Cybersecurity Glossary

Key terms and concepts in cybersecurity, networking, and internet scanning. Each term includes a detailed explanation and relevant Zondex search examples.

138
Terms
23
Letters
C15 terms
description

C2 Server

A C2 (Command and Control) server is a central hub attackers use to remotely manage compromised …

description

CDN

A Content Delivery Network (CDN) is a geographically distributed group of servers that work together to …

hub

CIDR

Classless Inter-Domain Routing — a method for allocating IP addresses and IP routing using variable-length subnet …

description

CPE

Common Platform Enumeration is a standardized naming scheme for IT systems, software, and hardware, providing a …

description

CSRF

Cross-Site Request Forgery (CSRF) is a vulnerability allowing an attacker to trick authenticated users into executing …

bug_report

CVE

Common Vulnerabilities and Exposures — a standardized identifier for known security vulnerabilities in software and hardware.

speed

CVSS

Common Vulnerability Scoring System — an open framework for communicating the severity of software vulnerabilities on …

description

CWE

Common Weakness Enumeration is a community-developed list of software and hardware weakness types that can lead …

description

Certificate Authority

A trusted entity that issues digital certificates, verifying the identity of websites and other entities to …

description

Certificate Transparency

An open framework designed to publicly log all SSL/TLS certificates issued by Certificate Authorities (CAs) to …

description

Cloud Security

Cloud security encompasses policies, technologies, and controls designed to protect data, applications, and infrastructure within cloud …

description

CoAP

CoAP is a specialized web transfer protocol for use with constrained nodes and constrained (e.g., low-power, …

description

Command Injection

Command injection is a vulnerability allowing an attacker to execute arbitrary commands on the host operating …

description

Container Security

Container security involves protecting containerized applications throughout their lifecycle, from image creation and deployment to runtime …

description

Credential Stuffing

Credential stuffing is an automated cyberattack where large sets of stolen username/password pairs from data breaches …

S15 terms
description

SCADA

Supervisory Control and Data Acquisition (SCADA) systems monitor and control industrial processes across vast geographical areas …

description

SIEM

Security Information and Event Management (SIEM) is a security solution that centralizes and analyzes log and …

description

SMB

SMB is a network file sharing protocol primarily used by Microsoft Windows, enabling applications to read/write …

description

SMTP

SMTP (Simple Mail Transfer Protocol) is the standard protocol for sending and receiving email messages between …

description

SNMP

SNMP (Simple Network Management Protocol) is an application-layer protocol for managing and monitoring network devices, allowing …

description

SOAR

SOAR platforms integrate security tools and automate incident response workflows, enabling organizations to efficiently manage and …

description

SOC

A Security Operations Center (SOC) is a centralized function within an organization responsible for continuously monitoring …

description

SQL Injection

A SQL Injection (SQLi) is a web security vulnerability allowing attackers to interfere with an application's …

description

SSH

SSH (Secure Shell) is a cryptographic network protocol for operating network services securely over an unsecured …

description

SSL

SSL (Secure Sockets Layer) is a deprecated cryptographic protocol that provided secure communication over a computer …

description

SSRF

Server-Side Request Forgery (SSRF) is a vulnerability where an attacker can induce a server-side application to …

description

SYN Scan

A port scanning technique that sends a SYN packet to a target port and analyzes the …

description

Service Enumeration

Service enumeration is the process of identifying and mapping all active services, their associated open ports, …

description

Shellcode

Shellcode is a small piece of low-level code, typically written in assembly, used as a payload …

description

Subnet

A subnet (subnetwork) is a logical subdivision of an IP network, allowing an organization to segment …

Learn by Doing

See these concepts in action. Search the internet's attack surface with Zondex's powerful dork syntax.