The Cyber Dictionary
No IT degree required. We translate confusing cybersecurity jargon into plain English.
Access Control List (ACL)
A list of rules that specifies which users or systems are granted or denied access to a particular object or system resource.
Read definition →Advanced Persistent Threat (APT)
A stealthy threat actor, typically a nation state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period.
Read definition →ARP Spoofing
A type of attack in which a malicious actor sends falsified ARP (Address Resolution Protocol) messages over a local area network.
Read definition →Botnet
A network of infected computers controlled by a single attacker, often without the owners knowing.
Read definition →Buffer Overflow
An anomaly where a program, while writing data to a buffer, overruns the buffer's boundary and overwrites adjacent memory locations.
Read definition →CIA Triad
Confidentiality, Integrity, and Availability. A model designed to guide policies for information security within an organization.
Read definition →Cross-Site Scripting (XSS)
A type of security vulnerability typically found in web applications that enables attackers to inject client-side scripts into web pages viewed by other users.
Read definition →CSRF
Cross-Site Request Forgery. An attack that forces an end user to execute unwanted actions on a web application in which they're currently authenticated.
Read definition →Cyber Kill Chain
A framework developed by Lockheed Martin that describes the stages of a cyberattack, from early reconnaissance to the final goal.
Read definition →DDoS Attack
A malicious attempt to disrupt the normal traffic of a targeted server by overwhelming the target with a flood of internet traffic.
Read definition →Deepfake
Highly realistic, computer-generated videos or audio recordings designed to make it look like someone said or did something they never actually did.
Read definition →Defense in Depth
An information assurance concept in which multiple layers of security controls are placed throughout an information technology system.
Read definition →DHCP
A network management protocol used on IP networks for automatically assigning IP addresses to devices connected to the network.
Read definition →Digital Certificates
An electronic document used to prove the ownership of a public key. The certificate includes information about the key, information about the identity of its owner, and the digital signature of an entity that has verified the certificate's contents.
Read definition →Directory Traversal
An HTTP exploit which allows an attacker to access restricted directories and execute commands outside of the web server's root directory.
Read definition →DMZ (Demilitarized Zone)
A physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted network, usually a larger network such as the Internet.
Read definition →DNS
The phonebook of the Internet. It translates domain names to IP addresses so browsers can load Internet resources.
Read definition →DoS vs DDoS
Denial of Service (DoS) and Distributed Denial of Service (DDoS). An attack meant to shut down a machine or network, making it inaccessible to its intended users.
Read definition →Drive-by Attack
A cyber attack that happens when a user visits a compromised website, which then silently installs malware on the user's device.
Read definition →Dumpster Diving
The practice of sifting through commercial or residential trash to find items that have been discarded by their owners, often for the purpose of finding sensitive information.
Read definition →EDR
Endpoint Detection and Response. An integrated endpoint security solution that combines real-time continuous monitoring and collection of endpoint data with rules-based automated response.
Read definition →Encryption
The process of scrambling your digital information into an unreadable secret code so that hackers cannot steal it.
Read definition →End-to-End Encryption (E2EE)
A system of communication where only the communicating users can read the messages.
Read definition →Evil Twin
A fraudulent Wi-Fi access point that appears to be legitimate but is set up to eavesdrop on wireless communications.
Read definition →Firewall
A network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies.
Read definition →FTP and SFTP
Protocols used for the transfer of computer files between a client and server on a computer network. SFTP adds a layer of security.
Read definition →Group Policy
A feature that controls the working environment of user accounts and computer accounts in an organization.
Read definition →Handshakes
The process that establishes the parameters of a secure communication channel between a client and a server.
Read definition →Hashing vs Salting
Hashing is a one-way mathematical function that turns data into a fixed-length string. Salting adds random data to the input before hashing to make it unique.
Read definition →Honeypot
A computer security mechanism set to detect, deflect, or, in some manner, counteract attempts at unauthorized use of information systems.
Read definition →HTTP and HTTPS
The foundation of data communication for the World Wide Web. HTTPS is the secure version.
Read definition →Hypervisor
Computer software, firmware or hardware that creates and runs virtual machines.
Read definition →IaaS
Infrastructure as a Service. A form of cloud computing that provides virtualized computing resources over the internet.
Read definition →ICMP
A supporting protocol in the Internet protocol suite used by network devices to send error messages and operational information.
Read definition →Identity and Access Management (IAM)
The framework of policies and technologies ensuring that the right users have the appropriate access to technology resources.
Read definition →IDS / IPS
Intrusion Detection System (monitors) / Intrusion Prevention System (blocks). Network security appliances that monitor network or system activities for malicious activity.
Read definition →IPsec
Internet Protocol Security. A secure network protocol suite that authenticates and encrypts the packets of data sent over an internet protocol network.
Read definition →Kerberos
A computer network authentication protocol that works on the basis of tickets to allow nodes communicating over a non-secure network to prove their identity to one another.
Read definition →Keylogger
A type of surveillance software that has the capability to record every keystroke you make to a log file.
Read definition →LAN vs WAN
A LAN connects computers in a small area (like a home). A WAN connects networks across a large area (like the Internet).
Read definition →LDAP
A protocol used for accessing and maintaining distributed directory information services over an IP network.
Read definition →Malware
Any software intentionally designed to cause damage to a computer or network.
Read definition →Man in the Middle (MITM)
An attack where the attacker secretly relays and possibly alters the communications between two parties who believe they are directly communicating with each other.
Read definition →Memory Leak
A type of resource leak that occurs when a computer program incorrectly manages memory allocations in a way that memory which is no longer needed is not released.
Read definition →MITRE ATT&CK
A globally-accessible knowledge base of adversary tactics and techniques based on real-world observations.
Read definition →Multi-Factor Authentication (MFA)
A security system that requires more than one method of authentication to verify a user.
Read definition →NAT (Network Address Translation)
A method of mapping an IP address space into another by modifying network address information in the IP header of packets while they are in transit across a traffic routing device.
Read definition →Netflow
A network protocol developed by Cisco for collecting IP traffic information and monitoring network traffic.
Read definition →Next-Gen Firewall (NGFW)
A network security device that provides capabilities beyond a traditional, stateful firewall, adding application-level inspection and intrusion prevention.
Read definition →PaaS
Platform as a Service. A complete development and deployment environment in the cloud.
Read definition →Pass-the-Hash
A hacking technique that allows an attacker to authenticate to a remote server or service by using the underlying NTLM or LanMan hash of a user's password, instead of requiring the associated plaintext password.
Read definition →Passkey
A digital credential tied to a user account and a specific website or application, replacing the need for passwords.
Read definition →Password Manager
A software application designed to store and manage online credentials.
Read definition →Phishing
What is Phishing? A simple explanation of how scammers use fake emails to steal your information.
Read definition →PKI
Public Key Infrastructure. A set of roles, policies, hardware, software and procedures needed to create, manage, distribute, use, store and revoke digital certificates.
Read definition →Principle of Least Privilege
The practice of limiting access rights for users to the bare minimum permissions they need to perform their work.
Read definition →RADIUS
A networking protocol that provides centralized Authentication, Authorization, and Accounting management for users who connect and use a network service.
Read definition →RDP (Remote Desktop Protocol)
A proprietary protocol developed by Microsoft which provides a user with a graphical interface to connect to another computer over a network connection.
Read definition →Rogue Access Point
A wireless access point that has been installed on a secure network without explicit authorization from a local network administrator.
Read definition →SaaS
Software as a Service. A method of software delivery and licensing in which software is accessed online via a subscription.
Read definition →Shoulder Surfing
The practice of spying on the user of an ATM, computer, or other electronic device in order to obtain their personal access information.
Read definition →SIEM
Security Information and Event Management. A solution that helps organizations recognize potential security threats and vulnerabilities before they have a chance to disrupt business operations.
Read definition →Single Sign-On (SSO)
An authentication scheme that allows a user to log in with a single ID and password to any of several related, yet independent, software systems.
Read definition →Sinkhole
A mechanism used to redirect malicious network traffic to a dead end, preventing it from reaching its intended destination.
Read definition →Smishing
A form of phishing that uses mobile phone text messages to lure victims into revealing personal information or downloading malware.
Read definition →SOAR
Security Orchestration, Automation, and Response. A solution stack of compatible software programs that allow an organization to collect data about security threats and respond to them automatically.
Read definition →Social Engineering
The psychological manipulation of people into performing actions or divulging confidential information.
Read definition →SQL Injection (SQLi)
A code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution.
Read definition →SSH (Secure Shell)
A cryptographic network protocol for operating network services securely over an unsecured network.
Read definition →SSL / TLS
Secure Sockets Layer and Transport Layer Security. Cryptographic protocols designed to provide communications security over a computer network.
Read definition →Subnet
A logical subdivision of an IP network. The practice of dividing a network into two or more networks is called subnetting.
Read definition →Syslogs
A standard for message logging. It allows separation of the software that generates messages, the system that stores them, and the software that reports and analyzes them.
Read definition →Tailgating
A physical security breach in which an unauthorized person follows an authorized person into a secured area.
Read definition →TCP/IP
The conceptual model and set of communications protocols used in the Internet and similar computer networks.
Read definition →The Dark Web
A part of the internet that isn't indexed by search engines and requires specific software, configurations, or authorization to access.
Read definition →True/False Positives & Negatives
Terms used to describe whether an alert correctly identified a threat (True Positive) or mistakenly flagged normal behavior (False Positive), or missed a threat (False Negative).
Read definition →UDP
A communications protocol that is primarily used for establishing low-latency and loss-tolerating connections between applications on the internet.
Read definition →Virtual Machine (VM)
An emulation of a computer system. Virtual machines are based on computer architectures and provide functionality of a physical computer.
Read definition →VLAN (Virtual LAN)
Any broadcast domain that is partitioned and isolated in a computer network at the data link layer.
Read definition →VPN (Virtual Private Network)
A tool that hides your internet activity from snoops and makes it look like you are browsing from a different location.
Read definition →Whaling
A specific kind of phishing attack that is targeted at high-profile executives like the CEO or CFO of a company.
Read definition →Zero Trust
A security framework requiring all users, whether in or outside the organization's network, to be authenticated, authorized, and continuously validated.
Read definition →Zero-Day
A brand-new flaw in a software program that hackers discover before the software creator even knows it exists.
Read definition →