A
- Attack Surface
- The total set of points where an unauthorised user can attempt to enter or extract data: exposed ports, endpoints, features, credentials and physical access paths.
C
- Command and Control (C2)
- The infrastructure an attacker uses to send instructions to compromised hosts and receive data back. Modern C2 blends into normal HTTPS traffic to avoid detection. Browse Attack Techniques
- Cross-Site Scripting (XSS)
- Injecting script into a page so it runs in another user's browser session, enabling cookie theft, page rewriting and credential capture. Browse Vulnerabilities
- CVE
- Common Vulnerabilities and Exposures. A public identifier such as CVE-2021-44228 assigned to a specific vulnerability, giving everyone one unambiguous name to reference. Browse Vulnerabilities
- CVSS
- Common Vulnerability Scoring System. A 0 to 10 severity score built from exploitability and impact metrics, used to prioritise patching alongside context. Browse Vulnerabilities
- CWE
- Common Weakness Enumeration. A catalogue of the underlying defect class, for example CWE-89 for SQL injection, independent of any particular product or version. Browse Vulnerabilities
I
- Indicator of Compromise (IoC)
- A forensic artefact that suggests a system was breached: a file hash, a suspicious domain, an unusual registry key or a known-bad IP address. Browse Vulnerabilities
M
- Multi-Factor Authentication (MFA)
- Requiring two or more independent factors, something you know, have and are, so a stolen password alone cannot grant access to an account.
P
- Patch Management
- The process of identifying, testing and deploying updates across an estate on a defined schedule, with exceptions tracked rather than silently skipped.
- Principle of Least Privilege
- Every account, process and token receives only the minimum permissions required for its task, for the minimum time required, and no more.
S
- Server-Side Request Forgery (SSRF)
- Coercing the server into making a request to a destination of the attacker's choosing, typically to reach internal services or cloud metadata endpoints. Browse Vulnerabilities
Z
- Zero-Day
- A vulnerability being exploited before the vendor has a patch available, so defenders have had zero days to prepare. Once a patch exists it is no longer a zero-day. Browse Attack Techniques