Skip to main content

Cybersecurity glossary

52 terms from SOC operations, Security+ domains, and AI security — each written for someone who has to make a decision, not pass a quiz.

  • AI hallucination

    Model invents confident-sounding info.

    AI security
  • Alert

    A signal that something might be wrong.

    SOC fundamentals
  • Blue Team

    Defenders.

    SOC fundamentals
  • Botnet

    Network of compromised machines.

    Threats & attacks
  • Brute force

    Trying many passwords until one works.

    Threats & attacks
  • CIA Triad

    Confidentiality, Integrity, Availability.

    General security concepts
  • Command and Control (C2)

    Attacker's remote handler.

    Threats & attacks
  • CVE

    Common Vulnerabilities and Exposures ID.

    Vulnerability management
  • CVSS

    Standard vulnerability severity score.

    Vulnerability management
  • Cyber Kill Chain

    Stages of a typical intrusion.

    Frameworks
  • Data poisoning

    Corrupting an AI's training data.

    AI security
  • Defense in Depth

    Layer your protections.

    Architecture
  • Digital Forensics

    Investigating what happened, with evidence.

    SOC fundamentals
  • DLP

    Data Loss Prevention.

    Data security
  • EDR

    Endpoint detection & response agent.

    SOC tooling
  • False positive

    Alert that looked bad but wasn't.

    Triage
  • Firewall

    Network traffic filter.

    Network security
  • Guardrails

    Safety controls around an AI system.

    AI security
  • Honeypot

    Decoy system to lure attackers.

    Detection engineering
  • IDS

    Intrusion Detection System.

    Network security
  • Incident Response (IR)

    Coordinated reaction to a breach.

    SOC fundamentals
  • Indicator of Compromise (IOC)

    Forensic clue that an attack may have happened.

    Threat intel
  • IPS

    Intrusion Prevention System.

    Network security
  • Lateral movement

    Attacker hops to other systems.

    Threats & attacks
  • Malware

    Any malicious software.

    Threats & attacks
  • MFA

    Multi-factor authentication.

    Identity & access
  • MITRE ATT&CK

    Map of attacker techniques.

    Frameworks
  • Model inversion

    Reconstructing training data from a model.

    AI security
  • MSSP

    Managed Security Service Provider.

    SOC fundamentals
  • Persistence

    Surviving reboots and logoffs.

    Threats & attacks
  • Phishing

    Tricking a user via email or messaging.

    Threats & attacks
  • Principle of Least Privilege

    Give only the access needed.

    Identity & access
  • Privilege escalation

    Going from low to high access.

    Threats & attacks
  • Prompt injection

    Hidden instructions hijack an AI.

    AI security
  • Purple Team

    Red + Blue working together.

    Offensive security
  • RAG (Retrieval Augmented Generation)

    AI grounded in your own data.

    AI architecture
  • Ransomware

    Malware that encrypts files for ransom.

    Threats & attacks
  • RBAC

    Role-Based Access Control.

    Identity & access
  • Red Team

    Offensive simulators.

    Offensive security
  • RLS

    Row-Level Security.

    Application security
  • Shadow AI

    Unsanctioned AI use inside the org.

    AI governance
  • SIEM

    Central log + alerting platform.

    SOC tooling
  • SOC

    Security Operations Center.

    SOC fundamentals
  • Spear phishing

    Phishing aimed at a specific person.

    Threats & attacks
  • SQL Injection

    Injecting SQL into app inputs.

    Application security
  • Threat Hunting

    Proactively searching for hidden attackers.

    SOC fundamentals
  • True positive

    Alert that was real malicious activity.

    Triage
  • TTP

    Tactics, Techniques, and Procedures.

    Threat intel
  • UEBA

    User & Entity Behavior Analytics.

    Detection engineering
  • XSS

    Cross-site scripting.

    Application security
  • Zero Trust

    Never trust, always verify.

    Architecture
  • Zero-day

    Vulnerability with no patch yet.

    Vulnerability management