volatile Memory AnalysisMemory Forensics
- VulnerabilityVuln
- Vulnerability AssessmentVA
- Vulnerability Disclosure ProgramVDP
- Vulnerability ManagementVM
- W
- Watering Hole Attack
- Web Application FirewallWAF
- Web Cache DeceptionWCD
- Web Cache PoisoningWCP
- Web Shell
- WebAuthn
- WebSocket Security
- White Box TestingWhite-Box Testing
- Wi-Fi Protected Access 3WPA3
- Workload
- Worm
- X
- X.509 CertificateX.509
- XDR TelemetryXDR
- XML External Entity AttackXXE
- XPath Injection
- XSS Filter Bypass
- Z
- Zero TrustZT
- Zero Trust Network AccessZTNA
- Zero-Day Vulnerability0-Day · Zero Day
- Zero-Knowledge ProofZKP
- Zero-Touch ProvisioningZTP
- ZombieBot