security terms
550 glossary entries tagged security, listed alphabetically.
- "a VPN makes you anonymous"
- "deleting a file erases it"
- "forced password changes make you safer"
- "NAT is a firewall"
- "public Wi-Fi means instant hacking"
- "quantum computers will break all encryption"
- "the padlock means the site is safe"
- 307 Temporary Security Conference (307c)
- 8.88.8 Computer Security Conference - Chile's technical hacking conference, wrapped in pop culture
- 802.1XIEEE 802.1X (port-based network access control)
- a lista do Anchises (Brazilian security profiles)
- ACL
- ACMEAutomatic Certificate Management Environment
- ACSAssertion Consumer Service
- Active Directory
- ADActive Directory
- Adi Shamir
- Adrian Lamo
- air gap
- AiTM (adversary-in-the-middle phishing)
- Albert Gonzalez
- Aleph One and Smashing the Stack
- alert fatigue
- ALPACA
- Amplification and reflection attacks
- Anchises Moraes
- APIsec UniversityAPIsec University (free API security training)
- App Connector
- Application segment
- APT (Advanced Persistent Threat)
- ARC (Authenticated Received Chain)
- archive formats (zip, tar, gz, 7z, rar, iso, cab)
- ARP poisoning
- ASLRaddress space layout randomization
- assertion
- assume breach
- ATP (Advanced Threat Protection)
- attack surface
- attack vector
- attackers only need to be right once
- attestation
- audit trail
- authentication
- authentication adapter
- Authentication Policy Contract
- authentication policy tree
- authorization
- Back Orifice
- backup
- BADoSBehavioral Denial of Service
- Banking trojan
- Barnaby Jack
- bastion host
- BCP 38 (source address validation)
- beaconing
- BEAST
- belt and suspenders
- BGP hijack
- BHack
- Bill Cheswick
- Black HatBlack Hat Briefings and Trainings
- blast radius
- blue team
- BlueKeep
- bogon
- botnet
- BREACH
- break-glass account
- Bruce Schneier
- brute force
- BSides São PauloSecurity BSides São Paulo (Co0L BSidesSP)
- buffer overflow
- bug bounty
- Byzantine fault toleranceBFT
- C2command and control
- CAcertificate authority
- CAACertification Authority Authorization record
- cache poisoning
- canary in the coal mine
- canary token
- Captain Crunch (the 2600 Hz whistle)
- CAPTCHACompletely Automated Public Turing test to tell Computers and Humans Apart
- Capture the Flag (CTF)
- Carding
- CASB
- castle-and-moat
- CDCiber (Centro de Defesa Cibernética)
- CERT (team)Computer Emergency Response Team
- CERT.br and the CGI.br system
- certificate
- Certificate authority (CA)
- certificate pinning
- Certificate Transparency (CT)
- chain of custody
- Chaos Communication Congress (CCC)
- CHAPChallenge-Handshake Authentication Protocol
- chkrootkit
- CIA triadConfidentiality, Integrity, Availability
- cipher suite
- CISSPCertified Information Systems Security Professional ((ISC)2)
- Citizenfour (2014)
- clean pipe
- Cliff Stoll
- cloud IAMIdentity and Access Management
- CNAPP
- Code Red
- command and controlC2
- compliance is not security
- conditional access
- Conficker
- confused deputy
- containment
- Content Security PolicyContent Security Policy (CSP)
- coordinated disclosure
- CORSCross-Origin Resource Sharing
- CORS preflight
- Cortex
- Countdown to Zero Day (Zetter, 2014)
- credential stuffing
- CRIME
- Cristine Hoepers
- CRLCertificate Revocation List
- Cross-device authentication (CDA)
- crown jewels
- crunchy outside, chewy center
- CSPM
- CSRCertificate Signing Request
- CSRFCross-Site Request Forgery
- Cult of the Dead Cow (cDc)
- CVECommon Vulnerabilities and Exposures
- CVSSCommon Vulnerability Scoring System
- CWECommon Weakness Enumeration
- CWPP
- Cyber EssentialsUK Cyber Essentials (NCSC scheme)
- Dan Kaminsky
- Daniel J. Bernstein
- dark web
- DARPA (Defense Advanced Research Projects Agency)
- data at rest
- data classification
- data in transit
- data store
- DCVDomain Control Validation
- DCWF (DoD Cyber Workforce Framework)
- DDoSDistributed Denial of Service
- DEF CON Goons
- defense in depth
- DEFLATE, gzip and zlib
- deprovisioning
- DERDistinguished Encoding Rules
- Detection engineering
- Deviant Ollam
- DevSecOps
- DHCP snooping
- DigiNotar (2011)
- digital signature
- DKIMDomainKeys Identified Mail
- DLP
- DMARC (Domain-based Message Authentication, Reporting and Conformance)
- DMZ
- DNS filtering
- DNSSECDomain Name System Security Extensions
- DoD (United States Department of Defense)
- DoHDNS over HTTPS
- DPDDead Peer Detection (IKE/IPsec liveness)
- DPI (Deep Packet Inspection)
- DragonJARDragonJAR Security Conference - Colombia's leading hacker con, deliberately in Spanish
- DROWN
- dumpster diving
- Dwell time
- EAP-TLS
- EDR
- Edward Snowden
- egress filtering
- end-to-end encryptionend-to-end encryption (E2EE)
- entropy
- EPSSExploit Prediction Scoring System
- ES256ECDSA signature with SHA-256 (JWA identifier)
- ESPEncapsulating Security Payload
- EternalBlue
- exfiltration
- exploit
- Fabio Assolini
- fail open vs. fail closed
- federation
- Federico Kirschbaum
- file inclusionLFI and RFI
- Filipe Balestra
- firewall
- FIRST (org)Forum of Incident Response and Security Teams
- flow logs
- forensics
- Fortinet CommunityFortinet Community (official forums)
- Fórum Brasileiro de CSIRTs
- forward secrecyPerfect Forward Secrecy (PFS)
- Francisco Amato
- FREAK
- FUDFear, Uncertainty, and Doubt
- full-disk encryption
- fuzzing
- Fyodor (Gordon Lyon) and Nmap
- GDBGNU Debugger
- George Hotz (geohot)
- Ghost in the Wires (Mitnick, 2011)
- GTS / GTERGTS and GTER - NIC.br's network security and network engineering working groups
- H2HCHackers to Hackers Conference
- Hackers (1995)
- Have I Been PwnedHave I Been Pwned (HIBP)
- HD Moore
- Heartbleed
- honeypot
- HOPE (Hackers On Planet Earth)
- HOTPHMAC-based One-Time Password
- HS256HMAC with SHA-256 (JWA identifier)
- HSM
- HSTSHTTP Strict Transport Security
- HTTP QUERY method
- IAM
- ICAPInternet Content Adaptation Protocol
- identity provider
- IDSIntrusion Detection System
- IKEInternet Key Exchange
- IKEv2
- IMDS
- Immutable backup (and the 3-2-1 rule)
- incident
- integer overflow
- IoCindicator of compromise
- IPSintrusion prevention system
- IPsec
- ISC2ISC2 (formerly (ISC)², the International Information System Security Certification Consortium)
- ISO/IEC 27001ISO/IEC 27001 (Information Security Management System)
- ISRGInternet Security Research Group
- JA3JA3 TLS client fingerprint
- JA4JA4 TLS client fingerprint (JA4+ suite)
- Jaime Andrés Restrepo (DragonJAR)
- Jeff Moss (Dark Tangent)
- John Markoff
- juice jacking
- just-in-time access
- JWICS
- JWKJSON Web Key
- JWKSJSON Web Key Set
- JWSJSON Web Signature
- JWTJSON Web Token
- Katie Moussouris
- KDC
- Ken Thompson
- Kerberos
- Kerckhoffs's principle
- Kevin Mitnick
- key rotation
- keytab
- KMS
- KRACK
- L0pht Heavy Industries
- landing zone
- lateral movement
- LDAPLightweight Directory Access Protocol
- least privilegeprinciple of least privilege (PoLP)
- Leonardo Pigñer
- living off the land
- Log4Shell
- logging
- Luiz Eduardo dos Santos
- LulzSec
- Mafiaboy (Michael Calce)
- magic number
- malware
- man-in-the-middle
- Marcus Hutchins (MalwareTech)
- martian packet
- Martin Hellman
- Max Butler (Iceman)
- MDM
- Meltdown
- memory safety
- Mente BináriaMente Binária (nonprofit teaching and research institution)
- MFAMulti-Factor Authentication
- Michal Zalewski (lcamtuf)
- microsegmentation
- Mind the SecMind the Sec
- Mirai
- MITREThe MITRE Corporation
- MITRE ATT&CK
- Moonlight Maze
- Mr. Robot (2015-2019)
- MTA-STS (and DANE for mail)
- Mudge (Peiter Zatko)
- multi-tenancy
- Nelson Brito
- Nelson Murilo
- network ACL (cloud)
- NICE Framework Work Role Categories
- Nimda
- NIPRNet
- NIS2Network and Information Security Directive 2 (EU)
- NISTNational Institute of Standards and Technology
- NIST CSF (Cybersecurity Framework)
- NIST CSRC (Computer Security Resource Center)
- no plan survives contact
- noncenumber used once
- NORAD (North American Aerospace Defense Command)
- NotPetya
- NSECNext Secure (record)
- NSEC3Next Secure version 3 (record)
- NTLMNT LAN Manager
- null pointer dereference
- Nullbyte Security Conference
- NullconNullcon - India's flagship hacker conference, grown from the null community
- NVDNational Vulnerability Database
- NX bit / DEPno-execute bit / data execution prevention
- OAuthOAuth 2.0
- OCSPOnline Certificate Status Protocol
- OGNL (Object-Graph Navigation Language)
- OIDCOpenID Connect
- onboarding / offboarding
- open relay
- OpenToken
- OpenVPN
- Operation Aurora
- OPSECoperations security
- OTPone-time password
- OWASPOpen Worldwide Application Security Project
- PACProxy Auto-Config
- packet filter
- PAMPrivileged Access Management
- PAPPassword Authentication Protocol
- Passkey
- Password Credential Validator
- password manager
- passwordless
- patch
- patch management
- Patch Tuesday, Exploit Wednesday
- Paul Vixie
- payload
- PCI DSSPayment Card Industry Data Security Standard
- PEMPrivacy-Enhanced Mail
- penetration testpenetration test
- pepper
- persistence
- PERÚHACK (and LimaHack)
- phishing
- PINpersonal identification number
- PKCEProof Key for Code Exchange
- PKIPublic Key Infrastructure
- POODLE
- port security
- post-quantum cryptographypost-quantum cryptography (PQC)
- Posture profile
- Prilex
- PrintNightmare
- Prisma
- privilege escalation
- promiscuous mode
- proxy
- ProxyLogon
- ProxyShell
- public-key cryptographyasymmetric cryptography
- purple team
- Pwn2Own
- pwned
- race condition
- RADIUS
- rainbow table
- Ransomware
- rate limiting
- RBAC
- RCERemote Code Execution
- red team
- ReDoSRegular expression Denial of Service
- Reflections on Trusting Trust
- replay attack
- responsible disclosure
- risk
- RoadsecRoadsec - Latin America's largest hacker festival
- ROBOT
- Rodrigo Montoro (Sp0oKeR)
- Rodrigo Rubira Branco (BSDaemon)
- Ron Rivest
- Rowhammer
- RPKIResource Public Key Infrastructure
- RPZResponse Policy Zone
- RS256RSA signature with SHA-256 (JWA identifier)
- RSA ConferenceRSA Conference - from cryptographers' gathering to the industry's biggest trade show
- salt
- same-origin policy
- SAMLSecurity Assertion Markup Language
- SampaSecSampaSec (Sao Paulo CitySec meetup)
- SANSubject Alternative Name
- Sandro Süffert
- SANS InstituteSANS Institute (originally SysAdmin, Audit, Network, and Security)
- SASESecure Access Service Edge
- SATAN (the 1995 scanner panic)
- SBOM
- SBSeg (Simpósio Brasileiro de Segurança)
- Schneier's law
- SCIM
- SCPSecure Copy Protocol
- script kiddie
- secrets management
- secure boot
- Security BSides
- Security BSides Perú
- Security BSides São Paulo (BSidesSP)
- security group
- security is a process, not a product
- Security Leaders
- security questions
- security theater
- Segment group
- service account
- service control policy
- service provider
- session
- severity
- SFTPSSH File Transfer Protocol
- shadow ITShadow IT
- shared responsibility model
- shellcode
- Shellshock
- shift-left
- shoulder surfing
- SIEM
- SIISubscriber Identity Information
- SIMSubscriber Identity Module
- SIPRNet
- SIRTSecurity Incident Response Team
- SISBIN (Sistema Brasileiro de Inteligência)
- SMBServer Message Block
- smishing
- smurf attack
- Sneakers (1992)
- SOAR
- SOCSecurity Operations Center
- social engineering
- Solar Designer (Alexander Peslyak)
- Source-port logging
- Space Rogue (Cris Thomas)
- spam filter
- Spectre
- SPFSender Policy Framework
- SPNService Principal Name
- SPNEGO
- Spring4Shell
- SQLStructured Query Language
- SQL injectionSQL injection (SQLi)
- SQL Slammer
- SSESecurity Service Edge
- SSHSecure Shell
- SSL stripping
- SSL VPN
- SSL/TLS inspection
- SSMA
- SSO
- SSRF
- stack canary
- standard user vs. admin
- stateful firewall
- stateful inspection
- Steven Bellovin
- Strata
- Stuxnet
- supply-chain attack
- Surrogate IP
- SYN flood
- TACACS+
- Takedown (Shimomura and Markoff, 1996)
- tarpit
- telemetry
- Telemetry selection (log sources)
- Terrapin
- the Anchises security events calendar
- The Art of Deception (Mitnick, 2002)
- the Blaster worm
- the Brazilian BSides circuit
- the Cuckoo's Egg
- the cyber kill chain
- the DEF CON badge
- the DNC hack (2016)
- the evil bit
- the first spam email
- the Green Card spam
- the ILOVEYOU virus
- the Jeep hack
- the Kaminsky DNS flaw
- the KGB hack (Karl Koch)
- the L0pht testimony
- The Matrix (1999)
- the Melissa virus
- the Morris Worm
- the only secure computer is powered off
- the Pwnie Awards
- the r-commands (rsh, rlogin, rcp, rexec)
- the RSA SecurID breach (2011)
- the S in IoT stands for security
- the Shadow Brokers
- The Shockwave Rider (Brunner, 1975)
- the Sony Pictures hack (2014)
- the STJ ransomware attack (2020)
- the Swiss cheese model
- the Target breach (2013)
- the Tetrade (Brazilian banking trojans)
- the Wall of Sheep
- the WANK worm
- the weakest link
- threat model
- tiger team
- Titan Rain
- TLSTransport Layer Security
- tokenization
- TorThe Onion Router
- TOTPTime-based One-Time Password
- TPMTrusted Platform Module
- TROOPERSTROOPERS - ERNW's Heidelberg conference, Europe's practitioners' favorite
- trust, but verify
- TSIGTransaction Signature
- Tsutomu Shimomura
- TTPtactics, techniques, and procedures
- use-after-free
- vulnerability
- WADWeb Application Daemon (FortiGate)
- WAFWeb Application Firewall
- WannaCry
- WarGames (1983)
- WebAuthn (and FIDO2, CTAP)
- wetware
- white / black / grey hat
- Whitfield Diffie
- Wietse Venema
- Willian Caprino
- workload identity
- WPAWi-Fi Protected Access
- WPADWeb Proxy Auto-Discovery
- xauth and X11 forwarding
- XDR
- XSSCross-Site Scripting
- XXEXML External Entity
- you can't secure what you can't see
- YSTSYou Shot the Sheriff
- ZCC
- zero trustZero Trust Architecture (ZTA)
- Zero Trust Exchange
- zero-day
- Zerologon
- ZIA
- ZIdentity
- ZPA
- ZTNA