The key terms around network security, threat detection, and security testing — in plain language, without marketing. Each term explained individually, with a link to practice.
KNOWLEDGE — THREAT DETECTION & MONITORING
Analyzes real network traffic and catches attacks that log-based systems miss.
Collects and correlates logs from many sources for central visibility, compliance, and forensics.
The team that assesses, triages, and responds to security alerts.
Bundles detection signals across multiple security layers into one correlated view.
Detects attacker activity directly on individual endpoints — laptops, servers, workstations.
Detects (IDS) or blocks (IPS) known attack patterns on the network.
KNOWLEDGE — THREATS & ATTACK TECHNIQUES
An attacker's sideways spread through a network after the initial foothold.
The covert communication a compromised system uses to talk to the attacker.
Fraud carried out through compromised or spoofed business email accounts.
Malware that encrypts data and demands a ransom for its release.
Long-term, well-resourced — often state-backed — attacker groups.
The standard, open knowledge base of real-world attacker tactics and techniques.
KNOWLEDGE — SECURITY TESTING
Authorized security assessment that exploits weaknesses and proves attack paths.
Automated check against known security flaws — without proving exploitability.
Proves attack paths like a pentest, but autonomous and repeatable.
Point-in-time check of whether a network is already compromised.
Realistic attack exercise against people, processes, and technology at once.