Security Glossary

12 plain-language definitions for the terms you will meet in reports, advisories and scanner output.

A

Attack Surface
The total set of points where an unauthorised user can attempt to enter or extract data: exposed ports, endpoints, features, credentials and physical access paths.

C

Command and Control (C2)
The infrastructure an attacker uses to send instructions to compromised hosts and receive data back. Modern C2 blends into normal HTTPS traffic to avoid detection.
Browse Attack Techniques
Cross-Site Scripting (XSS)
Injecting script into a page so it runs in another user's browser session, enabling cookie theft, page rewriting and credential capture.
Browse Vulnerabilities
CVE
Common Vulnerabilities and Exposures. A public identifier such as CVE-2021-44228 assigned to a specific vulnerability, giving everyone one unambiguous name to reference.
Browse Vulnerabilities
CVSS
Common Vulnerability Scoring System. A 0 to 10 severity score built from exploitability and impact metrics, used to prioritise patching alongside context.
Browse Vulnerabilities
CWE
Common Weakness Enumeration. A catalogue of the underlying defect class, for example CWE-89 for SQL injection, independent of any particular product or version.
Browse Vulnerabilities

I

Indicator of Compromise (IoC)
A forensic artefact that suggests a system was breached: a file hash, a suspicious domain, an unusual registry key or a known-bad IP address.
Browse Vulnerabilities

M

Multi-Factor Authentication (MFA)
Requiring two or more independent factors, something you know, have and are, so a stolen password alone cannot grant access to an account.

P

Patch Management
The process of identifying, testing and deploying updates across an estate on a defined schedule, with exceptions tracked rather than silently skipped.
Principle of Least Privilege
Every account, process and token receives only the minimum permissions required for its task, for the minimum time required, and no more.

S

Server-Side Request Forgery (SSRF)
Coercing the server into making a request to a destination of the attacker's choosing, typically to reach internal services or cloud metadata endpoints.
Browse Vulnerabilities

Z

Zero-Day
A vulnerability being exploited before the vendor has a patch available, so defenders have had zero days to prepare. Once a patch exists it is no longer a zero-day.
Browse Attack Techniques

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used