Cybersecurity Glossary

Terms and definitions from the world of information security

27 terms6 categories

Pentest & Red Team

5 terms

Penetration testing, attack methodologies, Red Team operations

Vulnerabilities

5 terms

CVE, OWASP Top 10, vulnerability types and classification

Attack Types

5 terms

DDoS, phishing, malware, social engineering

Standards & Compliance

3 terms

ISO 27001, PCI DSS, GDPR, SOC 2, regulatory requirements

Tools

4 terms

Burp Suite, Nmap, Metasploit, pentest and audit tools

All Terms

Penetration Testing

Controlled cyber attack simulation to assess system security

Red Team

Team of specialists simulating actions of real attackers

Vulnerability Assessment

Systematic process of identifying and classifying vulnerabilities in systems

Ethical Hacking

Legal use of hacking techniques to improve security

Social Engineering

Manipulation techniques to obtain confidential information from people

CVE (Common Vulnerabilities and Exposures)

Standardized system for identifying security vulnerabilities

Zero-Day (0-day)

Vulnerability unknown to the developer with no available patch

OWASP Top 10

List of 10 most critical web application security risks

SQL Injection (SQLi)

Attack injecting malicious SQL code through user input

XSS (Cross-Site Scripting)

Injection of malicious JavaScript code into web pages

DDoS Attack

Distributed Denial of Service attack

Phishing

Fraud aimed at stealing credentials through fake sites and emails

Ransomware

Malicious software that encrypts data and demands ransom

APT (Advanced Persistent Threat)

Long-term targeted cyber attack sponsored by a state or organization

MITM (Man-in-the-Middle)

Attack intercepting and modifying traffic between two parties

WAF (Web Application Firewall)

Firewall for protecting web applications from attacks

SIEM (Security Information and Event Management)

System for collecting, analyzing and correlating security events

SOC (Security Operations Center)

Center for monitoring and responding to security incidents 24/7

EDR (Endpoint Detection and Response)

Solution for detecting and responding to threats on endpoints

MFA (Multi-Factor Authentication)

Security method requiring multiple ways to verify identity

ISO 27001

International standard for information security management systems

PCI DSS

Payment Card Industry Data Security Standard

GDPR (General Data Protection Regulation)

European regulation on personal data protection

Burp Suite

Professional platform for web application security testing

Nmap

Network scanner for discovering hosts and services

Metasploit Framework

Platform for developing and executing exploits

Wireshark

Network protocol and packet analyzer