Cybersecurity Glossary
Technical definitions maintained by our team. Each entry links to a full guide covering what it is, what it is for and how to apply it.
A
What Is Adware: Types, Risks, Real Cases and How to Remove It
What adware is, types (legitimate, aggressive, malicious, mobile), real cases (Fireball, Lenovo Superfish, ad fraud) and how to remove it in enterprise.
What Is an Exploit: Types, CVE, 0-day and Defence
What an exploit is, types (RCE, LPE, info disclosure, DoS), difference with CVE, real examples (EternalBlue, Log4Shell), 0-day vs N-day and defence.
What Is an IDS: Types, IPS Differences and Snort vs Suricata
What an IDS is, types (NIDS and HIDS), differences with IPS and firewall, Snort vs Suricata vs Zeek and when to use NDR in 2026.
What Is an Infostealer: Credential Theft and Stealer Logs
What is an infostealer: how stealer logs work, families (Lumma, RedLine), session-cookie theft that bypasses MFA, and how to detect and prevent it.
B
Breach and Attack Simulation (BAS): Complete Guide
What Breach and Attack Simulation (BAS) is: the continuous security validation category, how it works, leading platforms and when to use BAS vs Red Team.
What Is a Backdoor: Types, Real Examples and Detection Methods
What a backdoor is in cybersecurity: types (software, hardware, firmware), APT examples, detection with EDR and hardening for enterprises.
What Is a Backup: Types, 3-2-1 Rule and Business Strategy
What a backup is, types (full, incremental, differential), the 3-2-1 rule, differences with disaster recovery and how to verify copies actually work.
What Is a Botnet: Architecture, Real Examples and Defence
What a botnet is, architectures (centralised C2, P2P, Fast Flux, DGA), uses (DDoS, ad fraud, distribution), examples (Mirai, Emotet, Mozi) and defence.
What is Blue Team: defense, SOC and security operations 2026
What is Blue Team: SOC tiers, detection engineering, threat hunting, IR playbooks, MTTD/MTTR KPIs and a defensive career in cybersecurity.
What Is Blue Team: Functions and Red Team Comparison
What the Blue Team is in cybersecurity: functions, tools, MTTD and MTTR metrics, differences with Red Team and Purple Team, and when you need it.
What is bug bounty: programs, platforms and rewards 2026
What is a bug bounty program: HackerOne, Bugcrowd, Yeswehack, Intigriti. Public vs private models, triage, payouts and how it differs from pentesting.
What is Burp Suite: complete guide to web pentesting 2026
What Burp Suite is, main modules (Proxy, Repeater, Intruder, Scanner), Community vs Professional vs Enterprise, extensions and pentesting workflow.
C
Cracker vs Hacker: Differences, Types and Real Examples
Cracker vs hacker: what a cracker is, how it differs from a hacker, profiles (black hat, gray hat, script kiddie), motivations, techniques and defence.
What Is a CISO: Functions, Responsibilities and Models
What a CISO is, eight core functions, reporting line, profile and certifications, models (vCISO, in-house, outsourced) and fit with NIS2 and DORA.
What Is a Computer Worm: Types, Examples and Removal
What a computer worm is, differences with virus and trojan, main types, real examples (Morris, ILOVEYOU, Conficker, WannaCry, NotPetya) and defence.
What Is a CVE: Common Vulnerabilities Explained
What a CVE is, how CNAs assign it, the difference with CVSS, CWE and EPSS, where it is published (NVD, GHSA, CISA KEV) and how to track it in your stack.
What is clickjacking: UI redressing attacks and defense
What clickjacking (UI redressing) is: how likejacking and cursorjacking work and defenses with X-Frame-Options, CSP frame-ancestors and SameSite cookies.
What Is CORS: How It Works and Exploitable Misconfigurations
What CORS is, how Same-Origin Policy and preflight work, Access-Control-* headers, seven exploitable misconfigurations and secure configuration.
What Is Credential Stuffing: Password Reuse Attacks
What credential stuffing is: combo lists, Sentry MBA, account takeover, difference with brute force, detection with WAF/CAPTCHA and MFA defence.
What is CSPM: Cloud Security Posture Management for AWS, Azure, GCP
What CSPM is: continuous detection of misconfigurations in AWS/Azure/GCP, CIS Benchmarks, vendors (Wiz, Prisma, Defender CSPM) and how it differs from CNAPP.
What is CSRF: cross-site request forgery, examples and defense
What CSRF (cross-site request forgery) is, how it works, exploit examples, defenses (CSRF tokens, SameSite cookies) and the difference with XSS.
D
What Is a DDoS Attack: Types and Mitigation
What a DDoS attack is: difference from DoS, OSI-layer taxonomy (volumetric, protocol, L7), DNS/NTP/memcached amplification and a mitigation stack.
What is a deepfake: business threats and defense in 2026
What is a deepfake in business: AI voice BEC, fake CEO video, Arup $25M case, biometric detection and out-of-band anti-fraud policies.
What Is DFIR? Digital Forensics & Incident Response
What DFIR is: digital forensics vs incident response, the PICERL lifecycle (NIST/SANS), core tooling, chain of custody and NIS2/DORA reporting duties.
What Is DLP: Types, NIS2/GDPR Fit and Deployment Mistakes
What DLP (Data Loss Prevention) is, types (endpoint, network, cloud, email), how to deploy, NIS2/DORA/GDPR/ISO 27001 fit and typical mistakes.
What Is the Dark Web? Risks for Businesses
What the dark web is, what gets traded on it (credentials, RaaS access, stolen data) and why it is a real risk for your business.
E
What Is EDR (Endpoint Detection and Response)
What an EDR is, how it works, what it detects, the difference with antivirus, XDR and MDR, and how it fits with SIEM and SOC in a defensive stack.
What Is Ethical Hacking: Types and Certifications
What ethical hacking is, types of hackers (white/grey/black hat), certifications (OSCP, OSWE, CEH), career path and legal framework in Spain.
F
H
I
ISO 27001: What It Is and How to Get Certified
ISO 27001:2022 explained for SMEs and midmarket: ISMS, the 93 Annex A controls, audit and certification step by step. Real cost and timelines.
What Is IAM: Identity and Access Management for Enterprise 2026
What is IAM (Identity Access Management): authentication, authorization, SSO, MFA, RBAC vs ABAC, IGA, PAM and the 2026 enterprise stack.
What is IDOR: broken access control, examples and defense
What IDOR (insecure direct object reference) is within broken access control (OWASP A01): exploit examples, how to test it with Burp and how to defend.
What Is INCIBE: Functions, Services and Difference with CCN
What INCIBE is, its functions, services for companies (INCIBE-CERT, Line 017, advisories), difference with CCN and CCN-CERT and how to report an incident.
K
What Is a Keylogger: Types, How It Works and How to Protect
What a keylogger is, types (software, hardware, web, acoustic), distribution, detection with EDR and antivirus, and protective measures.
What is the kernel and why it matters in cybersecurity
What the operating system kernel is, ring 0 vs userland, kernel exploits, rootkits and why kernel security is critical for enterprises.
M
Multi-Factor Authentication (MFA): What It Is and How It Works
What multi-factor authentication (MFA) is: the three factors, factor types (TOTP, FIDO2, passkeys), MFA fatigue, SIM swap and phishing-resistant MFA.
What Is a Man in the Middle (MitM) Attack: Types and Defence
What a MitM attack is, the six real vectors (ARP poisoning, DNS spoofing, evil twin, SSL strip, session hijacking, BGP hijack) and how to defend.
What Is Magerit: Risk Analysis Methodology and PILAR
What Magerit is, the 6 elements (assets, threats, safeguards), step-by-step process, PILAR tool and fit with ENS, ISO 27001, NIS2 and DORA.
What Is Maltego: OSINT, Threat Intel and Graph Investigation
What Maltego is, how entities and transforms work, CE/Pro/Enterprise versions, OSINT and Red Team use cases, alternatives and legal aspects.
What Is MDR (Managed Detection and Response)
What MDR is, what a mature MDR service includes, how it differs from SOC, MSSP, EDR and XDR, leading providers and how it maps to NIS2 and DORA.
What Is Mimikatz: Credential Dumping, Techniques and Detection in 2026
What Mimikatz is, credential dumping (sekurlsa, lsadump, kerberos), red team use and EDR/SIEM detection in Active Directory environments.
What Is MITRE ATT&CK: Tactics, Techniques and Use in SOC
What MITRE ATT&CK is, how it's organised in tactics, techniques and sub-techniques, the 14 Enterprise tactics and how SOCs, Red Teams and hunters use it.
O
OT Security: What Is It, ICS/SCADA Risks and Defense
What is OT security: IT/OT differences, ICS/SCADA/PLC components, the Purdue model, legacy protocols and a defense framework built on IEC 62443.
What is open redirect: risks and prevention
What open redirect (CWE-601) is: how it is abused for phishing and OAuth token theft, bypass techniques and defense through allowlist validation.
What Is OSINT: Cycle, Sources, Tools and Legal Framework
What OSINT (Open Source Intelligence) is, the intelligence cycle, sources, tools (Maltego, Shodan, SpiderFoot), real use cases and GDPR legal framework.
P
Path Traversal, LFI & RFI: Attacks and Defence
What path traversal, LFI and RFI are: the ../ mechanism, PHP wrappers, log poisoning, allow_url_include, real CVEs, detection and defence with allow-lists.
What Is a Passkey? Passwordless Login Explained
What a passkey is: a passwordless FIDO2/WebAuthn credential that resists phishing. How it works, synced vs device-bound, and enterprise migration.
What Is a Penetration Test? A Complete Guide for Businesses
Learn what a penetration test is, the different types, the phases involved, and when your business needs one. A practical guide for CISOs and CTOs.
What Is Penetration Testing: Complete Business Guide
What pentesting is, what it's for, the 5 phases, scope types, OWASP and OSSTMM methodologies and how it fits NIS2, DORA, ENS and ISO 27001.
What Is Pharming: Types, Phishing Differences and Defence
What pharming is, types (local DNS, DNS server, BGP hijacking), differences with phishing, real cases and how to protect with DNSSEC, MFA and EDR.
What Is PKI (Public Key Infrastructure)
What PKI is, components (CA, RA, CRL, OCSP), chain of trust, enterprise use cases, public vs private PKI and compliance with eIDAS, NIS2, ISO 27001.
What Is Prompt Injection: LLM Attacks and How to Defend
What prompt injection is, types (direct, indirect), real examples, OWASP LLM Top 10, mitigations and how to audit LLM-powered applications.
What Is Purple Team: Red and Blue Team Collaboration with MITRE ATT&CK
What Purple Team is: collaborative red+blue exercises, MITRE ATT&CK Navigator, detection metrics, Atomic Red Team and how it differs from pure red team.
R
What Is a Red Team: Complete Business Guide
What a Red Team is, how it differs from pentesting, Blue Team and Purple Team, exercise phases, when you need one and how to choose a provider.
What Is a Rootkit: Types, How It Works and Detection Methods
What a rootkit is in cybersecurity: types (kernel, bootkit, firmware, hypervisor), evasion techniques, EDR detection and DFIR response.
What Is Ransomware: How It Works, Examples and Defence
What ransomware is: encryption, double extortion, active families (LockBit, BlackCat, Akira), entry vectors, defensive controls and incident response.
S
Spear Phishing: What It Is, Examples and Defence
What spear phishing (targeted phishing) is: how it differs from phishing and BEC, OSINT anatomy, real cases and layered defence with DMARC, FIDO2 and EDR.
SQL Injection: What It Is, Attacks & Prevention
What SQL injection is, how the attack works, its types (union, error, blind, time-based) and how to prevent it with parameterized queries.
What is a sniffer: how it works, tools and detection 2026
What is a network sniffer: passive vs active capture, tools (Wireshark, tcpdump, Bettercap), legitimate pentest use and defensive detection.
What Is a SOC (Security Operations Center): How It Works
What a SOC is, how the detection workflow runs, L1/L2/L3 tiers, MTTD and MTTR metrics, internal vs managed models and when an organisation needs one.
What Is a Software Supply Chain Attack: Cases and SLSA Defence 2026
Software supply chain attacks: SolarWinds, XZ Utils, npm/PyPI poisoning, SLSA framework, sigstore, SBOM and enterprise defence.
What Is SAML 2.0: SSO Flow, OAuth/OIDC and Vulnerabilities
What SAML 2.0 is, SSO flow with IdP and SP, comparison with OAuth 2.0, OIDC and JWT, XML signature wrapping and assertion replay vulnerabilities.
What Is SHA-256: Hash Function, Real Uses and Comparison
What SHA-256 is, how it works as a cryptographic hash function, properties, uses (TLS, Bitcoin, integrity, JWT) and comparison with SHA-1, SHA-3 and BLAKE3.
What Is Shodan: Internet-Connected Device Search and Defensive Use
What Shodan is, the search engine for Internet-connected devices. Advanced operators, pentesting and threat hunting use cases, plus Censys and ZoomEye.
What Is SIEM: How It Works, SOAR vs XDR and Use Cases
What a SIEM is, how it works, how it differs from SOAR and XDR, real use cases, leading platforms and how it fits NIS2, ENS, ISO 27001 and PCI DSS.
What Is Social Engineering: Types, Cases and Defence
What social engineering is, Cialdini principles, types (phishing, vishing, BEC, pretexting), real cases (Twitter, Uber, MGM) and defence.
What is spoofing: types, examples and prevention techniques
What is spoofing in cybersecurity: types (email, ARP, DNS, IP, caller ID, GPS), detection techniques and defensive controls for business.
What is SSPM: SaaS Security Posture Management
What is SSPM: SaaS security posture management. Detects misconfig, third-party OAuth apps, over-privileged users and MFA gaps.
What is SSRF: server-side request forgery, cloud exploits and defense
What is SSRF (server-side request forgery): mechanics, attacks against cloud metadata (AWS IMDS, Azure), blind techniques and defense in depth.
T
What Is a Trojan: Types, Real Examples and How to Remove It
What a trojan is: types (RAT, banker, downloader, dropper, info-stealer), real examples (Emotet, Trickbot) and removal steps.
What Is Threat Hunting: Methodology and Tools
What threat hunting is: methodologies (hypothesis, IoC-driven, TTP-driven), MITRE ATT&CK, tools, practical examples and fit with NIS2 and DORA.
V
W
Watering Hole Attack: What It Is, How It Works and Cases
What a watering hole attack is: definition, how it works, real cases like Council on Foreign Relations and Polish banking, and how to defend.
What Is a WAF (Web Application Firewall)
What a WAF is, detection models (positive, negative, hybrid), deployment types (cloud, appliance, host), common mistakes and PCI DSS / NIS2 mapping.
What Is Wazuh: Open Source SIEM for Companies
What Wazuh is: architecture (agents, manager, indexer, dashboard), detection (FIM, logs, CVE, MITRE), vs Splunk/Sentinel and compliance with NIS2.
X
What Is XSS: Cross-Site Scripting Attacks Explained
What XSS (cross-site scripting) is: how it works, types reflected, stored and DOM, real payloads and defenses with CSP, output encoding and cookies.
What Is XXE: XML External Entity Injection Explained
What is XXE (XML External Entity): DTDs and external entities, in-band vs blind XXE, file read, SSRF, RCE, billion laughs and remediation per parser.
Y
Z
What Is a Zero-Day Vulnerability: Exploitation, Market and Defence
What zero-day means: life cycle, gray market (Zerodium), CISA KEV, virtual patching and why EDR does not always detect zero-day exploits.
What Is Zero Trust: Architecture, Principles, and Practical Implementation
Zero Trust explained: NIST 800-207 principles, architecture, microsegmentation, ZTNA vs VPN, implementation phases and NIS2/ENS alignment.
Frequently Asked Questions
- What is this glossary?
- An alphabetical index of cybersecurity technical definitions published by the Secra team. Each entry links to a full guide covering the concept, use cases and regulatory mapping.
- How is it updated?
- Entries get reviewed at least annually or when material changes occur (new standard version, relevant associated CVE, new regulatory control). The update date appears in each individual guide.
- Can I suggest a term?
- Yes. If you work in cybersecurity and find a missing entry, reach out via the contact form with the proposed term and a concrete use case.
Need to go deeper than the glossary?
Definitions explain what something is, not how to apply it in your specific environment. If you want to translate theory into operational controls inside your organisation, let's talk.
Talk to an expert
