TERMS A–Z
Understand cybersecurity.
Put terms in context.
From threat detection to network analysis: concise explanations of terms you encounter in security concepts, proposals, and technical conversations.
23 terms
TOPIC GROUP
Detection & security operations
Alert fatigueDeclining attention caused by a sustained volume of alerts that must be reviewed.EDREndpoint Detection and ResponseMonitors endpoints to detect, investigate, and respond to suspicious activity.IDS / IPSAn IDS detects suspicious network activity; an IPS can additionally block identified connections.MDRManaged Detection and ResponseAn operating model in which an external provider runs detection systems and reviews security alerts.NDRNetwork Detection and ResponseAnalyses network communications to identify unusual activity and provide context for investigation.SIEMSecurity Information and Event ManagementCollects and correlates log and event data from different sources for monitoring and investigation.SOCSecurity Operations CenterAn organisational function that monitors and assesses security events and coordinates incident response.XDRExtended Detection and ResponseConnects security data from several domains to support investigation of related activity.
TOPIC GROUP
Attacks & threats
APTAdvanced Persistent ThreatA long-term, targeted attack conducted by a capable and persistent threat actor.Business Email Compromise (BEC)Fraud that imitates or compromises business email communications to obtain payments or data.Command-and-Control (C2)Communication used by attackers to control compromised systems or exchange commands and data.Lateral MovementThe movement of an attacker between systems inside an environment they have already accessed.MITRE ATT&CKA knowledge base that structures observed adversary tactics and techniques.RansomwareMalware that restricts access to data or systems and is typically connected with a ransom demand.Threat IntelligenceCurated information about threat actors, infrastructure, and methods used to support security decisions.
TOPIC GROUP
Testing & assessment
Automated attack simulationAutomates defined attack steps to assess selected controls or possible attack paths repeatedly.Compromise AssessmentA time-bounded investigation for indications that systems or an environment have already been compromised.Penetration testAn authorised security assessment that practically examines selected vulnerabilities and attack opportunities.Red TeamingAn objective-led attack simulation that may include technical, organisational, and human controls.Vulnerability scanAn automated comparison of systems and services with known vulnerabilities and misconfigurations.
TOPIC GROUP
Networks & technical fundamentals
Encrypted network trafficNetwork communication with protected content whose connection characteristics can still be partly analysed.Shadow ITDevices, applications, or services used without the knowledge or approval of the responsible IT function.SPAN port / Network TAPTwo technical methods for providing copies of network traffic for passive analysis.
How do the terms relate?
Our articles and guides explain how security approaches complement one another and which practical questions they answer.
View articles and guidesWhat does this mean for your environment?
Would you like to assess the role network analysis could play in your security approach? Let us discuss your question.
Discuss your situation