Glossary

Clarify your Cyber Security Vocabulary

Thank you! Your submission has been received!
hero background graphics

A/AAAA Record

Maps a domain to an IPv4 (A) or IPv6 (AAAA) address.

External Attack Surface & Exposure

Abuse Box feed

An email inbox used to receive abuse or misuse complaints related to a domain or service. Often required by registries, ISPs, or hosting providers.

Digital Risk Protection

Acceptable Use Policy

A written set of rules that define what a user can and cannot do when using a company's computers, networks, and internet.

Account suspension

Suspension of fraudulent emails or social media accounts.

Account Takeover (ATO)

A security incident in which an attacker gains unauthorized access to a legitimate user’s account, typically by stealing, guessing, or phishing their login credentials, and then uses that access to perform fraudulent or malicious actions.

Digital Risk Protection

Accredited domain registrars of a registry

Registrars that are officially recognized by a Registry to provide domain-related services.

Active Intrusive Reconnaissance

A type of active reconnaissance involving deeper probing or testing of the target system, which may be detectable and can cause impact.

External Attack Surface & Exposure

Active Non-Intrusive Reconnaissance

A type of active reconnaissance where someone interacts with the target system in a careful and controlled way to gather information without causing disruption or noticeable impact.

External Attack Surface & Exposure

Active Reconnaissance

Gathering information by directly interacting with the target system to identify services, responses, or potential weaknesses.

External Attack Surface & Exposure

Adaptive Authentication

Also called risk-based authentication, is a security approach that dynamically adjusts access requirements based on real-time risk signals like user location, device, time, and behavior.

Advance Fee Fraud (419 Scam)

A scam where victims are promised a large amount of money but are first asked to pay a small upfront fee. After the payment is made, the scammer either asks for more fees or disappears.

Advance Fee Fraud/419 Scam/Nigerian 419

An advance-fee scam is a form of fraud and one of the most common types of confidence tricks. The scam typically involves promising the victim a significant share of a large sum of money, in return for a small up-front payment, which the fraudster requires in order to obtain the large sum. If a victim makes the payment, the fraudster either invents a series of further fees for the victim or simply disappears.

Adware

Software that shows unwanted ads on a device and may collect user information without permission.

Digital Risk Protection

Air Gap

Having a critical computer or machine in a physically isolated location as well as disconnecting it from the internet.

Alert Fatigue

When security teams become overwhelmed and desensitized by a massive volume of alerts, many being false positives, causing them to miss or ignore critical threats, leading to burnout, increased response times, and a compromised security posture.

Digital Risk Protection, External Attack Surface & Exposure

Angler Phishing

An attack in which the fraudster will masquerade as a customer support representative on social media to send phishing links to customers in order to get their information such as username and password as well as other personal information.

Anonymous Proxy

An anonymous proxy is a server that acts as an intermediary for requests from clients seeking resources from other servers, but without revealing the user's IP address or other identifying information to the target server.

Anti-Forensics

Techniques and actions used to hide, change, or delete digital evidence to prevent cyber forensic investigations and make it hard to identify an attacker's actions or understand what happened.

Anti-Malware

Security software designed to prevent, detect, and remove malicious software (malware) like viruses, spyware, ransomware, and worms from computers and networks

Digital Risk Protection

Anti-Phishing

Methods, software, and strategies (like email filtering, website blocking, DMARC, training) designed to detect and stop cybercriminals from tricking individuals into revealing sensitive data through deceptive emails, texts, or websites that impersonate trusted entities, protecting users from identity theft and network breaches.

Digital Risk Protection

App permissions

Permissions requested by an application to access specific device features or data. Excessive or unnecessary permissions can pose privacy and security risks.

APT

Advanced Persistent Threat (APT) refers to a long-term, targeted cyberattack where the attacker remains undetected inside a network to spy, steal data, or manipulate systems over time.

Asset

Any hardware, software, data, or resource that holds value for an organization and is directly associated with or controlled by the organization.

External Attack Surface & Exposure

Astroturfing

Astroturfing is abusing the power of customer reviews on sites like Yelp, Facebook, Amazon and others. Either a place of business will post rave reviews from fake customers about their product, or a business will post bad reviews about a competitor.

Digital Risk Protection

Attack Chain

Also known as the Cyber Kill Chain, it is a structured model that breaks down a cyberattack into stages, from initial research to achieving the attacker’s goal, helping organizations detect and stop attacks at any stage.

Digital Risk Protection, External Attack Surface & Exposure

Attack Surface

The total sum of all possible entry points (vulnerabilities, misconfigurations, vectors) where an unauthorized user can try to access, extract data from, or cause an effect on a system, network, or application.

External Attack Surface & Exposure

Attack Surface Reduction

The strategic process of identifying, managing, and minimizing all internet-facing assets, services, and entry points that attackers could exploit, thereby decreasing the overall risk of compromise.

Authentication

The process of confirming that a user is who they claim to be before allowing access.

Authorization

Giving a verified user permission to access specific systems, features, or data.

Auto-generated Emails

Programmatic emails triggered and sent by backend systems or application workflows without direct human drafting, including automated password resets, system alerts, out-of-the-office emails and auto-responders.

Email Security

Autonomous System Number (ASN)

A unique number assigned to a network provider or large organization that controls routing.

External Attack Surface & Exposure

Availability

Making sure systems and services are accessible and working when they are needed.

Backdoor

A hidden entry point in software or systems that allows bypassing normal authentication, often installed by attackers to regain access later.

Back links / Inward links

A backlink is any link received by a web node (web page, directory, website, or top level domain) from another web node.

Digital Risk Protection

Backscatter

Backscatter is an email phenomenon where a spoofed email address or domain receives automated bounce messages (Non-Delivery Reports or NDRs) for fraudulent emails that were never sent by the legitimate owner. This happens because attackers forge the sender's address, causing the bounce notifications to be delivered to the spoofed address.

Email Security

Banner Grabbing

A technique to gather intelligence about network services by capturing the "banner" (info messages) sent by servers when a connection is made, revealing software names, versions, and operating systems; useful for defenders to map assets but also for attackers to find known vulnerabilities (CVEs) for exploitation.

External Attack Surface & Exposure

Baseline Security

The foundational, minimum set of security controls and configurations an organization implements to protect its IT systems and data from common threats.

Bastion Host

A host with very few services/applications running on it, usually put between the internal network and the internet. This point acts as a proxy and is the only entry point to the internal network.

Benchmarking

The process of comparing practices, performance, or risk levels against standards, best practices, or similar organizations to identify gaps and improvements.

Third-Party Risk Management

BGP

Border Gateway Protocol used to exchange information about routing between AS Numbers.

BGP peers

When BGP runs between two peers in the same autonomous system (AS), it is referred to as Internal BGP (iBGP or Interior Border Gateway Protocol). When it runs between different autonomous systems, it is called External BGP (EBGP or Exterior Border Gateway Protocol).

BGP route

When BGP runs between two peers in the same autonomous system (AS), it is referred to as Internal BGP (iBGP or Interior Border Gateway Protocol). When it runs between different autonomous systems, it is called External BGP (EBGP or Exterior Border Gateway Protocol).

BIMI (Brand Indicators for Message Identification)

An inbox visual standard that renders an organization’s official trademarked logo alongside authenticated messages, transforming strong email authentication (DMARC) into instant brand trust for the recipient.

Email Security

BIN

Bank Identification Number. Which is the starting digits of a credit card, most commonly 6 or 8 digits.

Bitsquatting

Refers to the registration of a domain name one bit different than a popular domain. The name comes from typo-squatting: the act of registering domain names one key press different than a popular domain.

Digital Risk Protection

BitTorrent

A peer-to-peer file-sharing protocol that allows users to distribute large files, but it is often abused by attackers to spread malware or illegal content.

Blackbox Testing - Whitebox testing - Graybox Testing

The hacker does not know the in/outs of the IT infrastructure. Usually launches a full scale brute force attack to reveal vulnerabilities. Can be very time consuming.\n

Black Hat

A hacker who identifies and exploits vulnerabilities for malicious purposes or personal gain, often breaking laws or causing harm.

Black Hat SEO

In search engine optimization (SEO) terminology, Black Hat SEO refers to the use of aggressive SEO strategies, techniques and tactics that focus only on search engines and not a human audience, and usually does not follow search engine guidelines.

Blended Attack

A cyber attack that comprises multiple attack vectors and malware is known as a blended attack. Such attacks usually cause severe damage to targeted systems.

No entry found