CYBERSECURITY KNOWLEDGE BASE

Cybersecurity Glossary.

Understand the terminology behind cybersecurity, networking, ethical hacking, penetration testing, digital forensics, and defensive security.

60+CORE TERMS
11CATEGORIES
A–ZINDEX
KNOWLEDGE BASE

Explore the terminology.

Use the alphabetical index to navigate through common cybersecurity concepts.

A
Security Fundamentals

Access Control

A security mechanism that determines who or what is allowed to access a resource, system, or information.

Windows Security

Active Directory

A Microsoft directory service used to manage users, computers, groups, policies, and resources within a Windows domain environment.

Security

Attack Surface

The collection of points where an unauthorized user could potentially attempt to interact with or compromise a system.

Identity

Authentication

The process of verifying the identity of a user, device, application, or system.

Identity

Authorization

The process of determining what an authenticated identity is permitted to access or perform.

B
Threats

Backdoor

A mechanism that can provide access to a system while bypassing normal authentication or security controls.

Authentication

Brute Force

A technique that attempts many possible credentials or values until a valid one is discovered.

Web Security

Burp Suite

A collection of tools commonly used for testing and analyzing web applications.

C
Security Fundamentals

CIA Triad

A foundational security model consisting of Confidentiality, Integrity, and Availability.

Cryptography

Cryptography

The study and application of techniques used to protect information through mathematical transformations and security protocols.

Vulnerability Management

CVE

Common Vulnerabilities and Exposures is a system for identifying publicly known cybersecurity vulnerabilities.

Vulnerability Management

CVSS

Common Vulnerability Scoring System provides a standardized framework for describing and scoring the severity of vulnerabilities.

D
Network Security

DDoS

Distributed Denial-of-Service is an attack in which multiple systems generate traffic or requests intended to make a service unavailable.

Forensics

Digital Forensics

The process of collecting, preserving, examining, and analyzing digital evidence.

Networking

DNS

Domain Name System translates domain names into IP addresses and supports name resolution across networks.

E
Blue Team

EDR

Endpoint Detection and Response technology monitors endpoint activity to help detect, investigate, and respond to security threats.

Cryptography

Encryption

The process of transforming readable information into a protected form that requires appropriate cryptographic information to recover.

Offensive Security

Ethical Hacking

Authorized security testing performed to identify weaknesses and improve the security of systems.

F
Network Security

Firewall

A security control that monitors and controls network traffic according to defined rules.

Networking

FTP

File Transfer Protocol is a network protocol designed for transferring files between systems.

H
Cryptography

Hashing

A one-way transformation that produces a fixed-length value from input data.

Defense

Honeypot

A deliberately exposed or simulated system designed to attract, detect, or study unauthorized activity.

Web

HTTP

Hypertext Transfer Protocol is a foundational protocol used for communication between web clients and servers.

Web Security

HTTPS

HTTP communication protected using TLS encryption.

I
Network Security

IDS

Intrusion Detection System monitors activity and generates alerts when potentially malicious or suspicious behavior is detected.

Network Security

IPS

Intrusion Prevention System detects potentially malicious traffic and can take action to block or prevent it.

Blue Team

Incident Response

The organized process of detecting, analyzing, containing, and recovering from cybersecurity incidents.

K
Security Tools

Kali Linux

A Linux distribution designed for security testing, digital forensics, research, and related cybersecurity tasks.

Authentication

Kerberos

A network authentication protocol that uses tickets and cryptographic mechanisms to authenticate identities.

L
Identity

LDAP

Lightweight Directory Access Protocol is used to access and manage directory information.

Security Principles

Least Privilege

A principle where users, applications, and systems receive only the permissions required to perform their intended tasks.

Offensive Security

Linux Privilege Escalation

The process of identifying authorized paths through which a lower-privileged Linux context could obtain higher privileges.

M
Threats

Malware

Malicious software designed to perform unauthorized or harmful actions.

Threat Intelligence

MITRE ATT&CK

A knowledge base that organizes adversary tactics, techniques, and procedures observed in real-world attacks.

Authentication

MFA

Multi-Factor Authentication requires multiple authentication factors to verify an identity.

N
Networking

NAT

Network Address Translation modifies network address information as traffic passes between networks.

Security Tools

Nmap

A network discovery and security auditing tool commonly used to identify hosts, services, and network characteristics in authorized environments.

Network Security

Network Segmentation

The practice of dividing a network into separate segments to control communication and reduce security risk.

O
Web Security

OAuth

An authorization framework that enables applications to obtain limited access to resources without directly handling a user's credentials.

Web Security

OWASP

An organization that provides open resources, projects, standards, and educational material focused on application security.

Web Security

OWASP Top 10

A widely used awareness resource describing important categories of web application security risks.

P
Offensive Security

Penetration Testing

An authorized security assessment in which controlled testing is performed to identify and validate security weaknesses.

Social Engineering

Phishing

A social-engineering technique that attempts to trick people into revealing information or performing an unintended action.

Offensive Security

Privilege Escalation

The process of obtaining permissions beyond those initially available to an account or process.

Networking

Proxy

An intermediary that receives and forwards requests between a client and another system or service.

R
Threats

Ransomware

Malicious software that typically prevents access to data or systems and demands some form of payment or action.

Offensive Security

Reconnaissance

The information-gathering phase of a security assessment used to understand the authorized target environment.

Security Research

Reverse Engineering

The process of analyzing software or systems to understand their internal structure and behavior.

S
Blue Team

SIEM

Security Information and Event Management systems collect, correlate, analyze, and present security-related events and logs.

Security

Social Engineering

The use of psychological or social manipulation to influence people into revealing information or performing actions.

Web Security

SQL Injection

A class of vulnerability where untrusted input can interfere with the intended structure of a database query.

Networking

SSH

Secure Shell is a protocol commonly used for secure remote administration and communication.

Cryptography

SSL/TLS

Cryptographic protocols used to provide confidentiality, integrity, and authentication for network communication.

T
Security

Threat Intelligence

Information and analysis about threats that can help organizations understand, detect, and respond to security risks.

Cryptography

TLS

Transport Layer Security is a cryptographic protocol used to secure communications over networks.

Authentication

Token

A value used by an application or protocol to represent authentication, authorization, or a session context.

V
Security

Vulnerability

A weakness in a system, application, process, or configuration that could potentially be exploited.

Security Testing

Vulnerability Assessment

A process used to identify, analyze, and prioritize vulnerabilities in an authorized environment.

Network Security

VPN

Virtual Private Network technology creates a protected communication path across an underlying network.

W
Web Security

WAF

Web Application Firewall monitors and filters HTTP traffic to help protect web applications from malicious requests.

Network Analysis

Wireshark

A network protocol analyzer used to capture and inspect network traffic in authorized environments.

Web Security

Web Application Security

The practice of identifying and mitigating security risks in applications delivered through web technologies.

X
Web Security

XSS

Cross-Site Scripting is a class of web vulnerability where attacker-controlled content can execute in a victim's browser context.

KEEP LEARNING

Know the terms. Follow the roadmap.

The glossary explains the terminology. The roadmap shows you when and where these concepts fit into your cybersecurity learning journey.

Open Roadmap