- Home
- Glossary
Security Glossary
Plain-language definitions for the terms you'll encounter in attack surface management.
A
- ACME
- ACME (Automatic Certificate Management Environment) is a protocol, defined in RFC 8555, that automates TLS certificate issuance and renewal by proving domain control to a certificate authority.
- Admin Panel
- An admin panel is a web-based management interface that provides administrative control over a server, application, database, or network device.
- API Endpoint Discovery
- API endpoint discovery is the process of finding an organisation's reachable API paths and hosts, including undocumented, deprecated and internal endpoints exposed to the internet.
- Asset Discovery
- Asset discovery is the process of identifying all the systems, domains, services, and cloud resources an organisation owns or exposes, forming the inventory that security monitoring depends on.
- ASV Scan
- An ASV scan is an external vulnerability scan of an internet-facing cardholder data environment performed by an Approved Scanning Vendor qualified by the PCI Security Standards Council.
- Attack Surface
- An attack surface is the sum of all points where an unauthorised user could attempt to enter, attack, or extract data from a system, including exposed services, applications, and people.
- Attack Surface Reduction
- Attack surface reduction is the practice of removing or restricting reachable entry points -- services, ports, interfaces and accounts -- so there is less for an attacker to interact with.
- Attack Vector
- An attack vector is the specific path or method an attacker uses to reach a target and gain access, such as an exposed service, a phishing email, or a stolen set of credentials.
B
- Banner Grabbing
- Banner grabbing is the technique of collecting the identifying information a network service sends when a client connects, revealing the software name and version running on an open port.
- BEC
- Business email compromise (BEC) is a fraud in which an attacker impersonates a trusted party by email -- an executive, supplier, or colleague -- to redirect payments or extract sensitive data.
- BIMI
- BIMI (Brand Indicators for Message Identification) is an email standard that displays a brand's verified logo beside authenticated messages in supporting inboxes; it requires DMARC enforcement.
C
- CAA Record
- A CAA (Certification Authority Authorization) record is a DNS record that specifies which certificate authorities are permitted to issue TLS certificates for a domain.
- Certificate Authority
- A certificate authority (CA) is an organisation that verifies control of a domain and issues signed TLS certificates. Browsers and operating systems decide which CA roots they trust.
- Certificate Chain
- A certificate chain is the ordered set of certificates linking a server's TLS certificate through intermediate CAs to a trusted root, allowing clients to verify the certificate's authenticity.
- Certificate Pinning
- Certificate pinning makes a client accept only specific certificates or public keys for a host, instead of any certificate from a trusted CA. It is now used mainly in mobile and desktop apps.
- Certificate Revocation
- Certificate revocation declares a certificate invalid before it expires, usually after key compromise or mis-issuance. Clients learn about it through CRLs, OCSP or vendor-pushed revocation data.
- Certificate Transparency Logs
- Certificate Transparency (CT) logs are public, append-only records of TLS certificates issued by certificate authorities, enabling domain owners to detect unauthorised certificate issuance.
- Cipher Suite
- A cipher suite is a named combination of cryptographic algorithms used to secure a TLS connection, specifying the key exchange, authentication, encryption, and message integrity methods.
- CIS Benchmarks
- CIS Benchmarks are consensus-developed secure configuration guides published by the Center for Internet Security for operating systems, cloud platforms, network devices and applications.
- Clickjacking
- Clickjacking tricks a user into clicking something other than what they perceive, usually by framing a target page invisibly over bait, so the click performs an action on the framed site.
- CNAME Record
- A CNAME record maps one DNS name onto another name rather than an address, so a resolver follows the alias and looks up the target's records instead.
- Continuous Threat Exposure Management
- Continuous threat exposure management (CTEM) is a security programme that continuously scopes, discovers, prioritises, validates, and mobilises against exposures across an organisation's assets.
- CORS Misconfiguration
- A CORS misconfiguration is an overly permissive cross-origin policy -- such as reflecting any origin while allowing credentials -- that lets attacker sites read authenticated responses.
- CPE
- CPE (Common Platform Enumeration) is a structured naming scheme for hardware, operating systems, and applications, used by NIST's NVD to record which products a vulnerability affects.
- Credential Stuffing
- Credential stuffing replays username and password pairs leaked in other breaches against a target's login pages, exploiting password reuse rather than any flaw in the target's software.
- Cross-Site Scripting
- Cross-site scripting (XSS) is a flaw where an application places attacker-controlled data into a page without correct escaping, so the browser executes it as script within the site's own origin.
- CSP
- Content-Security-Policy (CSP) is an HTTP response header that restricts which content sources a browser may load on a page, preventing cross-site scripting and data injection attacks.
- CVE
- Common Vulnerabilities and Exposures—a unique identifier for publicly disclosed security vulnerabilities, maintained by MITRE and scored by the NVD.
- CVSS
- Common Vulnerability Scoring System—a standardised framework assigning severity scores (0.0–10.0) to security vulnerabilities based on exploitability and impact.
- Cyber Essentials
- Cyber Essentials is a UK certification scheme, owned by the NCSC and delivered by IASME, based on self-assessment against five technical control themes and verified by a certification body.
- Cyber Essentials Plus
- Cyber Essentials Plus covers the same five control themes as Cyber Essentials but adds hands-on technical verification by an independent assessor instead of relying on self-assessment.
D
- Dangling DNS Record
- A dangling DNS record is an entry that still points at a resource which no longer exists -- a released IP address or a deprovisioned cloud service -- leaving the name open to being claimed.
- DAST
- Dynamic application security testing (DAST) analyses a running application from the outside by sending requests and observing responses to find vulnerabilities, without access to source code.
- Database Exposure
- Database exposure is a database service listening on a public address, letting anyone on the internet attempt to connect and, where authentication is weak or absent, read or alter the data.
- Default Credentials
- Default credentials are the factory usernames and passwords shipped with software and devices. Left unchanged on an internet-facing system, they grant access with no exploit required.
- Defence in Depth
- Defence in depth is the practice of layering independent security controls so that the failure or bypass of any single control does not by itself lead to compromise.
- Directory Listing
- Directory listing is a web server generating an index of files when no default document exists, exposing backups, archives and configuration that were never meant to be browsable.
- DKIM
- DKIM (DomainKeys Identified Mail) is an email authentication method that uses cryptographic signatures to verify that an email was sent by an authorised server and was not modified in transit.
- DMARC
- DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a DNS-based email policy that uses SPF and DKIM to prevent domain spoofing and provides reporting on authentication results.
- DMARC Alignment
- DMARC alignment is the requirement that the domain validated by SPF or DKIM matches the domain in the visible From header, ensuring authentication applies to the address the recipient sees.
- DNS over HTTPS
- DNS over HTTPS (DoH) carries DNS queries inside encrypted HTTPS requests, as defined in RFC 8484, so on-path observers cannot read or alter lookups between client and resolver.
- DNS Propagation
- DNS propagation is the delay between changing a record and every resolver serving the new value. It is caused by cached answers expiring at their TTL, not by data spreading between servers.
- DNS Record Types
- DNS record types define what data an answer carries -- A and AAAA for addresses, CNAME for aliases, NS for delegation, MX for mail routing, and TXT for text used by policies like SPF.
- DNS Zone Transfer
- A DNS zone transfer (AXFR) copies a zone's complete record set from one name server to another. Left open to the public internet, it hands an attacker a full inventory of a domain's hosts.
- DNSSEC
- DNSSEC adds cryptographic signatures to DNS records so a validating resolver can confirm answers came from the authoritative zone and were not altered. It provides authenticity, not confidentiality.
- Domain Hijacking
- Domain hijacking is the unauthorised transfer or alteration of a domain's registration or DNS, letting an attacker redirect traffic, intercept mail and obtain certificates for the whole domain.
- Domain Registrar
- A domain registrar is an accredited company that registers domain names for customers and submits those registrations to the registry operating the relevant top-level domain.
E
- Elasticsearch Exposure
- Elasticsearch exposure is an Elasticsearch cluster reachable over the internet on its HTTP API, typically on port 9200, allowing index contents to be listed and read without credentials.
- EPSS
- EPSS (Exploit Prediction Scoring System) is a FIRST-maintained model that estimates the probability, from 0 to 1, that a vulnerability will be exploited in the wild in the next 30 days.
- Exploit
- An exploit is code or a technique that takes advantage of a vulnerability to make a system behave unintendedly -- running commands, bypassing authentication, or disclosing protected data.
- External Attack Surface Management
- External attack surface management (EASM) is the continuous discovery, monitoring, and assessment of an organisation's internet-facing assets from an attacker's outside-in perspective.
F
- FTP
- FTP (File Transfer Protocol) is a legacy file transfer protocol on TCP port 21 that sends credentials and data in plaintext, offering no confidentiality or integrity protection.
G
- GDPR Article 32
- Article 32 of the GDPR requires controllers and processors to implement technical and organisational measures appropriate to the risk, including regular testing of those measures' effectiveness.
- GraphQL Introspection
- GraphQL introspection is a built-in feature that lets a client query a server for its full schema -- every type, field, argument and mutation -- which also helps attackers when left public.
H
- Heartbleed
- Heartbleed (CVE-2014-0160) was a 2014 bug in OpenSSL's TLS heartbeat extension that let a peer read up to 64KB of the other side's process memory, potentially exposing keys and session data.
- Homoglyph Attack
- A homoglyph attack uses visually similar or identical characters, such as Cyrillic 'а' in place of Latin 'a', in domain names or text to impersonate legitimate sites and deceive users.
- HSTS
- HTTP Strict Transport Security (HSTS) is a security header that forces browsers to connect to a site exclusively over HTTPS, preventing protocol downgrade and SSL stripping attacks.
- HTTP to HTTPS Redirect
- An HTTP-to-HTTPS redirect answers plaintext requests with a permanent redirect to the HTTPS URL. It is the first step towards HTTPS-only, but only HSTS prevents the initial insecure request.
I
- Internationalised Domain Name
- An internationalised domain name (IDN) contains characters outside ASCII letters, digits and hyphens. Applications convert it to Punycode with an xn-- prefix before any DNS lookup.
- ISO 27001
- ISO/IEC 27001 is an international standard specifying requirements for an information security management system, against which organisations can be certified by an accredited certification body.
K
- KEV Catalogue
- The KEV catalogue is CISA's list of vulnerabilities with reliable evidence of exploitation in the wild, each carrying a remediation due date binding on US federal civilian agencies.
L
- Least Privilege
- Least privilege is the principle that every user, process and system should hold only the permissions needed for its task, and only for as long as it needs them.
- Login Fingerprinting
- Login fingerprinting is the technique of identifying the software behind a login page by analysing its HTML structure, HTTP headers, favicon, and other response characteristics.
M
- MITRE ATT&CK
- MITRE ATT&CK is a publicly available knowledge base of adversary tactics and techniques, maintained by MITRE and based on behaviour observed in real-world intrusions.
- Mixed Content
- Mixed content is an HTTPS page loading subresources over plain HTTP. Browsers block active mixed content such as scripts and iframes, and upgrade or block passive content like images.
- MTA-STS
- MTA-STS (Mail Transfer Agent Strict Transport Security) is a standard, defined in RFC 8461, that lets a domain require TLS encryption for inbound SMTP, preventing downgrade and interception attacks.
- MX Record
- An MX record is a DNS entry naming a mail server that accepts email for a domain, with a preference value that tells senders which server to try first.
N
- Network Segmentation
- Network segmentation divides a network into zones with controlled traffic between them, so that a compromise in one zone does not give an attacker reach across the whole estate.
- NIS2
- NIS2 is the EU directive on the security of network and information systems, replacing the 2016 NIS Directive and imposing risk-management, reporting and governance duties on in-scope entities.
- NS Record
- An NS record names an authoritative name server for a DNS zone. Parent zones publish NS records to delegate a subdomain, and every zone lists its own name servers at its apex.
- Nuclei
- Open-source vulnerability scanner by ProjectDiscovery using YAML-based templates to detect CVEs, misconfigurations, and exposures in web applications and services.
- NVD
- The NVD (National Vulnerability Database) is NIST's repository of CVE records enriched with CVSS severity scores, CPE product identifiers, and CWE weakness classifications.
O
- OCSP
- OCSP (Online Certificate Status Protocol) is a protocol, defined in RFC 6960, for checking in real time whether a TLS certificate has been revoked by its issuing certificate authority.
- OSINT
- OSINT (open-source intelligence) is intelligence built from publicly available sources -- DNS records, certificate logs, code repositories, filings -- without accessing the target directly.
- OWASP Top Ten
- The OWASP Top Ten is an awareness document from the Open Worldwide Application Security Project listing the most critical categories of web application security risk, revised periodically.
P
- Passive DNS
- Passive DNS is a historical archive of observed DNS resolutions, collected by sensors and resolvers, that shows which names have pointed at which addresses over time.
- Patch Management
- Patch management is the process of identifying, testing, applying, and verifying software and firmware updates so that known vulnerabilities are remediated before they can be exploited.
- PCI DSS External Scanning
- PCI DSS requires external vulnerability scans of internet-facing cardholder data environment systems at least quarterly and after significant changes, performed by a PCI-approved scanning vendor.
- Penetration Testing
- Penetration testing is an authorised, time-boxed assessment in which testers attempt to exploit weaknesses within an agreed scope and report what access they were able to achieve.
- Perfect Forward Secrecy
- Perfect forward secrecy means session keys come from an ephemeral key exchange, so an attacker who records traffic and later obtains the server's private key still cannot decrypt those sessions.
- Permissions-Policy
- Permissions-Policy is an HTTP header that declares which browser features a page and its embedded frames may use, such as camera, microphone, geolocation and payment request.
- POODLE Attack
- POODLE (CVE-2014-3566) was a 2014 padding-oracle attack on SSL 3.0's CBC cipher modes, letting an on-path attacker who could force a downgrade recover plaintext such as session cookies.
- Port Scanning
- Port scanning is the process of probing a host's TCP or UDP ports to determine which are open and what services they run, used by both attackers and defenders to map exposure.
- Proof-of-Concept Exploit
- A proof-of-concept (PoC) exploit is minimal code published to demonstrate that a vulnerability is genuinely exploitable, usually without the reliability or payload of a weaponised exploit.
- Punycode
- Punycode is an encoding defined in RFC 3492 that represents Unicode domain labels using only ASCII characters. Encoded labels carry an xn-- prefix so DNS can transport international names.
R
- Ransomware
- Ransomware is malware that encrypts a victim's data, and often steals it as well, so that the operator can demand payment for decryption or for not publishing the stolen files.
- RDP
- RDP (Remote Desktop Protocol) is Microsoft's protocol for remote graphical access to Windows systems, listening by default on TCP port 3389 and frequently targeted when exposed to the internet.
- Reconnaissance
- Reconnaissance is the information-gathering phase of an attack, in which an adversary maps a target's domains, hosts, services, and people before attempting any exploitation.
- Red Team
- A red team emulates a real adversary's tactics against an organisation over an extended engagement, testing detection and response as much as technical weaknesses.
- Referrer-Policy
- Referrer-Policy is an HTTP header, also settable per element, that controls how much of the current URL a browser includes in the Referer header of outgoing requests.
- Reverse DNS
- Reverse DNS resolves an IP address to a hostname using PTR records in the in-addr.arpa or ip6.arpa zones -- the opposite direction to an ordinary forward lookup.
S
- S3 Bucket Exposure
- S3 bucket exposure is cloud object storage made readable or writable by anyone, through permissive access controls or policies, allowing files to be listed and downloaded without credentials.
- SAST
- Static application security testing (SAST) analyses an application's source code, bytecode, or binaries for security vulnerabilities without executing the program.
- Security Misconfiguration
- Security misconfiguration is a weakness caused by insecure settings rather than a software flaw -- defaults left in place, unnecessary features enabled, or protections never switched on.
- Self-Signed Certificate
- A self-signed certificate is signed with its own private key rather than by a certificate authority, so no public trust chain validates it and browsers show a warning before proceeding.
- Server Header Disclosure
- Server header disclosure is a response advertising software and version details in headers such as Server and X-Powered-By, giving an attacker a version to match against known vulnerabilities.
- Service Fingerprinting
- Service fingerprinting identifies the specific software and version running on an open network port by analysing protocol responses, banners, and behavioural characteristics.
- Shadow IT
- Shadow IT is technology assets - servers, applications, SaaS tools, and cloud instances - deployed within an organisation without the knowledge or approval of IT and security departments.
- SMB Protocol
- SMB (Server Message Block) is the Windows file and printer sharing protocol, listening on TCP port 445, which should never be reachable from the internet.
- SOC 2
- SOC 2 is an AICPA reporting framework under which a licensed CPA firm examines a service organisation's controls against the Trust Services Criteria and issues an attestation report.
- SPF
- SPF (Sender Policy Framework) is a DNS TXT record that specifies which mail servers are authorised to send email for a domain, helping prevent email spoofing.
- SPF Lookup Limit
- SPF evaluation is capped at 10 DNS-querying mechanisms. Exceeding the limit makes receivers return permerror, so the record stops authorising any of the domain's legitimate senders.
- SSH
- SSH (Secure Shell) is an encrypted protocol for remote command-line access, file transfer and tunnelling, listening by default on TCP port 22.
- Subdomain Takeover
- A subdomain takeover is an attack where an attacker claims an external resource (S3 bucket, Heroku app) that a subdomain's DNS still references, gaining control of the subdomain.
- Subresource Integrity
- Subresource Integrity (SRI) lets a page attach a cryptographic hash to a script or stylesheet tag, so the browser refuses to use the file if its contents do not match the expected hash.
T
- TCP Port
- A TCP port is a numbered endpoint (0-65535) on a networked device that identifies a specific service or application. Open TCP ports accept incoming connections from other systems.
- Telnet
- Telnet is a legacy remote terminal protocol on TCP port 23 that transmits credentials and session data in plaintext, superseded by SSH but still present on older devices.
- Threat Actor
- A threat actor is an individual or group that conducts, or intends to conduct, malicious activity against systems or data -- from opportunistic criminals to state-sponsored operators.
- TLS
- TLS (Transport Layer Security) is a cryptographic protocol that encrypts data transmitted between a client and server, protecting against eavesdropping and tampering. It is the successor to SSL.
- TLS Handshake
- The TLS handshake is the negotiation that opens a TLS connection: the peers agree a version and cipher suite, the server authenticates with its certificate, and shared session keys are derived.
- TLS-RPT
- TLS-RPT (SMTP TLS Reporting) is a standard, defined in RFC 8460, that lets a domain receive daily reports from sending mail servers about TLS connection failures affecting its inbound email.
- TXT Record
- A TXT record holds free-form text in DNS. It carries machine-readable policies such as SPF, DKIM keys and DMARC, plus ownership verification tokens issued by third-party services.
- Typosquatting
- Typosquatting is the registration of domain names that are misspellings or variations of legitimate domains, used to capture mistyped traffic for phishing, malware delivery, or fraud.
V
- VPN Gateway
- A VPN gateway is the internet-facing device or service that terminates VPN tunnels, authenticating remote users or sites and bridging them into an internal network.
- Vulnerability Management
- Vulnerability management is the ongoing process of identifying, assessing, prioritising, and remediating security vulnerabilities across an organisation's systems and software.
W
- Web Application Firewall
- A web application firewall inspects HTTP requests and responses in front of an application, blocking, challenging or logging traffic that matches attack patterns or violates policy.
- WHOIS
- WHOIS is a query protocol and record set that returns registration details for a domain or IP range, including registrar, name servers, and key dates. RDAP is its modern successor.
- Wildcard Certificate
- A wildcard certificate is a TLS certificate that secures a domain's first-level subdomains using an asterisk label (e.g. *.example.com), so one certificate covers many hostnames.
X
- X-Frame-Options
- X-Frame-Options is an HTTP header that controls whether a page can be embedded in frames (iframe, frame, embed, object), preventing clickjacking attacks.
Z
- Zero-Day
- A zero-day is a vulnerability that is being exploited or is publicly known before the vendor has a patch available, leaving defenders with no official fix to apply.