Glossary term

Attack Surface

The total set of points where an unauthorised user can attempt to enter or extract data: exposed ports, endpoints, features, credentials and physical access paths.

Browse the glossary →

Related entries

More glossary terms

Multi-Factor Authentication (MFA)
Requiring two or more independent factors, something you know, have and are, so a stolen password alone cannot grant access to an account.
Server-Side Request Forgery (SSRF)
Coercing the server into making a request to a destination of the attacker's choosing, typically to reach internal services or cloud metadata endpoint...
Patch Management
The process of identifying, testing and deploying updates across an estate on a defined schedule, with exceptions tracked rather than silently skipped...
Principle of Least Privilege
Every account, process and token receives only the minimum permissions required for its task, for the minimum time required, and no more.
Command and Control (C2)
The infrastructure an attacker uses to send instructions to compromised hosts and receive data back. Modern C2 blends into normal HTTPS traffic to avo...
← Back to glossary

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used