Cybersecurity Glossary
More than 60 offensive and defensive cybersecurity terms explained in plain language by the MagnoSec team. From pentesting to Zero Trust, covering ransomware, exploits, regulations and attack/defense methodologies.
PentestingPenetration Testing
OffensivePenetration test: a controlled simulation of a real attack against an organization's systems, networks or applications to identify exploitable vulnerabilities. Unlike an automated vulnerability scan, a pentest involves manual exploitation of the flaws found to demonstrate their real impact. There are three modalities: black box (no prior information), grey box (limited credentials) and white box (full access to code and infrastructure). At MagnoSec we perform web, mobile, infrastructure, WiFi, Active Directory and cloud pentesting.
Red TeamRed Team
OffensiveAdversary simulation exercise where an offensive team attempts to compromise an organization's systems, networks and people over an extended period (weeks or months). Unlike traditional pentesting, Red Team operations go beyond technical vulnerabilities: they use social engineering, physical access, OSINT and any available vector to reach their objectives. The defensive team (Blue Team) is unaware the exercise is running, allowing assessment of the organization's real detection and response capability.
VulnerabilityVulnerability
FundamentalsA weakness or flaw in a system, application, network or process that can be exploited by an attacker to compromise the confidentiality, integrity or availability of information. Vulnerabilities are classified under the CVE standard (Common Vulnerabilities and Exposures) and scored with CVSS (Common Vulnerability Scoring System) on a 0-10 scale. A CVSS 9.0-10 vulnerability is considered critical and must be patched immediately.
Zero-DayZero-Day
ThreatsA vulnerability unknown to the software vendor with no patch available. 'Zero day' refers to defenders having had zero days to protect themselves since the vulnerability became public (or was discovered being exploited). Zero-days are the most dangerous vulnerabilities because attackers can exploit them with no known defense. When a zero-day is found under active exploitation, CISA adds it to its KEV catalog (Known Exploited Vulnerabilities) requiring US federal agencies to patch within short deadlines.
RansomwareRansomware
ThreatsMalware that encrypts the victim's files and demands a ransom (usually in cryptocurrency) in exchange for the decryption key. Modern ransomware has evolved into double extortion: before encrypting, attackers exfiltrate data and threaten to publish it. Ransomware operators run as criminal businesses with RaaS (Ransomware-as-a-Service), where a developer creates the malware and affiliates distribute it for a cut of the ransom.
PhishingPhishing
ThreatsSocial engineering technique that impersonates a legitimate entity (bank, supplier, coworker) via email, SMS (smishing) or phone calls (vishing) to trick the victim into revealing credentials, installing malware or making bank transfers. Spear phishing is a targeted variant using personal information gathered beforehand to increase credibility.
ExploitExploit
OffensiveA program, script or set of instructions designed to take advantage of a specific vulnerability in a system to achieve an unauthorized result: code execution, privilege escalation, denial of service or authentication bypass. Exploits can be public (available on platforms like Exploit-DB or Metasploit) or private (developed by intelligence agencies or criminal groups). A functional exploit for a newly patched vulnerability can be developed in under 24 hours via reverse engineering of the patch.
CVECommon Vulnerabilities and Exposures
FundamentalsInternational standard system for identifying and cataloging known security vulnerabilities. Each CVE receives a unique identifier formatted CVE-YEAR-NUMBER (e.g., CVE-2026-58644). The CVE database is maintained by MITRE Corporation and is the reference used by governments, companies and vendors to coordinate vulnerability disclosure and patching.
CVSSCommon Vulnerability Scoring System
FundamentalsNumeric scoring system (0-10) assessing the severity of a security vulnerability based on exploitability and impact. CVSS v4.0 considers base metrics (intrinsic), temporal metrics (change over time) and environmental metrics (specific to the deployment environment). A CVSS 9.0-10.0 score is classified as critical and requires immediate action.
MITRE ATT&CKMITRE ATT&CK
MethodologiesOpen knowledge framework cataloging the tactics, techniques and procedures (TTPs) used by real adversaries in cyberattacks. ATT&CK organizes techniques by tactics (initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, command and control, exfiltration and impact) and is universally used in Red Team, Purple Team and threat hunting exercises.
Active DirectoryActive Directory
InfrastructureMicrosoft directory service managing identity, authentication and authorization on corporate Windows networks. Active Directory (AD) is the primary target of most enterprise attacks because compromising it gives the attacker control of all users, devices and resources on the network. Techniques like Kerberoasting, AS-REP Roasting, DCSync, Pass-the-Hash and Golden Ticket are AD-specific and represent the most critical attack vectors in corporate environments.
OWASPOpen Web Application Security Project
MethodologiesNon-profit organization publishing free resources on web application security. Its best-known project is the OWASP Top 10, a list of the 10 most critical web security risks updated periodically. It also maintains the OWASP Testing Guide, the ASVS (Application Security Verification Standard), and tools like ZAP (Zed Attack Proxy), a free alternative to Burp Suite for web pentesting.
EDREndpoint Detection and Response
DefensiveSecurity system continuously monitoring endpoints (computers, servers, mobile devices) to detect, investigate and respond to threats in real time. Unlike traditional signature-based antivirus, EDR uses behavioral analysis, machine learning and indicators of attack (IOAs) to identify malicious activity. Modern attackers dedicate significant effort to disabling or evading EDRs before executing their payload.
SIEMSecurity Information and Event Management
DefensivePlatform that centralizes, correlates and analyzes security logs and events from multiple sources (firewalls, servers, applications, endpoints, network devices) to detect attack patterns, generate alerts and facilitate incident response. A well-configured SIEM is the nerve center of a SOC (Security Operations Center). The basic rule: if you don't send a system's logs to the SIEM, you'll never know if that system was compromised.
MFA / 2FAMulti-Factor Authentication
DefensiveAuthentication system requiring two or more independent factors to verify identity: something you know (password), something you have (token, phone) and something you are (fingerprint, facial recognition). MFA is the most effective defense against credential theft: Microsoft studies show it reduces 99.9% of account compromise attacks, though it doesn't protect against attacks exploiting vulnerabilities in MFA systems themselves.
VPNVirtual Private Network
InfrastructureTechnology creating an encrypted tunnel between a device and a private network over the internet. Corporate VPNs allow employees secure access to internal resources from remote locations. However, VPNs have become the favorite attack vector of ransomware gangs in 2026: compromising the VPN appliance gives the attacker direct access to the internal network, bypassing all perimeter defenses. Post-VPN segmentation and Zero Trust are essential.
Zero TrustZero Trust Architecture
MethodologiesSecurity model assuming no entity — user, device or application — is trustworthy by default, inside or outside the corporate network. Every access request is verified, authorized and encrypted individually, applying least privilege. Zero Trust is not a product: it's an architecture requiring continuous identity verification, network microsegmentation and constant monitoring. The mantra: 'never trust, always verify'.
ISO 27001ISO 27001
RegulationsInternational standard specifying requirements for establishing, implementing, maintaining and improving an Information Security Management System (ISMS). ISO 27001 certification demonstrates that an organization systematically manages information security according to international best practices. It is one of the most demanded standards in public and private contracts, along with the Spanish ENS.
ENSSpanish National Security Framework
RegulationsSpanish regulation establishing basic principles and minimum security requirements for information protection in the public sector. The ENS is mandatory for Spanish public administrations and their suppliers. It has three security categories (basic, medium, high) and covers confidentiality, integrity, availability, authenticity and traceability.
DORADigital Operational Resilience Act
RegulationsEU regulation establishing digital operational resilience requirements for financial entities and their critical ICT suppliers. DORA came into force in January 2025 and requires banks, insurers, fintechs and suppliers to perform regular penetration tests (including TLPT — Threat-Led Penetration Testing), manage third-party risk and notify major incidents.
NIS2Network and Information Security Directive 2
RegulationsEU directive significantly expanding the scope of the original NIS, obliging more sectors (energy, transport, health, digital infrastructure, water, public administration) to implement risk-proportionate cybersecurity measures. NIS2 imposes GDPR-like fines (up to €10M or 2% of annual turnover) and holds executives personally responsible for serious cybersecurity failures.
GDPR / RGPDGeneral Data Protection Regulation
RegulationsEuropean regulation on personal data protection establishing strict obligations on how organizations collect, store, process and transfer personal data. Fines can reach €20 million or 4% of global annual turnover. GDPR requires reporting breaches affecting personal data within 72 hours, making security audits a practical requirement for any organization handling EU citizens' data.
Cloud SecurityCloud Security
InfrastructurePractices, technologies and controls designed to protect data, applications and infrastructure hosted in cloud environments (AWS, Azure, Google Cloud). Cloud security follows a shared responsibility model: the provider secures physical and virtualization infrastructure, but securing what runs inside (configurations, access, code, data) is the customer's responsibility. Most common audit findings: exposed S3 buckets, overly permissive security groups and hardcoded API keys.
DevSecOpsDevelopment Security Operations
MethodologiesPhilosophy integrating security practices into every phase of the software development lifecycle (CI/CD), instead of adding them at the end. DevSecOps automates security testing (SAST, DAST, SCA, secret scanning) in the continuous integration pipeline to detect vulnerabilities before production. The goal is shifting security left: the earlier a flaw is found, the cheaper and faster it is to fix.
Supply Chain AttackSupply Chain Attack
ThreatsAttack compromising an organization through a trusted third party: a software vendor, an open-source library, a cloud service or a partner with system access. Supply chain attacks are devastating because one upstream compromise can affect thousands of downstream organizations. Notable examples include SolarWinds (2020), Kaseya (2021) and xz-utils/libzma (2024). Defense: audit suppliers, verify software integrity before deployment and apply least privilege to third-party access.
SQL Injection (SQLi)SQL Injection
WebVulnerability allowing an attacker to inject malicious SQL commands into web application input fields, gaining unauthorized access to read, modify or delete database data. Despite being one of the oldest known vulnerabilities (in the OWASP Top 10 since its first edition), SQL injection still appears in modern security audits, especially in legacy applications and internal APIs.
XSS (Cross-Site Scripting)Cross-Site Scripting
WebVulnerability allowing an attacker to inject malicious JavaScript into web pages viewed by other users. Three main types: reflected XSS (code travels in the HTTP request itself), stored XSS (code saved in the database, executed every time a user visits the affected page) and DOM-based XSS (vulnerability in client-side JavaScript). Successful XSS can steal session cookies, saved credentials or redirect victims to phishing sites.
CSRFCross-Site Request Forgery
WebAttack forcing an authenticated user to execute unwanted actions in a web application where they have an active session. The attacker creates a malicious page that, when visited, automatically sends a request to the target application using the victim's session cookies. Standard defense: unique per-session anti-CSRF tokens validated by the server on every state-changing request.
SSRFServer-Side Request Forgery
WebVulnerability allowing an attacker to force the server to make HTTP requests to arbitrary destinations, including internal resources that should not be accessible externally. Successful SSRF can access cloud instance metadata (like AWS IMDS), internal services, or perform port scans on the internal network using the vulnerable server as a proxy. Particularly dangerous in cloud environments where it can expose temporary IAM credentials.
RCERemote Code Execution
ThreatsAbility of an attacker to execute arbitrary commands or code on a remote system without authorization. RCE is the most severe vulnerability category because it gives the attacker total control of the affected system. Achievable through multiple vectors: insecure deserialization, command injection, buffer overflows, scripting engine vulnerabilities or file format parsing flaws. Unauthenticated RCE on an internet-exposed system is the most critical scenario in offensive security.
Local Privilege EscalationLocal Privilege Escalation
OffensiveTechnique allowing a limited-privilege user to obtain higher privileges (typically admin/root) on the same system by exploiting misconfiguration, a vulnerable binary or a kernel flaw. On Windows, tools like WinPEAS automate LPE vector enumeration. On Linux, classic techniques include SUID binary exploitation, misconfigured Linux capabilities, root cron jobs and kernel exploits like Dirty COW or its modern variant pedit COW (CVE-2026-46331).
Lateral MovementLateral Movement
OffensiveTechnique allowing an attacker, after compromising an initial system, to move through the network toward higher-value systems. Lateral movement relies on credential reuse (Pass-the-Hash, Pass-the-Ticket), trust relationship exploitation and abuse of legitimate admin tools (PSExec, WMI, WinRM, RDP) to avoid detection. It is the most critical attack phase — when the attacker goes from a foothold to controlling the infrastructure.
PersistencePersistence
OffensiveTechniques an attacker uses to maintain access to a compromised system across reboots, credential changes and other disruptions. Common persistence mechanisms: scheduled tasks, system services, Run registry keys, web shells, firmware backdoors and modification of legitimate system binaries (DLL sideloading). Sophisticated attackers deploy multiple redundant persistence mechanisms to ensure at least one survives remediation.
Data ExfiltrationData Exfiltration
ThreatsUnauthorized transfer of data from a compromised system to the outside, typically to attacker-controlled servers. Exfiltration can use multiple channels: HTTP/HTTPS, DNS tunneling, messaging protocols, cloud storage or even physical channels. Detection is difficult because outbound traffic is normal in any organization and attackers disguise stolen data as legitimate traffic (encryption, compression, fragmentation).
APTAdvanced Persistent Threat
ThreatsHighly sophisticated threat actor, typically state-sponsored, maintaining a prolonged and stealthy presence in target networks to steal strategic information or prepare sabotage capabilities. APTs are characterized by patience (months or years-long campaigns), resources (dedicated teams, zero-day exploits, own infrastructure) and targeting (specific high-value objectives). Notable examples: APT29/Cozy Bear (Russia), APT41 (China), Lazarus Group (North Korea).
OSINTOpen Source Intelligence
MethodologiesCollection and analysis of publicly available information about a target to build actionable intelligence. In offensive security, OSINT is used in the initial phases of a pentest or Red Team to map the attack surface: domains, subdomains, exposed IPs, employees on LinkedIn, leaked credentials, public code repositories and cloud service configurations. Tools like theHarvester, Shodan, Censys and Maltego are standard.
ShodanShodan
ToolsSearch engine indexing internet-connected devices: servers, routers, IP cameras, industrial systems (ICS/SCADA), databases and security appliances. Unlike Google, which indexes web content, Shodan indexes service banners and connection metadata. It's the most used tool in pentesting reconnaissance to identify unprotected exposed services, outdated software versions and default configurations.
MetasploitMetasploit Framework
ToolsOpen-source framework for developing, testing and executing exploits. Metasploit standardizes the exploitation process: the pentester selects an exploit module for a specific vulnerability, configures a payload (code executed after successful exploitation) and launches the attack. Includes modules for reconnaissance, exploitation, post-exploitation and persistence, with an exploit database constantly updated with the latest published vulnerabilities.
Burp SuiteBurp Suite
ToolsIntegrated platform for web application pentesting developed by PortSwigger. Burp Suite acts as an intercepting proxy between browser and web server, allowing the pentester to inspect, modify and resend HTTP requests. Includes modules for automated vulnerability scanning (Scanner), parameter fuzzing (Intruder), second-order vulnerability detection (Collaborator) and repetitive test automation (Repeater). The de facto standard tool in professional web audits.
NmapNetwork Mapper
ToolsOpen-source tool for network discovery and port scanning. Nmap sends specially designed packets to target hosts and analyzes responses to determine open ports, running services and versions, and the host's operating system. One of the oldest and most used tools in any pentester's arsenal. Its scripting engine (NSE) extends capabilities with custom scripts for vulnerability detection and advanced enumeration.
Cobalt StrikeCobalt Strike
ToolsCommercial adversary emulation platform used in Red Team exercises and, unfortunately, by real malicious actors. Cobalt Strike provides advanced command and control (C2), lateral movement, defense evasion and post-exploitation capabilities. Its Beacon is a modular payload enabling covert communication over multiple protocols (HTTP, HTTPS, DNS, SMB) and has become the de facto standard for emulating advanced adversaries in professional offensive exercises.
CI/CD PipelineCI/CD Pipeline
InfrastructureAutomated flow building, testing and deploying software from source code to production. CI/CD pipelines are high-value targets for attackers because they contain secrets (API keys, tokens, deployment passwords), access code repositories and can modify production software. A compromised pipeline can inject malicious code into software distributed to all customers (supply chain attack). Pipeline security is a natural extension of source code audits.
WAFWeb Application Firewall
DefensiveFirewall specialized in the application layer (OSI layer 7) that inspects, filters and blocks HTTP/S traffic to web applications. A WAF protects against common attacks like SQL injection, XSS, CSRF, local/remote file inclusion (LFI/RFI) and brute force. WAFs can be network-based (physical appliance), host-based (software on the web server) or cloud-based (Cloudflare, AWS WAF, Azure Application Gateway). Pentesters dedicate significant effort to finding WAF bypass techniques.
Mobile PentestingMobile Penetration Testing
OffensiveSecurity assessment specific to mobile applications (Android/iOS) covering static analysis (APK/IPA reversing, decompiled code analysis, hardcoded secret hunting), dynamic analysis (traffic interception with proxy, runtime manipulation with Frida/Objection) and backend communication assessment (API security, certificate pinning, insecure local storage). Mobile apps are a frequently forgotten vector in corporate security plans.
WiFi Security AuditWiFi Security Audit
OffensiveAssessment of an organization's wireless network security: access points, encryption protocols (WPA2/WPA3/802.1X), captive portals, guest network segmentation and radio configurations. A WiFi audit includes WPA handshake cracking tests, deauthentication attacks, Evil Twin AP spoofing, WPS attacks and captive portal bypass. Poorly segmented corporate WiFi can give an attacker direct internal network access just by being in the parking lot.
FuzzingFuzzing
MethodologiesAutomated testing technique sending random, unexpected or malformed data to an application and monitoring its behavior for crashes, memory leaks or anomalies indicating a vulnerability. Fuzzing is especially effective for finding flaws in protocol parsers, media codecs, file formats and APIs. Tools like AFL (American Fuzzy Lop), libFuzzer and Honggfuzz have discovered thousands of vulnerabilities in widely used software.
HardeningSystem Hardening
DefensiveProcess of reducing a system's attack surface by removing unnecessary services, applying strict security configurations, disabling unused features and applying the latest security patches. Hardening follows standardized guides like CIS benchmarks or DISA STIGs. A freshly installed server with default configuration can have dozens of exploitable vulnerabilities; after proper hardening, the attack surface is drastically reduced.
Threat HuntingThreat Hunting
DefensiveProactive, systematic search for threats already inside the network but undetected by automated security systems. Unlike passive monitoring (waiting for an alert), threat hunting formulates attack hypotheses based on threat intelligence, known TTPs and environment knowledge, then actively searches logs, traffic and endpoints for evidence. A good threat hunter thinks like an attacker to find what automated tools miss.
DFIRDigital Forensics and Incident Response
DefensiveDiscipline combining digital forensics (collection, preservation and analysis of digital evidence) with incident response (containment, eradication and recovery after a cyberattack). DFIR's goal is twofold: determine what happened, how and which data was compromised (forensics), and restore normal operations minimizing impact while preventing recurrence (response). Evidence collected must be admissible in court, making chain of custody critical.
Patch ManagementPatch Management
DefensiveSystematic process of identifying, testing and deploying security updates across all organizational systems. An effective patching policy distinguishes criticality levels: CISA KEV catalog vulnerabilities must be patched within 72 hours, critical flaws (CVSS > 9) within a week, and the rest per the regular maintenance window. Most security incidents exploit vulnerabilities that already had patches: the problem isn't vulnerability existence but patch process slowness.
Security TokenSecurity Token
FundamentalsPhysical device or software generating one-time codes (OTP — One-Time Password) for multi-factor authentication. Tokens can be hardware (USB keys like YubiKey, smart cards), software (apps like Google Authenticator or Microsoft Authenticator) or SMS-based (vulnerable to SIM swapping). In offensive security, session token theft (session hijacking) is a common technique to impersonate legitimate users without knowing their password or second factor.
HoneypotHoneypot
DefensiveDecoy system designed to attract attackers, detect their presence and study their techniques without risking real systems. Honeypots can be low-interaction (simulating basic services) or high-interaction (real systems fully compromisable under observation). In corporate environments, honeypots serve as early warning systems: any honeypot activity is inherently suspicious because no legitimate user should interact with it.
DLPData Loss Prevention
DefensiveTechnologies and policies designed to prevent sensitive data (financial information, intellectual property, personal data) from being extracted without authorization. DLP systems monitor data at rest (databases, file servers), in motion (network traffic, email) and in use (endpoints, USB devices) for exfiltration patterns. A well-configured DLP can automatically block the exfiltration of a credit card number or national ID via email.
SandboxSandbox
DefensiveIsolated, controlled environment where potentially malicious software runs to observe its behavior without risk to the real system. Sandboxes are used by malware analysts, EDR systems (detonating files before execution on real endpoints) and web browsers (isolating tabs and extensions). Modern malware includes sandbox evasion techniques: detecting virtualized environments and behaving innocuously to hide capabilities.
Vulnerability TriageVulnerability Triage
MethodologiesProcess of evaluating, prioritizing and assigning resources for remediating vulnerabilities discovered during a security audit. Not all vulnerabilities are equally urgent: an RCE on an internet-exposed system needs immediate correction, while a low-severity flaw on an internal system can wait for the next maintenance window. Effective triage prevents security teams from being paralyzed by endless finding lists and focuses resources where they matter.
Looking for more than definitions?
At MagnoSec we apply all these concepts in real audits. If you want to know how secure your business is, request a no-obligation assessment.