Attack Surface
The sum total of all potential entry vectors, interfaces, and code vulnerabilities that an unauthorized adversary can target to breach a system.
The sum total of all potential entry vectors, interfaces, and code vulnerabilities that an unauthorized adversary can target to breach a system.
The chronological and legally rigorous documentation tracking digital evidence from the precise moment of collection through investigation to preserve integrity.
The foundational information security model standing for Confidentiality, Integrity, and Availability, which forms the core operational objective of security controls.
A highly stealthy category of malware specialized in harvesting active browser session cookies, local authorization tokens, saved login credentials, and digital crypto-wallets directly from device memory to perform automated account takeover without password cracking.
A verification paradigm that enforces identity validation across distinct categories: something you know (knowledge), something you have (possession), and something you are (inherence).
A phishing-resistant authentication method based on FIDO2 and WebAuthn standards that replaces standard strings with unique, hardware-protected public-key cryptographic pairs bound strictly to a target domain.
An access management model dictating that user profiles and automated processing tools must operate with the absolute bare minimum system permissions required to execute their specific assignments.
An exploratory social engineering vector that wraps malicious tracking or harvesting hyperlinks inside an image-based QR code matrix, bypassing security mail gateways and moving the attack onto an unmonitored mobile endpoint.
A category of extortion malware that selectively targets files or drives for unauthorized encryption, halting system usability until financial terms are met.
A technology suite that aggregates, normalizes, and correlates security log feeds across an entire infrastructure layout to trigger proactive alerts for anomalous behavior patterns.
A bug, flaw, or systemic misconfiguration present within an application, infrastructure design, or operational habit that can be leveraged by a threat actor to gain unauthorized privileges.
« Previous: Careers, Labs, and Next Steps — Next: Free Online Resources (Curated by Category) »