Security has its own language.
This glossary collects the cybersecurity terms you’ll encounter across Cipherora, explained in plain English with no assumed background. Start with the basics, then explore the terms you meet as you work through the lessons and labs.
A
Access Control
The rules that determine who or what can access a system, resource, or piece of data.
Adversary
A person, group, or organization attempting to compromise a system, steal information, or cause damage.
API
Application Programming Interface — a way for different software programs to communicate with each other.
Attack Surface
Everything about a system that could potentially be attacked, including open ports, applications, login pages, APIs, and exposed services.
Authentication
Proving that you are who you claim to be, usually with a password, code, security key, or biometric such as a fingerprint.
Authorization
Determining what you’re allowed to access or do after you’ve been authenticated.
Authentication: “Who are you?”
Authorization: “What are you allowed to access?”
B
Backdoor
A hidden method of accessing a system that bypasses normal authentication or security controls.
Backup
A separate copy of important data that can be restored if the original is deleted, corrupted, encrypted, or destroyed.
Bot
A program that automatically performs tasks. Attackers may use bots to scan systems, send spam, or perform attacks.
Botnet
A network of compromised devices controlled by an attacker, often without the owners knowing.
Brute Force
Trying many possible passwords, keys, or combinations until the correct one is found.
Buffer Overflow
A vulnerability that occurs when a program writes more data into memory than the allocated space can hold, potentially allowing unexpected behavior or code execution.
C
CIA Triad
The three fundamental goals of information security:
- Confidentiality — keeping information private.
- Integrity — keeping information accurate and unaltered.
- Availability — keeping systems and information accessible when needed.
CAPTCHA
A test designed to distinguish humans from automated programs, commonly used to reduce automated abuse.
Certificate
A digital document used to prove the identity of a website, server, or other system and help establish encrypted connections.
Command Injection
A vulnerability where an attacker causes a system to execute unintended operating-system commands.
Cookie
A small piece of data stored by a website in a user’s browser, often used for preferences, sessions, or authentication.
CVE
Common Vulnerabilities and Exposures — a standardized identifier assigned to publicly known cybersecurity vulnerabilities.
Example: CVE-2026-XXXX
CVSS
Common Vulnerability Scoring System — a framework used to describe the severity of a vulnerability using a numerical score and other factors.
Cryptography
The science of protecting information using mathematical techniques such as encryption, hashing, and digital signatures.
D
DDoS
Distributed Denial of Service — an attack in which many systems send traffic or requests toward a service in an attempt to make it unavailable to legitimate users.
Data Breach
An incident where sensitive, confidential, or protected information is accessed, exposed, or stolen without authorization.
Data Exfiltration
The unauthorized transfer of data from a system or network to another location.
Defense in Depth
Using multiple layers of security so that if one security control fails, others can still provide protection.
Digital Certificate
A digital credential used to establish trust and help verify the identity of a website, server, or organization.
DNS
Domain Name System — the system that translates human-readable domain names such as example.com into IP addresses.
DNS Spoofing
An attack that attempts to provide false DNS information, potentially directing users to an unintended destination.
E
Encryption
Transforming readable data into an unreadable form using an encryption algorithm and key so that only authorized parties can recover the original information.
Endpoint
A device connected to a network, such as a laptop, phone, server, or workstation.
Endpoint Detection and Response (EDR)
Security software that monitors endpoint devices for suspicious activity and helps security teams investigate and respond to threats.
Exploit
A technique, code, or method that takes advantage of a vulnerability.
Exposure
A situation where a system, service, or piece of information is accessible in a way that could create security risk.
F
Firewall
A security control that monitors and filters network traffic according to defined rules.
Firmware
Low-level software built into a device, such as a router, printer, camera, or network appliance.
File Integrity
The assurance that a file has not been unexpectedly modified or corrupted.
Fuzzing
Testing software by providing unexpected, malformed, or unusual inputs to discover crashes and potential vulnerabilities.
G
Gateway
A device or system that connects different networks and can control or route traffic between them.
GDPR
General Data Protection Regulation — a European Union data-protection law governing how organizations handle personal data.
Gray Hat
A person who may discover or test vulnerabilities without authorization but does not necessarily have the same malicious intent associated with a black-hat attacker.
H
Hacker
A person who uses technical knowledge to explore, modify, analyze, or gain access to computer systems. The term itself does not always mean a criminal.
Hash
A fixed-length value generated from data using a hashing algorithm. The same input normally produces the same hash, and secure cryptographic hashes are designed to make recovering the original input computationally impractical.
Hashing
The process of converting data into a fixed-length hash value.
Honeypot
A deliberately exposed or simulated system designed to attract suspicious activity so defenders can observe and analyze attackers.
HTTP
Hypertext Transfer Protocol — a protocol used to transfer information between web clients and servers.
HTTPS
HTTP Secure — HTTP protected using TLS encryption.
I
Identity
Information used to represent a person, device, application, or other entity within a system.
Incident
A security-related event that may compromise the confidentiality, integrity, or availability of systems or information.
Incident Response
The process of detecting, containing, investigating, removing, and recovering from a security incident.
Indicator of Compromise (IOC)
A piece of evidence that may indicate a system has been compromised, such as a suspicious file hash, IP address, domain, or process.
IDS
Intrusion Detection System — a security system that monitors activity and alerts when it detects potentially malicious behavior.
IPS
Intrusion Prevention System — a security system that can detect and actively block suspicious network activity.
IP Address
A numerical address used to identify a device or network interface on a network.
J
JWT
JSON Web Token — a compact token format commonly used to securely transmit claims between systems. JWTs can be digitally signed to verify their integrity and authenticity; signing does not automatically encrypt the information inside them.
Jailbreaking
Removing restrictions imposed by a device’s manufacturer or operating system, sometimes creating additional security risks.
K
Key
A value used by cryptographic algorithms to encrypt, decrypt, sign, or verify information.
Keylogger
Software or hardware designed to record keystrokes. Attackers may use keyloggers to capture passwords and other sensitive information.
Kill Chain
A framework describing the stages an attacker may go through during a cyberattack, from initial reconnaissance to achieving their objective.
L
Least Privilege
Giving a person, application, or system only the permissions it needs to perform its task—and no more.
Log
A record of events generated by a computer system, application, device, or network.
Logging
The process of recording system and security events so they can later be monitored or investigated.
Lateral Movement
The process of moving from one compromised system or account to another within a network.
Localhost
A hostname that refers to the computer you’re currently using. It commonly resolves to 127.0.0.1 in IPv4 environments.
M
Malware
Software intentionally designed to disrupt, damage, spy on, steal from, or gain unauthorized access to systems.
Man-in-the-Middle (MitM)
An attack where an attacker positions themselves between two communicating parties and attempts to intercept or manipulate their communication.
MFA
Multi-Factor Authentication — requiring two or more different types of authentication factors to verify a user’s identity.
Misconfiguration
An incorrectly or insecurely configured system, application, server, cloud service, or network device.
MAC Address
A hardware-level network address associated with a network interface.
Memory
Computer storage used by running programs to temporarily hold instructions and data.
N
Network
A group of connected computers and devices that can communicate with each other.
Network Segmentation
Dividing a network into separate zones or segments to limit access and reduce the impact of a compromise.
Network Traffic
The data moving between devices across a network.
Non-Repudiation
A security property that helps provide evidence that a particular action or communication came from a specific party and was not later denied.
O
OAuth
An authorization framework that allows an application to obtain limited access to resources without requiring the user to share their password with that application.
Open Source
Software whose source code is made available under a license that permits specified forms of inspection, modification, and redistribution.
OSINT
Open-Source Intelligence — collecting and analyzing information from publicly available sources such as websites, public records, social media, and news.
Operating System
The core software that manages a computer’s hardware, applications, files, memory, and other resources.
P
Patch
A software update that fixes bugs, security vulnerabilities, or other problems.
Patch Management
The process of identifying, testing, deploying, and monitoring software updates.
Payload
The part of an attack or malicious program responsible for carrying out the attacker’s intended action after successful exploitation.
Penetration Testing
An authorized security assessment in which testers simulate attacks against systems to identify and validate vulnerabilities.
Phishing
A social-engineering technique that tricks people into revealing information, opening malicious content, or performing an unwanted action.
Port
A numbered logical endpoint used by network services to communicate.
For example, 443 is commonly associated with HTTPS.
Privilege Escalation
Gaining higher levels of access or permissions than were originally authorized.
Proxy
A server or service that acts as an intermediary between a client and another server.
Public Key
A cryptographic key designed to be shared publicly and used in systems such as public-key encryption and digital signatures.
Q
Quarantine
Isolating a suspicious or infected file, device, or system so it cannot cause further harm while it is investigated.
Query
A request for information from a database, search system, or other service.
QR Code Phishing
A phishing technique that uses malicious QR codes to direct victims toward fraudulent websites or other unwanted destinations.
R
Ransomware
Malware that prevents access to systems or data—often by encrypting files—and demands payment from the victim.
Reconnaissance
The information-gathering stage of security testing or an attack, such as identifying domains, systems, technologies, or publicly available information.
Red Team
A security team authorized to simulate realistic attacks in order to test an organization’s defenses.
Reverse Engineering
Analyzing software, hardware, or malware to understand how it works.
Risk
The possibility that a threat will exploit a vulnerability and cause harm.
Rootkit
Malicious software designed to maintain unauthorized access while attempting to hide its presence.
Root
A highly privileged account on Unix/Linux systems with extensive control over the operating system.
S
Salting
Adding unique random data to a password before hashing it. Salting helps prevent attackers from using precomputed tables and ensures identical passwords do not produce identical stored hashes.
Sandbox
An isolated environment used to safely execute or analyze software without exposing the main system to unnecessary risk.
Scanning
Automatically checking systems, networks, or applications for open ports, services, vulnerabilities, or other characteristics.
Security Information and Event Management (SIEM)
A security platform that collects and analyzes logs and events from many systems to help detect and investigate threats.
Session
A period of interaction between a user and an application, often tracked using a session identifier or token.
Session Hijacking
An attack in which an attacker obtains or takes control of a user’s active session.
Social Engineering
Manipulating people into revealing information, granting access, or performing actions that compromise security.
SQL Injection
A vulnerability where untrusted input is incorporated into database queries in an unsafe way, potentially allowing an attacker to alter the intended query.
SSL
Secure Sockets Layer — an older protocol for securing network communication. Modern systems generally use TLS instead.
Subnet
A logical division of an IP network used to organize and control network communication.
Supply Chain Attack
An attack that compromises software, hardware, services, or another component somewhere in the supply chain to affect its users.
Symmetric Encryption
Encryption where the same secret key is used for both encryption and decryption.
T
TCP
Transmission Control Protocol — a connection-oriented network protocol designed to deliver data reliably.
Threat
Anything capable of causing harm to a system, organization, or piece of information.
Threat Actor
An individual, group, or organization responsible for or attempting to conduct malicious activity.
Threat Intelligence
Information about threats, attackers, techniques, indicators, and vulnerabilities that helps organizations make security decisions.
TLS
Transport Layer Security — a cryptographic protocol used to protect data transmitted over networks, including HTTPS connections.
Token
A piece of data used to represent authorization, authentication, or a particular session.
Two-Factor Authentication (2FA)
A form of MFA that specifically requires two different authentication factors.
U
UDP
User Datagram Protocol — a connectionless network protocol that prioritizes speed and simplicity over guaranteed delivery.
Unpatched
Software that has not received an available security fix, potentially leaving a known vulnerability exposed.
URL
Uniform Resource Locator — the address used to locate a resource on the internet.
User Enumeration
A situation where an application unintentionally reveals whether a particular username or account exists.
V
Virus
Malware that can attach itself to legitimate files or programs and replicate when the infected file or program is executed.
Virtual Machine (VM)
A software-based computer that runs inside another physical computer.
VPN
Virtual Private Network — a technology that creates an encrypted connection between a device and a VPN server. It can protect traffic from local network observers, but it does not make a user completely anonymous.
Vulnerability
A weakness in software, hardware, configuration, or a process that could potentially be exploited.
Vulnerability Assessment
The process of identifying and analyzing security weaknesses in systems or applications.
W
Watering Hole Attack
An attack where compromised or malicious content is placed on a website likely to be visited by a particular group of targets.
Whitelist / Allowlist
A list of explicitly permitted users, applications, addresses, or actions. Anything not permitted by the rules may be blocked.
WHOIS
A service historically used to retrieve registration information about domain names and network resources. Availability of specific registration details varies by registry and privacy rules.
Worm
Malware capable of spreading from one system to another without necessarily requiring a user to manually execute an infected file.
X
XSS
Cross-Site Scripting — a vulnerability where attacker-controlled content can cause unintended JavaScript or other script code to execute in a victim’s browser.
XML
Extensible Markup Language — a format used to structure and exchange data. Insecure XML processing can create security vulnerabilities such as XXE.
XXE
XML External Entity — a vulnerability caused by unsafe processing of XML external entities, potentially allowing unauthorized access to files or other resources.
Y
YARA
A tool and rule language used by security researchers to identify and classify files or malware based on patterns.
YARA Rule
A set of patterns and conditions used to identify files or activity matching characteristics of interest, often in malware analysis.
Z
Zero-Day
A previously unknown or unaddressed vulnerability for which a security fix may not yet be available. The term can also refer to an attack exploiting such a vulnerability.
Zero Trust
A security approach based on the principle of “never trust, always verify.” Access is continuously evaluated rather than automatically trusted based only on network location.
Zombie
A compromised computer or device controlled by an attacker, often as part of a botnet.
Quick Reference
| Term | Simple Meaning |
|---|---|
| Authentication | Proving who you are |
| Authorization | What you’re allowed to access |
| Attack Surface | Things that could potentially be attacked |
| Vulnerability | A weakness |
| Exploit | A method that takes advantage of a weakness |
| Payload | What the attack does after gaining access |
| Malware | Malicious software |
| Phishing | Tricking people to gain information or access |
| Encryption | Making data unreadable without the required key |
| Hash | A one-way-style fingerprint of data |
| Firewall | Filters network traffic |
| VPN | Creates an encrypted connection to a VPN server |
| MFA | Uses multiple authentication factors |
| DDoS | Overwhelming a service with traffic |
| OSINT | Intelligence from public information |
| SIEM | Collects and analyzes security events |
| SOC | Team/function that monitors and responds to security events |
| CVE | Identifier for a known vulnerability |
| Zero-Day | Vulnerability without an available fix or prior notice |
| Zero Trust | Verify access instead of automatically trusting |
Keep Learning
Don’t try to memorize everything at once.
As you move through Cipherora’s lessons, return to this glossary whenever you encounter an unfamiliar term. Understanding the language of cybersecurity makes the technical concepts much easier to understand.
