Glossary


Access Control

The rules that determine who or what can access a system, resource, or piece of data.

Adversary

A person, group, or organization attempting to compromise a system, steal information, or cause damage.

API

Application Programming Interface — a way for different software programs to communicate with each other.

Attack Surface

Everything about a system that could potentially be attacked, including open ports, applications, login pages, APIs, and exposed services.

Authentication

Proving that you are who you claim to be, usually with a password, code, security key, or biometric such as a fingerprint.

Authorization

Determining what you’re allowed to access or do after you’ve been authenticated.

Authentication: “Who are you?”
Authorization: “What are you allowed to access?”


Backdoor

A hidden method of accessing a system that bypasses normal authentication or security controls.

Backup

A separate copy of important data that can be restored if the original is deleted, corrupted, encrypted, or destroyed.

Bot

A program that automatically performs tasks. Attackers may use bots to scan systems, send spam, or perform attacks.

Botnet

A network of compromised devices controlled by an attacker, often without the owners knowing.

Brute Force

Trying many possible passwords, keys, or combinations until the correct one is found.

Buffer Overflow

A vulnerability that occurs when a program writes more data into memory than the allocated space can hold, potentially allowing unexpected behavior or code execution.


CIA Triad

The three fundamental goals of information security:

  • Confidentiality — keeping information private.
  • Integrity — keeping information accurate and unaltered.
  • Availability — keeping systems and information accessible when needed.

CAPTCHA

A test designed to distinguish humans from automated programs, commonly used to reduce automated abuse.

Certificate

A digital document used to prove the identity of a website, server, or other system and help establish encrypted connections.

Command Injection

A vulnerability where an attacker causes a system to execute unintended operating-system commands.

Cookie

A small piece of data stored by a website in a user’s browser, often used for preferences, sessions, or authentication.

CVE

Common Vulnerabilities and Exposures — a standardized identifier assigned to publicly known cybersecurity vulnerabilities.

Example: CVE-2026-XXXX

CVSS

Common Vulnerability Scoring System — a framework used to describe the severity of a vulnerability using a numerical score and other factors.

Cryptography

The science of protecting information using mathematical techniques such as encryption, hashing, and digital signatures.


DDoS

Distributed Denial of Service — an attack in which many systems send traffic or requests toward a service in an attempt to make it unavailable to legitimate users.

Data Breach

An incident where sensitive, confidential, or protected information is accessed, exposed, or stolen without authorization.

Data Exfiltration

The unauthorized transfer of data from a system or network to another location.

Defense in Depth

Using multiple layers of security so that if one security control fails, others can still provide protection.

Digital Certificate

A digital credential used to establish trust and help verify the identity of a website, server, or organization.

DNS

Domain Name System — the system that translates human-readable domain names such as example.com into IP addresses.

DNS Spoofing

An attack that attempts to provide false DNS information, potentially directing users to an unintended destination.


Encryption

Transforming readable data into an unreadable form using an encryption algorithm and key so that only authorized parties can recover the original information.

Endpoint

A device connected to a network, such as a laptop, phone, server, or workstation.

Endpoint Detection and Response (EDR)

Security software that monitors endpoint devices for suspicious activity and helps security teams investigate and respond to threats.

Exploit

A technique, code, or method that takes advantage of a vulnerability.

Exposure

A situation where a system, service, or piece of information is accessible in a way that could create security risk.


Firewall

A security control that monitors and filters network traffic according to defined rules.

Firmware

Low-level software built into a device, such as a router, printer, camera, or network appliance.

File Integrity

The assurance that a file has not been unexpectedly modified or corrupted.

Fuzzing

Testing software by providing unexpected, malformed, or unusual inputs to discover crashes and potential vulnerabilities.


Gateway

A device or system that connects different networks and can control or route traffic between them.

GDPR

General Data Protection Regulation — a European Union data-protection law governing how organizations handle personal data.

Gray Hat

A person who may discover or test vulnerabilities without authorization but does not necessarily have the same malicious intent associated with a black-hat attacker.


Hacker

A person who uses technical knowledge to explore, modify, analyze, or gain access to computer systems. The term itself does not always mean a criminal.

Hash

A fixed-length value generated from data using a hashing algorithm. The same input normally produces the same hash, and secure cryptographic hashes are designed to make recovering the original input computationally impractical.

Hashing

The process of converting data into a fixed-length hash value.

Honeypot

A deliberately exposed or simulated system designed to attract suspicious activity so defenders can observe and analyze attackers.

HTTP

Hypertext Transfer Protocol — a protocol used to transfer information between web clients and servers.

HTTPS

HTTP Secure — HTTP protected using TLS encryption.


Identity

Information used to represent a person, device, application, or other entity within a system.

Incident

A security-related event that may compromise the confidentiality, integrity, or availability of systems or information.

Incident Response

The process of detecting, containing, investigating, removing, and recovering from a security incident.

Indicator of Compromise (IOC)

A piece of evidence that may indicate a system has been compromised, such as a suspicious file hash, IP address, domain, or process.

IDS

Intrusion Detection System — a security system that monitors activity and alerts when it detects potentially malicious behavior.

IPS

Intrusion Prevention System — a security system that can detect and actively block suspicious network activity.

IP Address

A numerical address used to identify a device or network interface on a network.


JWT

JSON Web Token — a compact token format commonly used to securely transmit claims between systems. JWTs can be digitally signed to verify their integrity and authenticity; signing does not automatically encrypt the information inside them.

Jailbreaking

Removing restrictions imposed by a device’s manufacturer or operating system, sometimes creating additional security risks.


Key

A value used by cryptographic algorithms to encrypt, decrypt, sign, or verify information.

Keylogger

Software or hardware designed to record keystrokes. Attackers may use keyloggers to capture passwords and other sensitive information.

Kill Chain

A framework describing the stages an attacker may go through during a cyberattack, from initial reconnaissance to achieving their objective.


Least Privilege

Giving a person, application, or system only the permissions it needs to perform its task—and no more.

Log

A record of events generated by a computer system, application, device, or network.

Logging

The process of recording system and security events so they can later be monitored or investigated.

Lateral Movement

The process of moving from one compromised system or account to another within a network.

Localhost

A hostname that refers to the computer you’re currently using. It commonly resolves to 127.0.0.1 in IPv4 environments.


Malware

Software intentionally designed to disrupt, damage, spy on, steal from, or gain unauthorized access to systems.

Man-in-the-Middle (MitM)

An attack where an attacker positions themselves between two communicating parties and attempts to intercept or manipulate their communication.

MFA

Multi-Factor Authentication — requiring two or more different types of authentication factors to verify a user’s identity.

Misconfiguration

An incorrectly or insecurely configured system, application, server, cloud service, or network device.

MAC Address

A hardware-level network address associated with a network interface.

Memory

Computer storage used by running programs to temporarily hold instructions and data.


Network

A group of connected computers and devices that can communicate with each other.

Network Segmentation

Dividing a network into separate zones or segments to limit access and reduce the impact of a compromise.

Network Traffic

The data moving between devices across a network.

Non-Repudiation

A security property that helps provide evidence that a particular action or communication came from a specific party and was not later denied.


OAuth

An authorization framework that allows an application to obtain limited access to resources without requiring the user to share their password with that application.

Open Source

Software whose source code is made available under a license that permits specified forms of inspection, modification, and redistribution.

OSINT

Open-Source Intelligence — collecting and analyzing information from publicly available sources such as websites, public records, social media, and news.

Operating System

The core software that manages a computer’s hardware, applications, files, memory, and other resources.


Patch

A software update that fixes bugs, security vulnerabilities, or other problems.

Patch Management

The process of identifying, testing, deploying, and monitoring software updates.

Payload

The part of an attack or malicious program responsible for carrying out the attacker’s intended action after successful exploitation.

Penetration Testing

An authorized security assessment in which testers simulate attacks against systems to identify and validate vulnerabilities.

Phishing

A social-engineering technique that tricks people into revealing information, opening malicious content, or performing an unwanted action.

Port

A numbered logical endpoint used by network services to communicate.

For example, 443 is commonly associated with HTTPS.

Privilege Escalation

Gaining higher levels of access or permissions than were originally authorized.

Proxy

A server or service that acts as an intermediary between a client and another server.

Public Key

A cryptographic key designed to be shared publicly and used in systems such as public-key encryption and digital signatures.


Quarantine

Isolating a suspicious or infected file, device, or system so it cannot cause further harm while it is investigated.

Query

A request for information from a database, search system, or other service.

QR Code Phishing

A phishing technique that uses malicious QR codes to direct victims toward fraudulent websites or other unwanted destinations.


Ransomware

Malware that prevents access to systems or data—often by encrypting files—and demands payment from the victim.

Reconnaissance

The information-gathering stage of security testing or an attack, such as identifying domains, systems, technologies, or publicly available information.

Red Team

A security team authorized to simulate realistic attacks in order to test an organization’s defenses.

Reverse Engineering

Analyzing software, hardware, or malware to understand how it works.

Risk

The possibility that a threat will exploit a vulnerability and cause harm.

Rootkit

Malicious software designed to maintain unauthorized access while attempting to hide its presence.

Root

A highly privileged account on Unix/Linux systems with extensive control over the operating system.


Salting

Adding unique random data to a password before hashing it. Salting helps prevent attackers from using precomputed tables and ensures identical passwords do not produce identical stored hashes.

Sandbox

An isolated environment used to safely execute or analyze software without exposing the main system to unnecessary risk.

Scanning

Automatically checking systems, networks, or applications for open ports, services, vulnerabilities, or other characteristics.

Security Information and Event Management (SIEM)

A security platform that collects and analyzes logs and events from many systems to help detect and investigate threats.

Session

A period of interaction between a user and an application, often tracked using a session identifier or token.

Session Hijacking

An attack in which an attacker obtains or takes control of a user’s active session.

Social Engineering

Manipulating people into revealing information, granting access, or performing actions that compromise security.

SQL Injection

A vulnerability where untrusted input is incorporated into database queries in an unsafe way, potentially allowing an attacker to alter the intended query.

SSL

Secure Sockets Layer — an older protocol for securing network communication. Modern systems generally use TLS instead.

Subnet

A logical division of an IP network used to organize and control network communication.

Supply Chain Attack

An attack that compromises software, hardware, services, or another component somewhere in the supply chain to affect its users.

Symmetric Encryption

Encryption where the same secret key is used for both encryption and decryption.


TCP

Transmission Control Protocol — a connection-oriented network protocol designed to deliver data reliably.

Threat

Anything capable of causing harm to a system, organization, or piece of information.

Threat Actor

An individual, group, or organization responsible for or attempting to conduct malicious activity.

Threat Intelligence

Information about threats, attackers, techniques, indicators, and vulnerabilities that helps organizations make security decisions.

TLS

Transport Layer Security — a cryptographic protocol used to protect data transmitted over networks, including HTTPS connections.

Token

A piece of data used to represent authorization, authentication, or a particular session.

Two-Factor Authentication (2FA)

A form of MFA that specifically requires two different authentication factors.


UDP

User Datagram Protocol — a connectionless network protocol that prioritizes speed and simplicity over guaranteed delivery.

Unpatched

Software that has not received an available security fix, potentially leaving a known vulnerability exposed.

URL

Uniform Resource Locator — the address used to locate a resource on the internet.

User Enumeration

A situation where an application unintentionally reveals whether a particular username or account exists.


Virus

Malware that can attach itself to legitimate files or programs and replicate when the infected file or program is executed.

Virtual Machine (VM)

A software-based computer that runs inside another physical computer.

VPN

Virtual Private Network — a technology that creates an encrypted connection between a device and a VPN server. It can protect traffic from local network observers, but it does not make a user completely anonymous.

Vulnerability

A weakness in software, hardware, configuration, or a process that could potentially be exploited.

Vulnerability Assessment

The process of identifying and analyzing security weaknesses in systems or applications.


Watering Hole Attack

An attack where compromised or malicious content is placed on a website likely to be visited by a particular group of targets.

Whitelist / Allowlist

A list of explicitly permitted users, applications, addresses, or actions. Anything not permitted by the rules may be blocked.

WHOIS

A service historically used to retrieve registration information about domain names and network resources. Availability of specific registration details varies by registry and privacy rules.

Worm

Malware capable of spreading from one system to another without necessarily requiring a user to manually execute an infected file.


XSS

Cross-Site Scripting — a vulnerability where attacker-controlled content can cause unintended JavaScript or other script code to execute in a victim’s browser.

XML

Extensible Markup Language — a format used to structure and exchange data. Insecure XML processing can create security vulnerabilities such as XXE.

XXE

XML External Entity — a vulnerability caused by unsafe processing of XML external entities, potentially allowing unauthorized access to files or other resources.


YARA

A tool and rule language used by security researchers to identify and classify files or malware based on patterns.

YARA Rule

A set of patterns and conditions used to identify files or activity matching characteristics of interest, often in malware analysis.


Zero-Day

A previously unknown or unaddressed vulnerability for which a security fix may not yet be available. The term can also refer to an attack exploiting such a vulnerability.

Zero Trust

A security approach based on the principle of “never trust, always verify.” Access is continuously evaluated rather than automatically trusted based only on network location.

Zombie

A compromised computer or device controlled by an attacker, often as part of a botnet.


Quick Reference


Keep Learning

Don’t try to memorize everything at once.

As you move through Cipherora’s lessons, return to this glossary whenever you encounter an unfamiliar term. Understanding the language of cybersecurity makes the technical concepts much easier to understand.