EZ Cybersecurity Encyclopedia

Learn the language of cybersecurity. Then learn what to do with it.

A free, plain-English cybersecurity learning resource built for people entering the field, employees, sellers, partners, leaders, and practitioners who want the terminology without the jargon wall.

Start here

Cybersecurity essentials

New to the field? These concepts unlock the language used throughout security teams, products, incidents, and customer conversations.

How the library works

01

Know

Understand the term in plain English and learn how it works.

02

Practice

Recognize the concept inside realistic security scenarios.

03

Prove

Use knowledge checks to demonstrate understanding.

04

Perform

Apply response actions, controls, and role-specific guidance.

Explore

The encyclopedia

Search by the words you know. Browse by domain, difficulty, concept type, or validation. Switch between card and dense list views depending on how you want to learn.

100 reviewed concepts

Identity & AccessIntermediate

Active Directory (AD)

Microsoft's directory service for centrally managing users, computers, groups, authentication, authorization, and policy in many enterprise environments.

1 evidence record
TechnologyLearn it →
Identity SecurityIntermediate

Adversary-in-the-Middle Phishing (AiTM)

A phishing technique that proxies a real authentication session so the attacker can capture credentials and session tokens in real time, potentially bypassing non-phishing-resistant MFA.

1 evidence record
Attack TechniqueLearn it →
AI SecurityIntermediate

Agentic Workflow Automation

The use of AI agents to plan and carry out multi-step workflows using tools, data, and policies with varying levels of human oversight.

3 evidence records
TechnologyLearn it →
AI SecurityIntermediate

AI Bill of Materials (AIBOM)

A structured inventory describing important components and dependencies of an AI system, such as models, datasets, software, services, and other artifacts needed to understand its supply chain and risk.

2 evidence records
ProgramLearn it →
AI SecurityIntermediate

AI-Accelerated Cyberattacks

Cyber operations in which attackers use AI to increase the speed, scale, personalization, adaptability, or technical capability of reconnaissance, social engineering, exploitation, malware, or evasion.

7 evidence records
ThreatLearn it →
Application & Software SecurityIntermediate

API Security (APIsec)

The practices and controls used to protect application programming interfaces from unauthorized access, abuse, data exposure, and implementation flaws.

1 evidence record
ProgramLearn it →
Vulnerabilities & ExploitationIntermediate

Attack Surface Management (ASM)

Continuous discovery and assessment of assets and exposures that an attacker could reach or abuse.

1 evidence record
ProgramLearn it →
Incident ResponseIntermediate

Automated Incident Response

The use of software and predefined logic to execute parts of an incident-response process automatically.

3 evidence records
ControlLearn it →
Threats & Social EngineeringBeginner

Business Email Compromise (BEC)

A fraud scheme in which an attacker impersonates or compromises a trusted business identity to manipulate payments, payroll, credentials, or sensitive information.

1 evidence record
ThreatLearn it →
Cloud SecurityIntermediate

Cloud Access Security Broker (CASB)

A security enforcement point that provides visibility and policy controls between users and cloud services.

1 evidence record
TechnologyLearn it →
Cloud SecurityBeginner

Cloud Security

The practices and controls used to protect cloud identities, data, applications, workloads, configurations, and infrastructure.

3 evidence records
ProgramLearn it →
Cloud SecurityIntermediate

Cloud Security Posture Management (CSPM)

Technology that continuously evaluates cloud configurations, identities, and resources for misconfiguration and compliance risk.

1 evidence record
TechnologyLearn it →
Cloud SecurityIntermediate

Cloud Workload Protection Platform (CWPP)

Security capabilities focused on protecting cloud workloads such as virtual machines, containers, serverless functions, and hosts.

1 evidence record
TechnologyLearn it →
Cloud SecurityIntermediate

Cloud-Native Application Protection Platform (CNAPP)

An integrated cloud-security platform combining posture, workload, identity, vulnerability, and application-context capabilities.

1 evidence record
TechnologyLearn it →
Threat Intelligence & Adversary BehaviorIntermediate

Command and Control (C2)

The communication channel or mechanism used by an adversary to control compromised systems and exchange instructions or data.

2 evidence records
Attack TechniqueLearn it →
Vulnerabilities & ExposureBeginner

Common Vulnerabilities and Exposures (CVE)

A standardized identifier for a publicly disclosed cybersecurity vulnerability.

3 evidence records
ProgramLearn it →
Vulnerabilities & ExposureIntermediate

Common Vulnerability Scoring System (CVSS)

An open framework for describing and scoring characteristics that contribute to the severity of a vulnerability.

3 evidence records
FrameworkLearn it →
Cloud SecurityIntermediate

Container Security

The practices and controls used to secure container images, registries, runtimes, hosts, orchestration, identities, and supply chains.

1 evidence record
ProgramLearn it →
Threats & Social EngineeringBeginner

Credential Harvesting

The collection of usernames, passwords, tokens, or other authentication material through deceptive or malicious means.

2 evidence records
Attack TechniqueLearn it →
Application & Software SecurityIntermediate

Cross-Site Scripting (XSS)

A web vulnerability that allows attacker-controlled script to execute in another user's browser within a trusted application context.

1 evidence record
Attack TechniqueLearn it →
Threat IntelligenceIntermediate

Cyber Threat Intelligence (CTI)

Evidence-based knowledge about threats and adversaries that helps an organization make better security decisions.

5 evidence records
ProgramLearn it →
FundamentalsBeginner

Cybersecurity

The practice of protecting systems, networks, applications, identities, and data from unauthorized access, disruption, manipulation, or destruction.

13 evidence records
FoundationLearn it →
Data Security & PrivacyIntermediate

Data Exfiltration

Unauthorized transfer of data out of an environment, account, application, or device.

1 evidence record
Attack TechniqueLearn it →
Threats & Social EngineeringBeginner

Data Extortion

Theft of sensitive information followed by threats to publish, sell, misuse, or otherwise weaponize the data unless the victim pays or complies with the attacker’s demands.

1 evidence record
ThreatLearn it →
Data Security & PrivacyIntermediate

Data Loss Prevention (DLP)

Controls that identify sensitive data and help prevent unauthorized disclosure, transfer, or use.

1 evidence record
ControlLearn it →
Threats & Social EngineeringBeginner

Deepfake Impersonation

Use of AI-generated or manipulated audio, video, images, or personas to impersonate a trusted person and make a fraudulent request appear authentic.

1 evidence record
ThreatLearn it →
Identity SecurityIntermediate

Device Code Phishing

A phishing technique that tricks a user into entering an attacker-controlled device code into a legitimate authentication page, authorizing the attacker’s session instead of the user’s device.

2 evidence records
Attack TechniqueLearn it →
Incident Response & Digital ForensicsIntermediate

Digital Forensics (DFIR)

The disciplined collection, preservation, examination, and analysis of digital evidence to understand events and support response or investigation.

1 evidence record
ProgramLearn it →
Email, Domain & Brand AbuseIntermediate

Domain-based Message Authentication, Reporting and Conformance (DMARC)

An email-authentication policy and reporting mechanism that builds on SPF and DKIM alignment.

1 evidence record
ControlLearn it →
Email, Domain & Brand AbuseIntermediate

DomainKeys Identified Mail (DKIM)

An email authentication mechanism that uses cryptographic signatures so recipients can validate message integrity and domain responsibility.

1 evidence record
ControlLearn it →
Network SecurityAdvanced

Edge Device Exploitation

Compromise of internet-facing infrastructure such as VPNs, firewalls, gateways, routers, or other edge appliances to gain durable access while avoiding endpoint-focused defenses.

3 evidence records
Attack TechniqueLearn it →
Email, Domain & Brand AbuseBeginner

Email Spoofing

Falsifying email sender information so a message appears to originate from another person or domain.

1 evidence record
Attack TechniqueLearn it →
Cryptography & PKIBeginner

Encryption

The transformation of readable data into ciphertext using a cryptographic algorithm and key so unauthorized parties cannot read it.

1 evidence record
TechnologyLearn it →
Endpoint & MalwareBeginner

Endpoint Detection and Response (EDR)

Security technology that collects endpoint telemetry to detect, investigate, and respond to suspicious behavior on devices and workloads.

2 evidence records
TechnologyLearn it →
Vulnerabilities & ExploitationBeginner

Exploit

Code, input, or a technique that takes advantage of a vulnerability to produce unintended behavior.

2 evidence records
Attack TechniqueLearn it →
Vulnerabilities & ExploitationIntermediate

Exposure Management

A risk-based program for continuously identifying, validating, prioritizing, and reducing exploitable security exposures.

2 evidence records
ProgramLearn it →
Security OperationsIntermediate

Extended Detection and Response (XDR)

A detection and response approach that correlates security telemetry across multiple control planes such as endpoint, identity, cloud, email, network, and other sources.

2 evidence records
TechnologyLearn it →
Network SecurityBeginner

Firewall

A security control that enforces rules about network traffic crossing a boundary or host interface.

1 evidence record
TechnologyLearn it →
Identity & AccessAdvanced

Golden Ticket

A forged Kerberos ticket-granting ticket created after compromise of the KRBTGT account secret in Active Directory.

1 evidence record
Attack TechniqueLearn it →
Cryptography & PKIBeginner

Hashing

A one-way cryptographic transformation that produces a fixed-size digest used for integrity, verification, and other security purposes.

1 evidence record
TechnologyLearn it →
Threats & Social EngineeringIntermediate

Help Desk Social Engineering

Social engineering aimed at IT or identity-support personnel to reset credentials, enroll attacker-controlled MFA, recover accounts, or change trusted access.

2 evidence records
Attack TechniqueLearn it →
Identity & AccessBeginner

Identity and Access Management (IAM)

The policies, processes, and technologies used to manage digital identities and control what they are allowed to access.

5 evidence records
ProgramLearn it →
Identity SecurityIntermediate

Identity-Driven Intrusion

An intrusion in which stolen, manipulated, over-privileged, or otherwise abused identities become the attacker’s primary path into and through an environment.

4 evidence records
ThreatLearn it →
Incident Response & Digital ForensicsBeginner

Incident Response (IR)

The coordinated capability for preparing for, detecting, containing, eradicating, recovering from, and learning from cybersecurity incidents.

2 evidence records
ProgramLearn it →
Threat Intelligence & Adversary BehaviorBeginner

Initial Access

The tactics and techniques adversaries use to gain their first foothold in an environment.

4 evidence records
Attack TechniqueLearn it →
Network SecurityBeginner

Intrusion Detection System (IDS)

A system that monitors activity or traffic for signs of malicious behavior or policy violations and generates alerts.

1 evidence record
TechnologyLearn it →
Network SecurityIntermediate

Intrusion Prevention System (IPS)

A security system that detects suspicious traffic and can automatically block or disrupt it.

1 evidence record
TechnologyLearn it →
Identity & AccessAdvanced

Kerberoasting

An Active Directory credential attack that requests Kerberos service tickets and attempts to crack service-account material offline.

1 evidence record
Attack TechniqueLearn it →
Cloud SecurityAdvanced

Kubernetes Security

The security of Kubernetes clusters, workloads, control planes, identities, configuration, networking, secrets, and software supply chains.

1 evidence record
ProgramLearn it →
Threat Intelligence & Adversary BehaviorIntermediate

Lateral Movement

Adversary movement from one compromised identity or system to additional systems and resources inside an environment.

2 evidence records
Attack TechniqueLearn it →
Identity & AccessBeginner

Least Privilege

The practice of granting only the permissions needed to perform an authorized task for only as long as needed.

1 evidence record
ControlLearn it →
Cloud SecurityAdvanced

Living off the Cloud (LOTC)

Abuse of legitimate cloud identities, APIs, services, storage, automation, and administrative capabilities to conduct malicious activity while blending into normal cloud operations.

3 evidence records
Attack TechniqueLearn it →
Threat Intelligence & Adversary BehaviorIntermediate

Living off the Land (LotL)

Abusing legitimate built-in tools, services, scripts, or administrative capabilities to perform malicious activity.

1 evidence record
Attack TechniqueLearn it →
AI SecurityIntermediate

LLMJacking

Unauthorized use of another organization’s cloud or API credentials to consume paid large-language-model services, steal AI capacity, or support further malicious activity.

2 evidence records
ThreatLearn it →
Endpoint & MalwareBeginner

Malware

Software or code designed to perform unauthorized or harmful actions on a device, application, network, or data set.

4 evidence records
ThreatLearn it →
Identity & AccessBeginner

MFA Fatigue

Repeated MFA prompts intended to pressure a user into approving a fraudulent authentication request.

1 evidence record
Attack TechniqueLearn it →
Threat IntelligenceBeginner

MITRE ATT&CK

A publicly available knowledge base that organizes observed adversary behaviors into tactics, techniques, sub-techniques, and procedures.

4 evidence records
FrameworkLearn it →
Identity & AccessBeginner

Multi-Factor Authentication (MFA)

Authentication that requires evidence from more than one factor category rather than relying on a password alone.

2 evidence records
ControlLearn it →
Network SecurityIntermediate

Network Segmentation

Dividing networks into controlled zones or segments to limit access, reduce exposure, and constrain lateral movement.

1 evidence record
ControlLearn it →
Identity & AccessIntermediate

OAuth 2.0 (OAuth)

An authorization framework that lets applications obtain scoped access to resources without receiving a user's password.

1 evidence record
TechnologyLearn it →
Identity & AccessIntermediate

OAuth Consent Phishing

A social-engineering attack that tricks users into granting a malicious application legitimate OAuth permissions.

1 evidence record
Attack TechniqueLearn it →
Identity & AccessAdvanced

Pass-the-Hash (PtH)

Authenticating with a stolen password hash instead of the cleartext password to access systems or move laterally.

1 evidence record
Attack TechniqueLearn it →
Identity & AccessIntermediate

Passkeys / WebAuthn (WebAuthn)

Public-key based authentication designed to reduce password theft and resist common phishing attacks.

1 evidence record
TechnologyLearn it →
Identity & AccessBeginner

Passwordless Authentication

Authentication that does not rely on a memorized shared password as the primary user secret.

1 evidence record
ControlLearn it →
Vulnerabilities & ExploitationBeginner

Patch Management

The process of identifying, testing, prioritizing, deploying, and verifying software and firmware updates.

3 evidence records
ProgramLearn it →
Offensive Security & AssuranceIntermediate

Penetration Testing (Pentest)

An authorized assessment that attempts to exploit weaknesses to demonstrate realistic security impact.

1 evidence record
ProgramLearn it →
Threat Intelligence & Adversary BehaviorIntermediate

Persistence

Techniques used by an adversary to maintain access across restarts, credential changes, or defensive actions.

1 evidence record
Attack TechniqueLearn it →
Threats & Social EngineeringBeginner

Phishing

A social-engineering attack that uses a deceptive message or interaction to persuade someone to reveal information, open malicious content, send money, or take another unsafe action.

7 evidence records
ThreatLearn it →
Threat Intelligence & Adversary BehaviorIntermediate

Privilege Escalation

Techniques used to gain higher permissions than those initially obtained.

1 evidence record
Attack TechniqueLearn it →
Identity & AccessIntermediate

Privileged Access Management (PAM)

Processes and technologies used to govern, protect, monitor, and limit high-privilege accounts and sessions.

1 evidence record
ControlLearn it →
Cryptography & PKIIntermediate

Public Key Infrastructure (PKI)

The ecosystem of certificates, certificate authorities, keys, policies, and processes used to establish and manage digital trust.

1 evidence record
TechnologyLearn it →
Offensive Security & AssuranceIntermediate

Purple Team

A collaborative security exercise that brings offensive and defensive teams together to improve detection, prevention, and response.

1 evidence record
ProgramLearn it →
Threats & Social EngineeringBeginner

QR Code Phishing

A phishing technique that uses a QR code to hide or simplify navigation to a malicious destination.

1 evidence record
ThreatLearn it →
Endpoint & MalwareBeginner

Ransomware

Malware or an extortion operation that denies access to systems or data, often through encryption, while demanding payment or another concession.

2 evidence records
ThreatLearn it →
Vulnerability & ExploitationIntermediate

Rapid Vulnerability Exploitation

The exploitation of newly disclosed vulnerabilities at machine-speed or near-machine-speed, often within hours of public technical details or proof-of-concept code becoming available.

3 evidence records
Attack TechniqueLearn it →
Offensive Security & AssuranceIntermediate

Red Team

An authorized adversary-emulation function that tests how well an organization prevents, detects, and responds to realistic attacks.

1 evidence record
ProgramLearn it →
Vulnerabilities & ExploitationAdvanced

Remote Code Execution (RCE)

The ability to cause a target system or application to execute attacker-controlled code from a remote position.

1 evidence record
Attack TechniqueLearn it →
Cloud SecurityIntermediate

SaaS Account Takeover (SaaS ATO)

Unauthorized control of a legitimate software-as-a-service account, often using stolen credentials, tokens, MFA enrollment, OAuth grants, or compromised SSO access.

3 evidence records
ThreatLearn it →
Network SecurityIntermediate

Secure Access Service Edge (SASE)

An architecture that converges wide-area networking with cloud-delivered security services and identity-aware access.

1 evidence record
FrameworkLearn it →
Data & AIIntermediate

Security Data Lake

A data architecture that stores large volumes of security-relevant telemetry in a form that can support detection, investigation, analytics, and long-term analysis.

3 evidence records
TechnologyLearn it →
Security OperationsBeginner

Security Information and Event Management (SIEM)

A security platform that centralizes and analyzes event and log data to support detection, investigation, reporting, and security operations.

2 evidence records
TechnologyLearn it →
Security OperationsIntermediate

Security Orchestration, Automation and Response (SOAR)

Technology and workflows that coordinate security tools and automate repeatable investigation or response actions.

2 evidence records
TechnologyLearn it →
Network SecurityIntermediate

Security Service Edge (SSE)

Cloud-delivered security services for user and application access, commonly including secure web gateway, CASB, and zero-trust access capabilities.

1 evidence record
FrameworkLearn it →
Email, Domain & Brand AbuseIntermediate

Sender Policy Framework (SPF)

A DNS-based email authentication mechanism that lets a domain publish which systems are authorized to send mail for it.

1 evidence record
ControlLearn it →
Identity SecurityIntermediate

Session Token Theft

The theft or reuse of a token, cookie, or other session artifact that represents an already-authenticated user or application.

3 evidence records
Attack TechniqueLearn it →
AI SecurityBeginner

Shadow AI

Use of AI applications, agents, models, browser extensions, or integrations outside approved governance, visibility, or security controls.

2 evidence records
ThreatLearn it →
Identity & AccessBeginner

Single Sign-On (SSO)

An authentication model that lets a user access multiple applications through a central identity provider and sign-in process.

1 evidence record
TechnologyLearn it →
Threats & Social EngineeringBeginner

Smishing

Phishing delivered through SMS or other text-messaging channels.

1 evidence record
ThreatLearn it →
Application & Software SecurityAdvanced

Software Supply Chain Compromise

An attack that compromises software, dependencies, build systems, developer tooling, updates, integrations, or trusted vendors so malicious access is inherited by downstream users.

4 evidence records
ThreatLearn it →
Threats & Social EngineeringBeginner

Spear Phishing

A targeted phishing attack tailored to a specific person, role, company, or relationship.

1 evidence record
ThreatLearn it →
Application & Software SecurityIntermediate

SQL Injection (SQLi)

An injection flaw where untrusted input changes the meaning of a database query and can expose or modify data.

1 evidence record
Attack TechniqueLearn it →
Cryptography & PKIIntermediate

Transport Layer Security (TLS)

A protocol that protects network communications with encryption, integrity protection, and authenticated key establishment.

1 evidence record
TechnologyLearn it →
Email, Domain & Brand AbuseBeginner

Typosquatting

Registering or using domains that closely resemble trusted domains to deceive users or capture traffic.

1 evidence record
Attack TechniqueLearn it →
Network SecurityBeginner

Virtual Private Network (VPN)

A technology that creates an encrypted logical connection across an untrusted network to provide remote or site-to-site access.

1 evidence record
TechnologyLearn it →
Threats & Social EngineeringBeginner

Vishing

Phishing conducted by voice, phone, or voice-enabled communication in order to manipulate a person into granting access, revealing information, or taking an unsafe action.

3 evidence records
Attack TechniqueLearn it →
Vulnerabilities & ExposureBeginner

Vulnerability Management

The continuous process of discovering, evaluating, prioritizing, remediating, and verifying vulnerabilities across an organization’s assets.

6 evidence records
ProgramLearn it →
Application & Software SecurityIntermediate

Web Application Firewall (WAF)

A control that inspects and filters HTTP/S traffic to help protect web applications from malicious requests.

1 evidence record
TechnologyLearn it →
Application & Software SecurityBeginner

Web Application Security (AppSec)

The discipline of designing, building, testing, and operating web applications to reduce exploitable security weaknesses.

1 evidence record
ProgramLearn it →
Identity & AccessBeginner

Zero Trust

A security model that does not grant implicit trust based only on network location or ownership and instead continually evaluates access to resources.

4 evidence records
FrameworkLearn it →
Vulnerabilities & ExploitationIntermediate

Zero-Day Vulnerability (0-day)

A vulnerability for which defenders lack an effective patch or remediation at the time attackers can exploit it.

1 evidence record
ThreatLearn it →