Security Glossary

Plain-language definitions for the terms you'll encounter in attack surface management.

A

ACME
ACME (Automatic Certificate Management Environment) is a protocol, defined in RFC 8555, that automates TLS certificate issuance and renewal by proving domain control to a certificate authority.
Admin Panel
An admin panel is a web-based management interface that provides administrative control over a server, application, database, or network device.
API Endpoint Discovery
API endpoint discovery is the process of finding an organisation's reachable API paths and hosts, including undocumented, deprecated and internal endpoints exposed to the internet.
Asset Discovery
Asset discovery is the process of identifying all the systems, domains, services, and cloud resources an organisation owns or exposes, forming the inventory that security monitoring depends on.
ASV Scan
An ASV scan is an external vulnerability scan of an internet-facing cardholder data environment performed by an Approved Scanning Vendor qualified by the PCI Security Standards Council.
Attack Surface
An attack surface is the sum of all points where an unauthorised user could attempt to enter, attack, or extract data from a system, including exposed services, applications, and people.
Attack Surface Reduction
Attack surface reduction is the practice of removing or restricting reachable entry points -- services, ports, interfaces and accounts -- so there is less for an attacker to interact with.
Attack Vector
An attack vector is the specific path or method an attacker uses to reach a target and gain access, such as an exposed service, a phishing email, or a stolen set of credentials.

B

Banner Grabbing
Banner grabbing is the technique of collecting the identifying information a network service sends when a client connects, revealing the software name and version running on an open port.
BEC
Business email compromise (BEC) is a fraud in which an attacker impersonates a trusted party by email -- an executive, supplier, or colleague -- to redirect payments or extract sensitive data.
BIMI
BIMI (Brand Indicators for Message Identification) is an email standard that displays a brand's verified logo beside authenticated messages in supporting inboxes; it requires DMARC enforcement.

C

CAA Record
A CAA (Certification Authority Authorization) record is a DNS record that specifies which certificate authorities are permitted to issue TLS certificates for a domain.
Certificate Authority
A certificate authority (CA) is an organisation that verifies control of a domain and issues signed TLS certificates. Browsers and operating systems decide which CA roots they trust.
Certificate Chain
A certificate chain is the ordered set of certificates linking a server's TLS certificate through intermediate CAs to a trusted root, allowing clients to verify the certificate's authenticity.
Certificate Pinning
Certificate pinning makes a client accept only specific certificates or public keys for a host, instead of any certificate from a trusted CA. It is now used mainly in mobile and desktop apps.
Certificate Revocation
Certificate revocation declares a certificate invalid before it expires, usually after key compromise or mis-issuance. Clients learn about it through CRLs, OCSP or vendor-pushed revocation data.
Certificate Transparency Logs
Certificate Transparency (CT) logs are public, append-only records of TLS certificates issued by certificate authorities, enabling domain owners to detect unauthorised certificate issuance.
Cipher Suite
A cipher suite is a named combination of cryptographic algorithms used to secure a TLS connection, specifying the key exchange, authentication, encryption, and message integrity methods.
CIS Benchmarks
CIS Benchmarks are consensus-developed secure configuration guides published by the Center for Internet Security for operating systems, cloud platforms, network devices and applications.
Clickjacking
Clickjacking tricks a user into clicking something other than what they perceive, usually by framing a target page invisibly over bait, so the click performs an action on the framed site.
CNAME Record
A CNAME record maps one DNS name onto another name rather than an address, so a resolver follows the alias and looks up the target's records instead.
Continuous Threat Exposure Management
Continuous threat exposure management (CTEM) is a security programme that continuously scopes, discovers, prioritises, validates, and mobilises against exposures across an organisation's assets.
CORS Misconfiguration
A CORS misconfiguration is an overly permissive cross-origin policy -- such as reflecting any origin while allowing credentials -- that lets attacker sites read authenticated responses.
CPE
CPE (Common Platform Enumeration) is a structured naming scheme for hardware, operating systems, and applications, used by NIST's NVD to record which products a vulnerability affects.
Credential Stuffing
Credential stuffing replays username and password pairs leaked in other breaches against a target's login pages, exploiting password reuse rather than any flaw in the target's software.
Cross-Site Scripting
Cross-site scripting (XSS) is a flaw where an application places attacker-controlled data into a page without correct escaping, so the browser executes it as script within the site's own origin.
CSP
Content-Security-Policy (CSP) is an HTTP response header that restricts which content sources a browser may load on a page, preventing cross-site scripting and data injection attacks.
CVE
Common Vulnerabilities and Exposures—a unique identifier for publicly disclosed security vulnerabilities, maintained by MITRE and scored by the NVD.
CVSS
Common Vulnerability Scoring System—a standardised framework assigning severity scores (0.0–10.0) to security vulnerabilities based on exploitability and impact.
Cyber Essentials
Cyber Essentials is a UK certification scheme, owned by the NCSC and delivered by IASME, based on self-assessment against five technical control themes and verified by a certification body.
Cyber Essentials Plus
Cyber Essentials Plus covers the same five control themes as Cyber Essentials but adds hands-on technical verification by an independent assessor instead of relying on self-assessment.

D

Dangling DNS Record
A dangling DNS record is an entry that still points at a resource which no longer exists -- a released IP address or a deprovisioned cloud service -- leaving the name open to being claimed.
DAST
Dynamic application security testing (DAST) analyses a running application from the outside by sending requests and observing responses to find vulnerabilities, without access to source code.
Database Exposure
Database exposure is a database service listening on a public address, letting anyone on the internet attempt to connect and, where authentication is weak or absent, read or alter the data.
Default Credentials
Default credentials are the factory usernames and passwords shipped with software and devices. Left unchanged on an internet-facing system, they grant access with no exploit required.
Defence in Depth
Defence in depth is the practice of layering independent security controls so that the failure or bypass of any single control does not by itself lead to compromise.
Directory Listing
Directory listing is a web server generating an index of files when no default document exists, exposing backups, archives and configuration that were never meant to be browsable.
DKIM
DKIM (DomainKeys Identified Mail) is an email authentication method that uses cryptographic signatures to verify that an email was sent by an authorised server and was not modified in transit.
DMARC
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a DNS-based email policy that uses SPF and DKIM to prevent domain spoofing and provides reporting on authentication results.
DMARC Alignment
DMARC alignment is the requirement that the domain validated by SPF or DKIM matches the domain in the visible From header, ensuring authentication applies to the address the recipient sees.
DNS over HTTPS
DNS over HTTPS (DoH) carries DNS queries inside encrypted HTTPS requests, as defined in RFC 8484, so on-path observers cannot read or alter lookups between client and resolver.
DNS Propagation
DNS propagation is the delay between changing a record and every resolver serving the new value. It is caused by cached answers expiring at their TTL, not by data spreading between servers.
DNS Record Types
DNS record types define what data an answer carries -- A and AAAA for addresses, CNAME for aliases, NS for delegation, MX for mail routing, and TXT for text used by policies like SPF.
DNS Zone Transfer
A DNS zone transfer (AXFR) copies a zone's complete record set from one name server to another. Left open to the public internet, it hands an attacker a full inventory of a domain's hosts.
DNSSEC
DNSSEC adds cryptographic signatures to DNS records so a validating resolver can confirm answers came from the authoritative zone and were not altered. It provides authenticity, not confidentiality.
Domain Hijacking
Domain hijacking is the unauthorised transfer or alteration of a domain's registration or DNS, letting an attacker redirect traffic, intercept mail and obtain certificates for the whole domain.
Domain Registrar
A domain registrar is an accredited company that registers domain names for customers and submits those registrations to the registry operating the relevant top-level domain.

E

Elasticsearch Exposure
Elasticsearch exposure is an Elasticsearch cluster reachable over the internet on its HTTP API, typically on port 9200, allowing index contents to be listed and read without credentials.
EPSS
EPSS (Exploit Prediction Scoring System) is a FIRST-maintained model that estimates the probability, from 0 to 1, that a vulnerability will be exploited in the wild in the next 30 days.
Exploit
An exploit is code or a technique that takes advantage of a vulnerability to make a system behave unintendedly -- running commands, bypassing authentication, or disclosing protected data.
External Attack Surface Management
External attack surface management (EASM) is the continuous discovery, monitoring, and assessment of an organisation's internet-facing assets from an attacker's outside-in perspective.

F

FTP
FTP (File Transfer Protocol) is a legacy file transfer protocol on TCP port 21 that sends credentials and data in plaintext, offering no confidentiality or integrity protection.

G

GDPR Article 32
Article 32 of the GDPR requires controllers and processors to implement technical and organisational measures appropriate to the risk, including regular testing of those measures' effectiveness.
GraphQL Introspection
GraphQL introspection is a built-in feature that lets a client query a server for its full schema -- every type, field, argument and mutation -- which also helps attackers when left public.

H

Heartbleed
Heartbleed (CVE-2014-0160) was a 2014 bug in OpenSSL's TLS heartbeat extension that let a peer read up to 64KB of the other side's process memory, potentially exposing keys and session data.
Homoglyph Attack
A homoglyph attack uses visually similar or identical characters, such as Cyrillic 'а' in place of Latin 'a', in domain names or text to impersonate legitimate sites and deceive users.
HSTS
HTTP Strict Transport Security (HSTS) is a security header that forces browsers to connect to a site exclusively over HTTPS, preventing protocol downgrade and SSL stripping attacks.
HTTP to HTTPS Redirect
An HTTP-to-HTTPS redirect answers plaintext requests with a permanent redirect to the HTTPS URL. It is the first step towards HTTPS-only, but only HSTS prevents the initial insecure request.

I

Internationalised Domain Name
An internationalised domain name (IDN) contains characters outside ASCII letters, digits and hyphens. Applications convert it to Punycode with an xn-- prefix before any DNS lookup.
ISO 27001
ISO/IEC 27001 is an international standard specifying requirements for an information security management system, against which organisations can be certified by an accredited certification body.

K

KEV Catalogue
The KEV catalogue is CISA's list of vulnerabilities with reliable evidence of exploitation in the wild, each carrying a remediation due date binding on US federal civilian agencies.

L

Least Privilege
Least privilege is the principle that every user, process and system should hold only the permissions needed for its task, and only for as long as it needs them.
Login Fingerprinting
Login fingerprinting is the technique of identifying the software behind a login page by analysing its HTML structure, HTTP headers, favicon, and other response characteristics.

M

MITRE ATT&CK
MITRE ATT&CK is a publicly available knowledge base of adversary tactics and techniques, maintained by MITRE and based on behaviour observed in real-world intrusions.
Mixed Content
Mixed content is an HTTPS page loading subresources over plain HTTP. Browsers block active mixed content such as scripts and iframes, and upgrade or block passive content like images.
MTA-STS
MTA-STS (Mail Transfer Agent Strict Transport Security) is a standard, defined in RFC 8461, that lets a domain require TLS encryption for inbound SMTP, preventing downgrade and interception attacks.
MX Record
An MX record is a DNS entry naming a mail server that accepts email for a domain, with a preference value that tells senders which server to try first.

N

Network Segmentation
Network segmentation divides a network into zones with controlled traffic between them, so that a compromise in one zone does not give an attacker reach across the whole estate.
NIS2
NIS2 is the EU directive on the security of network and information systems, replacing the 2016 NIS Directive and imposing risk-management, reporting and governance duties on in-scope entities.
NS Record
An NS record names an authoritative name server for a DNS zone. Parent zones publish NS records to delegate a subdomain, and every zone lists its own name servers at its apex.
Nuclei
Open-source vulnerability scanner by ProjectDiscovery using YAML-based templates to detect CVEs, misconfigurations, and exposures in web applications and services.
NVD
The NVD (National Vulnerability Database) is NIST's repository of CVE records enriched with CVSS severity scores, CPE product identifiers, and CWE weakness classifications.

O

OCSP
OCSP (Online Certificate Status Protocol) is a protocol, defined in RFC 6960, for checking in real time whether a TLS certificate has been revoked by its issuing certificate authority.
OSINT
OSINT (open-source intelligence) is intelligence built from publicly available sources -- DNS records, certificate logs, code repositories, filings -- without accessing the target directly.
OWASP Top Ten
The OWASP Top Ten is an awareness document from the Open Worldwide Application Security Project listing the most critical categories of web application security risk, revised periodically.

P

Passive DNS
Passive DNS is a historical archive of observed DNS resolutions, collected by sensors and resolvers, that shows which names have pointed at which addresses over time.
Patch Management
Patch management is the process of identifying, testing, applying, and verifying software and firmware updates so that known vulnerabilities are remediated before they can be exploited.
PCI DSS External Scanning
PCI DSS requires external vulnerability scans of internet-facing cardholder data environment systems at least quarterly and after significant changes, performed by a PCI-approved scanning vendor.
Penetration Testing
Penetration testing is an authorised, time-boxed assessment in which testers attempt to exploit weaknesses within an agreed scope and report what access they were able to achieve.
Perfect Forward Secrecy
Perfect forward secrecy means session keys come from an ephemeral key exchange, so an attacker who records traffic and later obtains the server's private key still cannot decrypt those sessions.
Permissions-Policy
Permissions-Policy is an HTTP header that declares which browser features a page and its embedded frames may use, such as camera, microphone, geolocation and payment request.
POODLE Attack
POODLE (CVE-2014-3566) was a 2014 padding-oracle attack on SSL 3.0's CBC cipher modes, letting an on-path attacker who could force a downgrade recover plaintext such as session cookies.
Port Scanning
Port scanning is the process of probing a host's TCP or UDP ports to determine which are open and what services they run, used by both attackers and defenders to map exposure.
Proof-of-Concept Exploit
A proof-of-concept (PoC) exploit is minimal code published to demonstrate that a vulnerability is genuinely exploitable, usually without the reliability or payload of a weaponised exploit.
Punycode
Punycode is an encoding defined in RFC 3492 that represents Unicode domain labels using only ASCII characters. Encoded labels carry an xn-- prefix so DNS can transport international names.

R

Ransomware
Ransomware is malware that encrypts a victim's data, and often steals it as well, so that the operator can demand payment for decryption or for not publishing the stolen files.
RDP
RDP (Remote Desktop Protocol) is Microsoft's protocol for remote graphical access to Windows systems, listening by default on TCP port 3389 and frequently targeted when exposed to the internet.
Reconnaissance
Reconnaissance is the information-gathering phase of an attack, in which an adversary maps a target's domains, hosts, services, and people before attempting any exploitation.
Red Team
A red team emulates a real adversary's tactics against an organisation over an extended engagement, testing detection and response as much as technical weaknesses.
Referrer-Policy
Referrer-Policy is an HTTP header, also settable per element, that controls how much of the current URL a browser includes in the Referer header of outgoing requests.
Reverse DNS
Reverse DNS resolves an IP address to a hostname using PTR records in the in-addr.arpa or ip6.arpa zones -- the opposite direction to an ordinary forward lookup.

S

S3 Bucket Exposure
S3 bucket exposure is cloud object storage made readable or writable by anyone, through permissive access controls or policies, allowing files to be listed and downloaded without credentials.
SAST
Static application security testing (SAST) analyses an application's source code, bytecode, or binaries for security vulnerabilities without executing the program.
Security Misconfiguration
Security misconfiguration is a weakness caused by insecure settings rather than a software flaw -- defaults left in place, unnecessary features enabled, or protections never switched on.
Self-Signed Certificate
A self-signed certificate is signed with its own private key rather than by a certificate authority, so no public trust chain validates it and browsers show a warning before proceeding.
Server Header Disclosure
Server header disclosure is a response advertising software and version details in headers such as Server and X-Powered-By, giving an attacker a version to match against known vulnerabilities.
Service Fingerprinting
Service fingerprinting identifies the specific software and version running on an open network port by analysing protocol responses, banners, and behavioural characteristics.
Shadow IT
Shadow IT is technology assets - servers, applications, SaaS tools, and cloud instances - deployed within an organisation without the knowledge or approval of IT and security departments.
SMB Protocol
SMB (Server Message Block) is the Windows file and printer sharing protocol, listening on TCP port 445, which should never be reachable from the internet.
SOC 2
SOC 2 is an AICPA reporting framework under which a licensed CPA firm examines a service organisation's controls against the Trust Services Criteria and issues an attestation report.
SPF
SPF (Sender Policy Framework) is a DNS TXT record that specifies which mail servers are authorised to send email for a domain, helping prevent email spoofing.
SPF Lookup Limit
SPF evaluation is capped at 10 DNS-querying mechanisms. Exceeding the limit makes receivers return permerror, so the record stops authorising any of the domain's legitimate senders.
SSH
SSH (Secure Shell) is an encrypted protocol for remote command-line access, file transfer and tunnelling, listening by default on TCP port 22.
Subdomain Takeover
A subdomain takeover is an attack where an attacker claims an external resource (S3 bucket, Heroku app) that a subdomain's DNS still references, gaining control of the subdomain.
Subresource Integrity
Subresource Integrity (SRI) lets a page attach a cryptographic hash to a script or stylesheet tag, so the browser refuses to use the file if its contents do not match the expected hash.

T

TCP Port
A TCP port is a numbered endpoint (0-65535) on a networked device that identifies a specific service or application. Open TCP ports accept incoming connections from other systems.
Telnet
Telnet is a legacy remote terminal protocol on TCP port 23 that transmits credentials and session data in plaintext, superseded by SSH but still present on older devices.
Threat Actor
A threat actor is an individual or group that conducts, or intends to conduct, malicious activity against systems or data -- from opportunistic criminals to state-sponsored operators.
TLS
TLS (Transport Layer Security) is a cryptographic protocol that encrypts data transmitted between a client and server, protecting against eavesdropping and tampering. It is the successor to SSL.
TLS Handshake
The TLS handshake is the negotiation that opens a TLS connection: the peers agree a version and cipher suite, the server authenticates with its certificate, and shared session keys are derived.
TLS-RPT
TLS-RPT (SMTP TLS Reporting) is a standard, defined in RFC 8460, that lets a domain receive daily reports from sending mail servers about TLS connection failures affecting its inbound email.
TXT Record
A TXT record holds free-form text in DNS. It carries machine-readable policies such as SPF, DKIM keys and DMARC, plus ownership verification tokens issued by third-party services.
Typosquatting
Typosquatting is the registration of domain names that are misspellings or variations of legitimate domains, used to capture mistyped traffic for phishing, malware delivery, or fraud.

V

VPN Gateway
A VPN gateway is the internet-facing device or service that terminates VPN tunnels, authenticating remote users or sites and bridging them into an internal network.
Vulnerability Management
Vulnerability management is the ongoing process of identifying, assessing, prioritising, and remediating security vulnerabilities across an organisation's systems and software.

W

Web Application Firewall
A web application firewall inspects HTTP requests and responses in front of an application, blocking, challenging or logging traffic that matches attack patterns or violates policy.
WHOIS
WHOIS is a query protocol and record set that returns registration details for a domain or IP range, including registrar, name servers, and key dates. RDAP is its modern successor.
Wildcard Certificate
A wildcard certificate is a TLS certificate that secures a domain's first-level subdomains using an asterisk label (e.g. *.example.com), so one certificate covers many hostnames.

X

X-Frame-Options
X-Frame-Options is an HTTP header that controls whether a page can be embedded in frames (iframe, frame, embed, object), preventing clickjacking attacks.

Z

Zero-Day
A zero-day is a vulnerability that is being exploited or is publicly known before the vendor has a patch available, leaving defenders with no official fix to apply.