EZ Cybersecurity Encyclopedia
Learn the language of cybersecurity. Then learn what to do with it.
A free, plain-English cybersecurity learning resource built for people entering the field, employees, sellers, partners, leaders, and practitioners who want the terminology without the jargon wall.
Start here
Cybersecurity essentials
New to the field? These concepts unlock the language used throughout security teams, products, incidents, and customer conversations.
Cybersecurity
The practice of protecting systems, networks, applications, identities, and data from unauthorized access, disruption, manipulation, or destruction.
Learn it →Threats & Social EngineeringPhishing
A social-engineering attack that uses a deceptive message or interaction to persuade someone to reveal information, open malicious content, send money, or take another unsafe action.
Learn it →Endpoint & MalwareRansomware
Malware or an extortion operation that denies access to systems or data, often through encryption, while demanding payment or another concession.
Learn it →Identity & AccessMulti-Factor Authentication (MFA)
Authentication that requires evidence from more than one factor category rather than relying on a password alone.
Learn it →Identity & AccessZero Trust
A security model that does not grant implicit trust based only on network location or ownership and instead continually evaluates access to resources.
Learn it →Endpoint & MalwareEndpoint Detection and Response (EDR)
Security technology that collects endpoint telemetry to detect, investigate, and respond to suspicious behavior on devices and workloads.
Learn it →How the library works
Know
Understand the term in plain English and learn how it works.
Practice
Recognize the concept inside realistic security scenarios.
Prove
Use knowledge checks to demonstrate understanding.
Perform
Apply response actions, controls, and role-specific guidance.
Explore
The encyclopedia
Search by the words you know. Browse by domain, difficulty, concept type, or validation. Switch between card and dense list views depending on how you want to learn.
Active Directory (AD)
Microsoft's directory service for centrally managing users, computers, groups, authentication, authorization, and policy in many enterprise environments.
Adversary-in-the-Middle Phishing (AiTM)
A phishing technique that proxies a real authentication session so the attacker can capture credentials and session tokens in real time, potentially bypassing non-phishing-resistant MFA.
Agentic Workflow Automation
The use of AI agents to plan and carry out multi-step workflows using tools, data, and policies with varying levels of human oversight.
AI Bill of Materials (AIBOM)
A structured inventory describing important components and dependencies of an AI system, such as models, datasets, software, services, and other artifacts needed to understand its supply chain and risk.
AI-Accelerated Cyberattacks
Cyber operations in which attackers use AI to increase the speed, scale, personalization, adaptability, or technical capability of reconnaissance, social engineering, exploitation, malware, or evasion.
API Security (APIsec)
The practices and controls used to protect application programming interfaces from unauthorized access, abuse, data exposure, and implementation flaws.
Attack Surface Management (ASM)
Continuous discovery and assessment of assets and exposures that an attacker could reach or abuse.
Automated Incident Response
The use of software and predefined logic to execute parts of an incident-response process automatically.
Business Email Compromise (BEC)
A fraud scheme in which an attacker impersonates or compromises a trusted business identity to manipulate payments, payroll, credentials, or sensitive information.
Cloud Access Security Broker (CASB)
A security enforcement point that provides visibility and policy controls between users and cloud services.
Cloud Security
The practices and controls used to protect cloud identities, data, applications, workloads, configurations, and infrastructure.
Cloud Security Posture Management (CSPM)
Technology that continuously evaluates cloud configurations, identities, and resources for misconfiguration and compliance risk.
Cloud Workload Protection Platform (CWPP)
Security capabilities focused on protecting cloud workloads such as virtual machines, containers, serverless functions, and hosts.
Cloud-Native Application Protection Platform (CNAPP)
An integrated cloud-security platform combining posture, workload, identity, vulnerability, and application-context capabilities.
Command and Control (C2)
The communication channel or mechanism used by an adversary to control compromised systems and exchange instructions or data.
Common Vulnerabilities and Exposures (CVE)
A standardized identifier for a publicly disclosed cybersecurity vulnerability.
Common Vulnerability Scoring System (CVSS)
An open framework for describing and scoring characteristics that contribute to the severity of a vulnerability.
Container Security
The practices and controls used to secure container images, registries, runtimes, hosts, orchestration, identities, and supply chains.
Credential Harvesting
The collection of usernames, passwords, tokens, or other authentication material through deceptive or malicious means.
Cross-Site Scripting (XSS)
A web vulnerability that allows attacker-controlled script to execute in another user's browser within a trusted application context.
Cyber Threat Intelligence (CTI)
Evidence-based knowledge about threats and adversaries that helps an organization make better security decisions.
Cybersecurity
The practice of protecting systems, networks, applications, identities, and data from unauthorized access, disruption, manipulation, or destruction.
Data Exfiltration
Unauthorized transfer of data out of an environment, account, application, or device.
Data Extortion
Theft of sensitive information followed by threats to publish, sell, misuse, or otherwise weaponize the data unless the victim pays or complies with the attacker’s demands.
Data Loss Prevention (DLP)
Controls that identify sensitive data and help prevent unauthorized disclosure, transfer, or use.
Deepfake Impersonation
Use of AI-generated or manipulated audio, video, images, or personas to impersonate a trusted person and make a fraudulent request appear authentic.
Device Code Phishing
A phishing technique that tricks a user into entering an attacker-controlled device code into a legitimate authentication page, authorizing the attacker’s session instead of the user’s device.
Digital Forensics (DFIR)
The disciplined collection, preservation, examination, and analysis of digital evidence to understand events and support response or investigation.
Domain-based Message Authentication, Reporting and Conformance (DMARC)
An email-authentication policy and reporting mechanism that builds on SPF and DKIM alignment.
DomainKeys Identified Mail (DKIM)
An email authentication mechanism that uses cryptographic signatures so recipients can validate message integrity and domain responsibility.
Edge Device Exploitation
Compromise of internet-facing infrastructure such as VPNs, firewalls, gateways, routers, or other edge appliances to gain durable access while avoiding endpoint-focused defenses.
Email Spoofing
Falsifying email sender information so a message appears to originate from another person or domain.
Encryption
The transformation of readable data into ciphertext using a cryptographic algorithm and key so unauthorized parties cannot read it.
Endpoint Detection and Response (EDR)
Security technology that collects endpoint telemetry to detect, investigate, and respond to suspicious behavior on devices and workloads.
Exploit
Code, input, or a technique that takes advantage of a vulnerability to produce unintended behavior.
Exposure Management
A risk-based program for continuously identifying, validating, prioritizing, and reducing exploitable security exposures.
Extended Detection and Response (XDR)
A detection and response approach that correlates security telemetry across multiple control planes such as endpoint, identity, cloud, email, network, and other sources.
Firewall
A security control that enforces rules about network traffic crossing a boundary or host interface.
Golden Ticket
A forged Kerberos ticket-granting ticket created after compromise of the KRBTGT account secret in Active Directory.
Hashing
A one-way cryptographic transformation that produces a fixed-size digest used for integrity, verification, and other security purposes.
Help Desk Social Engineering
Social engineering aimed at IT or identity-support personnel to reset credentials, enroll attacker-controlled MFA, recover accounts, or change trusted access.
Identity and Access Management (IAM)
The policies, processes, and technologies used to manage digital identities and control what they are allowed to access.
Identity-Driven Intrusion
An intrusion in which stolen, manipulated, over-privileged, or otherwise abused identities become the attacker’s primary path into and through an environment.
Incident Response (IR)
The coordinated capability for preparing for, detecting, containing, eradicating, recovering from, and learning from cybersecurity incidents.
Initial Access
The tactics and techniques adversaries use to gain their first foothold in an environment.
Intrusion Detection System (IDS)
A system that monitors activity or traffic for signs of malicious behavior or policy violations and generates alerts.
Intrusion Prevention System (IPS)
A security system that detects suspicious traffic and can automatically block or disrupt it.
Kerberoasting
An Active Directory credential attack that requests Kerberos service tickets and attempts to crack service-account material offline.
Kubernetes Security
The security of Kubernetes clusters, workloads, control planes, identities, configuration, networking, secrets, and software supply chains.
Lateral Movement
Adversary movement from one compromised identity or system to additional systems and resources inside an environment.
Least Privilege
The practice of granting only the permissions needed to perform an authorized task for only as long as needed.
Living off the Cloud (LOTC)
Abuse of legitimate cloud identities, APIs, services, storage, automation, and administrative capabilities to conduct malicious activity while blending into normal cloud operations.
Living off the Land (LotL)
Abusing legitimate built-in tools, services, scripts, or administrative capabilities to perform malicious activity.
LLMJacking
Unauthorized use of another organization’s cloud or API credentials to consume paid large-language-model services, steal AI capacity, or support further malicious activity.
Malware
Software or code designed to perform unauthorized or harmful actions on a device, application, network, or data set.
MFA Fatigue
Repeated MFA prompts intended to pressure a user into approving a fraudulent authentication request.
MITRE ATT&CK
A publicly available knowledge base that organizes observed adversary behaviors into tactics, techniques, sub-techniques, and procedures.
Multi-Factor Authentication (MFA)
Authentication that requires evidence from more than one factor category rather than relying on a password alone.
Network Segmentation
Dividing networks into controlled zones or segments to limit access, reduce exposure, and constrain lateral movement.
OAuth 2.0 (OAuth)
An authorization framework that lets applications obtain scoped access to resources without receiving a user's password.
OAuth Consent Phishing
A social-engineering attack that tricks users into granting a malicious application legitimate OAuth permissions.
Pass-the-Hash (PtH)
Authenticating with a stolen password hash instead of the cleartext password to access systems or move laterally.
Passkeys / WebAuthn (WebAuthn)
Public-key based authentication designed to reduce password theft and resist common phishing attacks.
Passwordless Authentication
Authentication that does not rely on a memorized shared password as the primary user secret.
Patch Management
The process of identifying, testing, prioritizing, deploying, and verifying software and firmware updates.
Penetration Testing (Pentest)
An authorized assessment that attempts to exploit weaknesses to demonstrate realistic security impact.
Persistence
Techniques used by an adversary to maintain access across restarts, credential changes, or defensive actions.
Phishing
A social-engineering attack that uses a deceptive message or interaction to persuade someone to reveal information, open malicious content, send money, or take another unsafe action.
Privilege Escalation
Techniques used to gain higher permissions than those initially obtained.
Privileged Access Management (PAM)
Processes and technologies used to govern, protect, monitor, and limit high-privilege accounts and sessions.
Public Key Infrastructure (PKI)
The ecosystem of certificates, certificate authorities, keys, policies, and processes used to establish and manage digital trust.
Purple Team
A collaborative security exercise that brings offensive and defensive teams together to improve detection, prevention, and response.
QR Code Phishing
A phishing technique that uses a QR code to hide or simplify navigation to a malicious destination.
Ransomware
Malware or an extortion operation that denies access to systems or data, often through encryption, while demanding payment or another concession.
Rapid Vulnerability Exploitation
The exploitation of newly disclosed vulnerabilities at machine-speed or near-machine-speed, often within hours of public technical details or proof-of-concept code becoming available.
Red Team
An authorized adversary-emulation function that tests how well an organization prevents, detects, and responds to realistic attacks.
Remote Code Execution (RCE)
The ability to cause a target system or application to execute attacker-controlled code from a remote position.
SaaS Account Takeover (SaaS ATO)
Unauthorized control of a legitimate software-as-a-service account, often using stolen credentials, tokens, MFA enrollment, OAuth grants, or compromised SSO access.
Secure Access Service Edge (SASE)
An architecture that converges wide-area networking with cloud-delivered security services and identity-aware access.
Security Data Lake
A data architecture that stores large volumes of security-relevant telemetry in a form that can support detection, investigation, analytics, and long-term analysis.
Security Information and Event Management (SIEM)
A security platform that centralizes and analyzes event and log data to support detection, investigation, reporting, and security operations.
Security Orchestration, Automation and Response (SOAR)
Technology and workflows that coordinate security tools and automate repeatable investigation or response actions.
Security Service Edge (SSE)
Cloud-delivered security services for user and application access, commonly including secure web gateway, CASB, and zero-trust access capabilities.
Sender Policy Framework (SPF)
A DNS-based email authentication mechanism that lets a domain publish which systems are authorized to send mail for it.
Session Token Theft
The theft or reuse of a token, cookie, or other session artifact that represents an already-authenticated user or application.
Shadow AI
Use of AI applications, agents, models, browser extensions, or integrations outside approved governance, visibility, or security controls.
Single Sign-On (SSO)
An authentication model that lets a user access multiple applications through a central identity provider and sign-in process.
Smishing
Phishing delivered through SMS or other text-messaging channels.
Software Supply Chain Compromise
An attack that compromises software, dependencies, build systems, developer tooling, updates, integrations, or trusted vendors so malicious access is inherited by downstream users.
Spear Phishing
A targeted phishing attack tailored to a specific person, role, company, or relationship.
SQL Injection (SQLi)
An injection flaw where untrusted input changes the meaning of a database query and can expose or modify data.
Transport Layer Security (TLS)
A protocol that protects network communications with encryption, integrity protection, and authenticated key establishment.
Typosquatting
Registering or using domains that closely resemble trusted domains to deceive users or capture traffic.
Virtual Private Network (VPN)
A technology that creates an encrypted logical connection across an untrusted network to provide remote or site-to-site access.
Vishing
Phishing conducted by voice, phone, or voice-enabled communication in order to manipulate a person into granting access, revealing information, or taking an unsafe action.
Vulnerability Management
The continuous process of discovering, evaluating, prioritizing, remediating, and verifying vulnerabilities across an organization’s assets.
Web Application Firewall (WAF)
A control that inspects and filters HTTP/S traffic to help protect web applications from malicious requests.
Web Application Security (AppSec)
The discipline of designing, building, testing, and operating web applications to reduce exploitable security weaknesses.
Zero Trust
A security model that does not grant implicit trust based only on network location or ownership and instead continually evaluates access to resources.
Zero-Day Vulnerability (0-day)
A vulnerability for which defenders lack an effective patch or remediation at the time attackers can exploit it.