Məzmuna keç
7/24 Təcili Cavab Xətti
az
Xidmətlər
Həllər
Tədqiqat
Şirkət
AlətlərTrust Center

Tədqiqat

Təhlükəsizlik Lüğəti

Plain-language explanations of terms we use in reports and meetings.

2 dəq oxuma

Bu məzmun hazırda yalnız ingilis dilində təqdim olunur.

E – L

TermMeaning
EDREndpoint detection and response: software that detects and responds to suspicious activity on endpoints.
ExploitCode or a technique that takes advantage of a vulnerability.
IDORInsecure direct object reference: an authorization flaw where changing an identifier exposes other users’ objects.
IOCIndicator of compromise: a technical trace of an attack (IP, domain, file hash).
KerberoastingRequesting Kerberos tickets for service accounts and cracking their passwords offline.
Lateral movementAn attacker moving from one system to another inside a network.

M – R

TermMeaning
MDRManaged detection and response: monitoring and first response delivered as a service.
MFAMulti-factor authentication: sign-in that requires more than a password.
MITRE ATT&CKA public knowledge base classifying adversary tactics and techniques.
PhishingTricking users with fake messages into giving up information or taking harmful actions.
Prompt injectionGetting a language model to follow unintended instructions through its input or the content it reads.
Purple teamRed and blue teams working together to improve detection.
RansomwareMalware that encrypts or steals data and demands a ransom.
Red teamA team or engagement that tests detection and response with realistic attack scenarios.

S – Z

TermMeaning
SIEMA platform that collects and correlates logs from many sources and raises alerts.
SOARA platform that automates and orchestrates security response steps.
SOCSecurity operations center: the team that monitors and responds to events.
SQL injectionUser input leaking into a database query, allowing data to be read or modified.
SSRFServer-side request forgery: forcing a server to send requests to attacker-chosen addresses.
TTPTactics, techniques and procedures of a threat actor.
XDRExtended detection and response across endpoint, network, email and cloud data.
Zero-dayA vulnerability with no vendor fix available yet.
Zero TrustA security model that trusts no access by default and verifies every request.