{"status":"success","data":[{"_id":"610be0574e64cc0060f84dec","resources":{"roomCodes":["vulnerabilities101","introtoresearch","sigma"],"videos":["https://www.youtube.com/watch?v=qfpnJyTl1To"],"articles":["https://nvd.nist.gov/vuln/full-listing"]},"term":"CVE","definition":"Common Vulnerabilities and Exposures (CVE), this term is given to a publicly disclosed vulnerability","__v":2},{"_id":"615d4eb9ba6c770042c62a7b","resources":{"videos":[],"roomCodes":["protocolsandservers2","securityprinciples"],"articles":[]},"term":"DAD","definition":"Disclosure, Alternation, and Destruction (DAD) is the opposite of Confidentiality, Integrity, and Availability (CIA).","__v":1},{"_id":"60f83e4ca3355d00419a834d","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"PHP","definition":"A scripting language mostly used for web development.","__v":0},{"_id":"61386bd8abe22e00485d9e71","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"PoC","definition":"A Proof of Concept is often a piece of code or an application that is used to demonstrate an idea or theory is possible. Proof of Concepts are often used to demonstrate vulnerabilities","__v":0},{"_id":"610be18284a8c800499edfa2","resources":{"videos":[],"roomCodes":["pentestingfundamentals"],"articles":["https://www.nist.gov/"]},"term":"NIST","definition":"National Institute of Standards and Technology (NIST). This organisation develops frameworks and policies for information security that is used all throughout the industry. ","__v":0},{"_id":"610be7477c96c0005263441b","resources":{"videos":[],"roomCodes":["vulnerabilities101","blog"],"articles":["https://kinsta.com/knowledgebase/content-management-system/"]},"term":"CMS","definition":"Content Management System (CMS).  These web applications are used to manage content on a website. For example, blogs, news sites, e-commerce sites and more!","__v":0},{"_id":"615d54715580e6004abd8a3f","resources":{"videos":[],"roomCodes":["protocolsandservers","protocolsandservers2"],"articles":[]},"term":"MTA","definition":"Mail Transport Agent. The MTA usually receives an email from an email client or another MTA.","__v":0},{"_id":"60d9e9ac5745fe00428c9993","resources":{"videos":[],"roomCodes":["linuxfundamentalspart1"," linuxfundamentalspart2"," linuxfundamentalspart3"],"articles":[]},"term":"Linux","definition":"Linux is a command line operating system based on unix. There are multiple operating systems that are based on Linux.","__v":0},{"_id":"6148b782926f7600503a6285","resources":{"videos":[],"roomCodes":["vulnerabilities101","principlesofsecurity","pentestingfundamentals"],"articles":["https://whatis.techtarget.com/definition/Confidentiality-integrity-and-availability-CIA"]},"term":"CIA","definition":"Confidentiality, Integrity, and Availability (CIA) is the opposite of Disclosure, Alternation, and Destruction (DAD).","__v":0},{"_id":"6148b717926f7600503a5f13","resources":{"videos":[],"roomCodes":["vulnerabilities101","hipflask","unifiedkillchain"],"articles":["https://nvd.nist.gov/vuln-metrics/cvss"]},"term":"CVSS","definition":"Common Vulnerability Scoring System","__v":1},{"_id":"61e69b89e1f68900425cf47a","resources":{"videos":[],"roomCodes":[],"articles":["https://www.sciencedirect.com/topics/computer-science/network-intrusion-detection-system"]},"term":"HIPS","definition":"Host Intrusion Prevention System (HIPS) protects workstations and servers through software that resides on the system. It catches suspect activity on the system and then either allows or disallows the event to happen, depending on the rules. Finally, it can also monitor data requests and read or write attempts and network connection attempts, potentially allowing it to be used as a compensating control for other requirements.","__v":0},{"_id":"6204e24791bace0189fb3071","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"DPI","definition":"Deep Packet Inspection","__v":0},{"_id":"62750e65901d880052a1d702","resources":{"videos":[],"roomCodes":["unifiedkillchain"," SDLC"," securesdlc"],"articles":["https://stackify.com/what-is-sdlc/"]},"term":"SDLC","definition":"Software Development Life Cycle is a software engineering concept which is the structured process of developing an application","__v":3},{"_id":"62bc40a25d6f9f0042f2c531","resources":{"videos":[],"roomCodes":["securesdlc"],"articles":[]},"term":"BSIMM","definition":" Building Security In Maturity Model (BSIMM) is a study of real-world software security initiatives and reflects the current state of software security.","__v":0},{"_id":"63032a71ce8f9900609a98df","resources":{"videos":[],"roomCodes":["tshark"],"articles":["https://en.wikipedia.org/wiki/Berkeley_Packet_Filter"]},"term":"BPF","definition":"The Berkeley Packet Filter (BPF) is a technology used in certain computer operating systems for programs that need to, among other things, analyze network traffic.  BPF supports filtering packets, allowing a userspace process to supply a filter program that specifies which packets it wants to receive.","__v":0},{"_id":"636f3a6fbd6244004a06d935","resources":{"videos":[],"roomCodes":[],"articles":["https://iapp.org/resources/article/personally-identifiable-information/"]},"term":"PII","definition":"Personally Identifiable Information is any representation of data that can be used to identify an individual directly.","__v":1},{"_id":"64e743066dfea0da31bc1345","term":"UEFI","definition":"The Unified Extensible Firmware Interface (UEFI) provides an interface between the operating system (OS) and the platform firmware. The UEFI replaces the BIOS.","resources":{"videos":[],"roomCodes":["operatingsystemsecurity"],"articles":[]},"__v":0},{"_id":"64e7477962a00b02f5ce126d","term":"Keylogger","definition":"A keylogger is a tool that is used to record user keystrokes on a physical computer.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e74867616167350af6e31c","term":"XXE","definition":"XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML data. It often allows an attacker to view files on the application server filesystem, and to interact with any back-end or external systems that the application itself can access.","resources":{"videos":[],"roomCodes":[],"articles":["https://portswigger.net/web-security/xxe"]},"__v":0},{"_id":"64e758f1e7009dab4898da1f","term":"AWS","definition":"Amazon Web Services (AWS) is a comprehensive cloud computing platform offered by Amazon. It provides a wide range of services such as computing power, storage, databases, networking, analytics, and more, delivered over the internet on a pay-as-you-go basis.","resources":{"videos":[],"roomCodes":["awsbasicconcepts"],"articles":[]},"__v":0},{"_id":"64e774d597d17507cc064d2c","term":"ROT","definition":"Also known as a Caesar cipher, is a simple form of substitution cipher used in cryptography. It involves replacing each letter in the text by a letter some fixed number of positions down or up the alphabet.","resources":{"videos":[],"roomCodes":["madness"],"articles":[]},"__v":0},{"_id":"64e77f2436f997cedf20a65e","term":"Persistence","definition":"Malware often tries to keep a footprint in the system such that it keeps running even after a system restart. This is called persistence. For example, If a malware adds itself to the startup registry keys, it will persist even after a system restart.","resources":{"videos":[],"roomCodes":["linuxforensics","windowsforensics1"],"articles":[]},"__v":0},{"_id":"64e8a86c7f1e943bb33c39fa","term":"HIPAA","definition":"Health Information Portability and Accountability Act (HIPAA). The primary law in the United States that governs the privacy of healthcare information","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://csrc.nist.gov/glossary/term/hipaa"]},"__v":0},{"_id":"64e8ab657d97de55d56e01ae","term":"GUI","definition":"The graphical user interface, or GUI, is a form of user interface that allows users to interact with electronic devices through graphical icons and audio indicators such as primary notation, instead of text-based UIs, typed command labels or text navigation. GUIs were introduced in reaction to the perceived steep learning curve of command-line interfaces (CLIs),which require commands to be typed on a computer keyboard.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://en.wikipedia.org/wiki/Graphical_user_interface"]},"__v":0},{"_id":"64e8e3496c8410fa3e688988","term":"PID","definition":"In the context of operating systems, PID stands for Process ID. It is a unique identifier assigned to each running process in a system. PIDs are usually assigned in sequential order as processes are created, but can be recycled once a process has completed and terminated. ","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"61644333365c0b00413500bd","resources":{"videos":[],"roomCodes":["passiverecon","activerecon"],"articles":[]},"term":"SMTP","definition":"Simple Mail Transfer Protocol (SMTP) is a protocol used to send the email to an SMTP server, more specifically to a Mail Submission Agent (MSA) or a Mail Transfer Agent (MTA).","__v":0},{"_id":"6164ff321891ea0048f02606","resources":{"videos":[],"roomCodes":["passiverecon"],"articles":[]},"term":"DNS","definition":"Domain Name System (DNS) is the protocol responsible for resolving hostnames, such as tryhackme.com, to their respective IP addresses.","__v":0},{"_id":"62f478e11c4393004859227c","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"OU","definition":"In Windows domains, Organizational Unit (OU) refers to containers that hold users, groups and computers to which similar policies should apply. In most cases, OUs will match departments in an enterprise.","__v":0},{"_id":"6304fe01a8a3880061a60159","resources":{"videos":[],"roomCodes":["cyberthreatintel"],"articles":[]},"term":"CTI","definition":"Cyber Threat Intelligence is evidence-based knowledge about adversaries, including their indicators, tactics, motivations, and actionable advice against them.","__v":0},{"_id":"64e71a096d6817b42113f762","term":"Zombie","definition":"A compromised computer or device controlled remotely by an attacker, typically part of a botnet used for malicious activities.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e743706dfea0da31bc2391","term":"DES","definition":"The Data Encryption Standard (DES) is a symmetric encryption block encryption algorithm which uses a cryptographic key size of 56 bits. AES became the new standard in 2001.","resources":{"videos":[],"roomCodes":["cryptographyintro"],"articles":[]},"__v":0},{"_id":"64e74d61e5c55d828a501c4b","term":"Blue Team","definition":"A blue team comprises cyber security and technology professionals whose aim is to protect an information system from impending cyber threats by performing and implementing defensive actions.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e758556ec72fd20bc81fde","term":"Gobuster","definition":"A command-line tool written in Go that performs directory, file, DNS subdomain, and virtual host brute-forcing by rapidly requesting every entry in a wordlist against a target and reporting which ones return a real response.","resources":{"roomCodes":["vulnversity","gobusterthebasics"],"videos":[],"articles":[]},"__v":0},{"_id":"64e75a413a2ae4c8c7dae15b","term":"AppLocker","definition":"A Windows application control feature that allows or blocks executables and scripts by rule, logging allow and deny decisions to the AppLocker event channels.","resources":{"roomCodes":["microsoftwindowshardening"],"videos":[],"articles":[]},"__v":0},{"_id":"64e8aba27d97de55d56e0863","term":"TTL","definition":"Time to live (TTL) refers to the amount of time or “hops” that a packet is set to exist inside a network before being discarded by a router. TTL is also used in other contexts including CDN caching and DNS caching.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://www.cloudflare.com/learning/cdn/glossary/time-to-live-ttl/"]},"__v":0},{"_id":"615728facbada7004ab02cd2","resources":{"videos":[],"roomCodes":[],"articles":["https://www.w3schools.com/xml/xml_whatis.asp"]},"term":"XML","definition":"Extensible Markup Language is a markup language that defines a set of rules for encoding documents in a format that is both human-readable and machine-readable","__v":0},{"_id":"61ae0c92869b150053f61b89","resources":{"roomCodes":["phishingemails1","cyberkillchain"],"videos":[],"articles":[]},"term":"Phishing","definition":"When emails are sent to a target(s) purporting to be from a trusted entity to lure individuals into providing sensitive information. ","__v":0},{"_id":"6225526ba1b1fa00433011d6","resources":{"videos":[],"roomCodes":["introtoc2"],"articles":["https://docs.fileformat.com/programming/hta/"]},"term":"HTA","definition":"HTML Application (HTA) files are files that contain HTML, JScript, and or VBScript code that can be executed on client system. This can to lead to more dynamic applications or remote code execution on a client or victim.","__v":0},{"_id":"626bbf9d44d1ac0043123175","resources":{"videos":[],"roomCodes":["dataxexfilt"],"articles":[]},"term":"Apache","definition":"Apache is the most widely used web server software. Developed and maintained by Apache Software Foundation, Apache is an open source software available for free.","__v":0},{"_id":"6282c6b2548cd7004b176b1e","resources":{"videos":[],"roomCodes":["securesdlc"],"articles":[]},"term":"Sprint","definition":"A short period of time wherein a development team works to complete specific tasks, milestones, or deliverables.","__v":0},{"_id":"62bc3fc921035e0049387328","resources":{"videos":[],"roomCodes":["securesdlc"],"articles":[]},"term":"DAST","definition":"Dynamic Application Security Testing scans running aplications for vulnerabilities","__v":0},{"_id":"62bc4038a043ab005f64ec0e","resources":{"videos":[],"roomCodes":["securesdlc"],"articles":[]},"term":"RASP","definition":"Runtime Application Self-Protection is a tool / software built at the runtime environment and it can control application execution to detect real time attacks","__v":0},{"_id":"62c1babe15190d004847de69","resources":{"videos":[],"roomCodes":["cve202226134"],"articles":[]},"term":"OGNL","definition":"Object-Graph Navigation Language","__v":0},{"_id":"6365fb27c9e88d0042cbb3e4","resources":{"videos":[],"roomCodes":["registrypersistencedetection"],"articles":[]},"term":"PowerShell","definition":"PowerShell is a task automation and configuration management program from Microsoft, consisting of a command-line shell and the associated scripting language.","__v":0},{"_id":"637c94f76677bc004b913728","resources":{"videos":[],"roomCodes":[],"articles":["https://en.wikipedia.org/wiki/MIME"]},"term":"MIME","definition":"Multipurpose Internet Mail Extensions (MIME) is an Internet standard that extends the format of email messages to support text in character sets other than ASCII, as well as attachments of audio, video, images, and application programs.","__v":0},{"_id":"644264d1bd356e00564550d4","resources":{"roomCodes":["containerhardening"],"videos":[],"articles":["https://www.infoworld.com/article/3271126/what-is-cicd-continuous-integration-and-continuous-delivery-explained.html"]},"term":"CI","definition":"Continuous  Integration is a software development practice that involves automatically building, testing and implementing changes to an application's source code","__v":0},{"_id":"646b03ce389d5e0060210321","resources":{"roomCodes":[],"videos":[],"articles":["https://en.wikipedia.org/wiki/User_behavior_analytics"]},"term":"UBA","definition":"User behavior analytics (UBA) or User and Entity Behavior Analytics (UEBA),[1] is the concept of analyzing the behavior of users, subjects, visitors, etc. for a specific purpose.[2] Il allows cybersecurity tools to build a profile of each individual's normal activity, by looking at patterns of human behavior, and then highlighting deviations from that profile (or anomalies) that may indicate a potential compromise.[3][4][5]","__v":0},{"_id":"646fe62aaf8db9004be8ed74","resources":{"roomCodes":[],"videos":[],"articles":["https://en.wikipedia.org/wiki/Link-Local_Multicast_Name_Resolution"]},"term":"LLMNR","definition":"The Link-Local Multicast Name Resolution (LLMNR) is a protocol based on the Domain Name System (DNS) packet format that allows both IPv4 and IPv6 hosts to perform name resolution for hosts on the same local link.","__v":0},{"_id":"64e7759b97d17507cc0781ce","term":"XOR","definition":"Is a binary operation that is commonly used for encryption and decryption of data. XOR operates on binary data (bits) and is based on the principles of Boolean algebra. The operation involves two bits. The result of the operation is \"1\" if the two bits are different, and \"0\" if they are the same.","resources":{"videos":[],"roomCodes":["antireverseengineering"],"articles":[]},"__v":0},{"_id":"64e777efbb76e2a4e4c4cdd3","term":"DOS","definition":"A computer operating system that provides a file system for operations such as reading, writing, and erasing data on a disk. It is a non-graphical line-oriented command-driven computer operating system designed for the IBM PC. Several variations of DOS were developed, such as MS-DOS (Microsoft) and PC-DOS (IBM).","resources":{"videos":[],"roomCodes":["dissectingpeheaders"],"articles":[]},"__v":0},{"_id":"64e778b97f998be834810512","term":"IR","definition":"Incident Response (IR) is a structured approach to managing and addressing the aftermath of a security breach or cyberattack, also known as an IT incident, computer incident, or security incident. It involves identifying, investigating, handling, and learning from security events or incidents to prevent a similar occurrence.","resources":{"roomCodes":["introductoryroomdfirmodule","preparation"],"videos":[],"articles":[]},"__v":0},{"_id":"64e77a099fba389b9f10c17d","term":"DFIR","definition":"Digital Forensics and Incident Response","resources":{"videos":[],"roomCodes":["introductoryroomdfirmodule"],"articles":[]},"__v":0},{"_id":"64e8a9d032480a50b6e40b1f","term":"FISMA","definition":"FISMA is an acronym that stands for the Federal Information Security Modernization Act. FISMA is United States legislation that defines a comprehensive framework to protect government information, operations and assets against natural or man-made threats. FISMA was signed into law part of the Electronic Government Act of 2002.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://olao.od.nih.gov/content/what-fisma"]},"__v":0},{"_id":"61890135bb6c65005470b16a","resources":{"videos":[],"roomCodes":[],"articles":["https://en.wikipedia.org/wiki/DMARC"]},"term":"DMARC","definition":"Domain-based Message Authentication, Reporting, and Conformance, or DMARC, is a technical standard that helps protect email senders and recipients from spam, spoofing, and phishing.","__v":0},{"_id":"6164fe89f5e4ed005e047898","resources":{"roomCodes":["nmap01"],"videos":[],"articles":[]},"term":"ARP","definition":"Address Resolution Protocol (ARP) is responsible for finding the MAC (hardware) address related to a specific IP address. It works by broadcasting an ARP query, \"Who has this IP address? Tell me.\" And the response is of the form, \"The IP address is at this MAC address.\"","__v":0},{"_id":"61b0ed8caf680c004f11bc72","resources":{"videos":[],"roomCodes":["disgruntled"],"articles":["https://www.vmware.com/topics/glossary/content/virtual-machine"]},"term":"VM","definition":"Virtual Machine","__v":1},{"_id":"615d54855580e6004abd8ac8","resources":{"videos":[],"roomCodes":["protocolsandservers","protocolsandservers2"],"articles":[]},"term":"MUA","definition":"Mail User Agent. MUA refers to the email client that the user relies on to send and receive email. Examples of MUA are Thunderbird and MS Outlook. The MUA connects to a Mail Transport Agent (MTA) to send its message, and it connects to a Mail Delivery Agent (MDA) to download its email messages.","__v":0},{"_id":"616941f33b6eeb005085b835","resources":{"roomCodes":["auroraedr"],"videos":[],"articles":[]},"term":"EDR","definition":"Endpoint detection and response (EDR) is a series of tools that monitor devices for activity that could indicate a threat.","__v":3},{"_id":"61e69ddd9f481d0ad7b8ac95","resources":{"videos":[],"roomCodes":[],"articles":["https://www.sciencedirect.com/topics/computer-science/network-intrusion-detection-system"]},"term":"NIDS","definition":"Network Intrusion Detection System (NIDS) is an independent platform that examines network traffic patterns to identify intrusions for an entire network.","__v":1},{"_id":"61fc68700e31d40041ede20a","resources":{"videos":[],"roomCodes":[],"articles":["https://www.snort.org/faq/readme-daq"]},"term":"DAQ","definition":"Data Acquisition library, for packet I/O. The DAQ replaces direct calls to libpcap functions with an abstraction layer that facilitates operation on a variety of hardware and software interfaces without requiring changes to Snort.","__v":0},{"_id":"620cd0684e4940004b736002","resources":{"videos":[],"roomCodes":[],"articles":["https://www.solarwinds.com/resources/it-glossary/pcap"]},"term":"PCAP","definition":"Packet capture (PCAP) is a networking practice involving the interception of data packets travelling over a network. Once the packets are captured, they can be stored by IT teams for further analysis. The inspection of these packets allows IT teams to identify issues and solve network problems affecting daily operations.","__v":0},{"_id":"62254b6fbf3b3000444e33de","resources":{"videos":[],"roomCodes":["introtoc2 ","opsec"],"articles":[]},"term":"OPSEC","definition":"Operational Security (OPSEC) is a set of principals and tactics used to attempt to protect the security of an operator or operation. An example of this may be using code names instead of your real names, or using a proxy to conceal your IP address.","__v":0},{"_id":"6229ae2f69208a004a937248","resources":{"videos":[],"roomCodes":[],"articles":["https://www.sciencedirect.com/science/article/pii/B9780124172081000118"]},"term":"NSM","definition":"Network Security Monitoring is based upon the collection of data to perform detection and analysis. With the collection of a large amount of data, it makes sense that a SOC should have the ability to generate statistical data from existing data, and that these statistics can be used for detection and analysis.","__v":0},{"_id":"62792734e98329004a1dd6b5","resources":{"roomCodes":["opencti","intelcreationandcontainment","threatemulationintro"],"videos":[],"articles":["https://csrc.nist.gov/glossary/term/Tactics_Techniques_and_Procedures"]},"term":"TTP","definition":"Tactics, Techniques and Procedures describe the methodologies, tools, behavioural patterns and strategies that adversaries use to plan and execute attacks against target networks and organisations.","__v":1},{"_id":"62a2a1c71149220043dd052e","resources":{"videos":[],"roomCodes":["windowslocalpersistence"],"articles":["https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/acls-dacls-sacls-aces"]},"term":"DACL","definition":"Discretionary Access Control Lists are used by Windows systems to specify who can access a given resource. While they are often referenced when talking about files, they also apply to other components as registry keys, services and scheduled tasks.","__v":0},{"_id":"64539c0da6e8cb0060478191","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"CSF","definition":"Cyber Security Framework (CSF) is a set of guidelines and measures for organisations to manage and improve their cybersecurity posture by identifying, assessing, and managing their cybersecurity risks.","__v":0},{"_id":"64a67edb64ad2a0044bfb80f","resources":{"videos":[],"roomCodes":["threatemulationintro"],"articles":[]},"term":"DMZ","definition":"A DMZ  or demilitarized zone is a perimeter network that protects and adds an extra layer of security to an organization’s internal local-area network from untrusted traffic.  The end goal of a demilitarized zone network is to allow an organization to access untrusted networks, such as the internet, while ensuring its private network or LAN remains secure","__v":0},{"_id":"64e745c87007606a14cbf370","term":"WPA","definition":"Wi-Fi Protected Access is a Wi-Fi protocol that has better security mechanisms than protocols such as WEP by means of handling user authentication and keys more securely. WPA has been further improved by versions such as WPA2 and WPA3","resources":{"videos":[],"roomCodes":[],"articles":["https://www.kaspersky.com/resource-center/definitions/wep-vs-wpa"]},"__v":0},{"_id":"64e754701bf2b9500842a90b","term":"SoD","definition":"The Spreadsheet of Doom (SoD) is an Excel spreadsheet containing a carefully maintained collection of Indicators of Compromise (IoCs).\n\nThese IoCs act as warning signs, alerting security experts to suspicious behaviour or potential system breaches. By keeping track of these indicators, the SoD offers a detailed snapshot of possible threats, allowing for quick identification, analysis, and response.\n\nWhether it involves tracking IP addresses, URLs, file hashes, or other distinguishing features associated with malicious activities, the SoD is vital in bolstering security protocols and keeping cyber attackers at bay.","resources":{"videos":[],"roomCodes":["identificationandscoping"],"articles":[]},"__v":0},{"_id":"64e8ac64738754697b078bd7","term":"IMAP","definition":"The Internet Message Access Protocol (IMAP) is a protocol for receiving email. Protocols standardize technical processes so computers and servers can connect with each other regardless of whether or not they use the same hardware or software.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://www.cloudflare.com/learning/email-security/what-is-imap/"]},"__v":0},{"_id":"64e8d4d100f4cb5e7789b804","term":"LFI","definition":"Local File Inclusion (LFI) is a security vulnerability that occurs when a web application allows users to include files from the local file system. Attackers exploit LFI by manipulating input fields to retrieve sensitive files or execute malicious code. This can lead to unauthorised access to system files, data leakage, and potential remote code execution.","resources":{"videos":[],"roomCodes":["fileinc"],"articles":[]},"__v":0},{"_id":"64e8e6ed89d425441c459c47","term":"EVTX","definition":"An EVTX file is a Windows XML event log file. It is a file format used to store event logs generated by the Windows Event Logging system. ","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"6148b73d6ea74a005f0811c8","resources":{"videos":[],"roomCodes":[],"articles":["https://docs.tenable.com/tenablesc/Content/RiskMetrics.htm"]},"term":"VPR","definition":"Vulnerability Priority Rating","__v":0},{"_id":"6241b5eaf6612800442dba82","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"command-line application","definition":"Command-line applications are computer programs designed to be used from a text interface; think of it as if you're using an application without a user interface.","__v":0},{"_id":"6164ffaa8040a600415e9685","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"OS","definition":"Operating System (OS) is a layer between the hardware and the applications. From the application's perspective, the OS provides an interface to access the different hardware components, such as CPU, RAM, and disk storage. Examples of OS are Android, FreeBSD, Linux, macOS, and Windows.","__v":0},{"_id":"61e69a0ce1f68900425cec4c","resources":{"videos":[],"roomCodes":[],"articles":["https://www.sciencedirect.com/topics/computer-science/network-intrusion-detection-system"]},"term":"HIDS","definition":"Host Intrusion Detection System (HIDS) analyzes system state, system calls, file-system modifications, application logs, and other system activity.","__v":1},{"_id":"640866454ada700048d6e8b1","resources":{"roomCodes":["activedirectoryhardening"],"videos":[],"articles":[]},"term":"ACL","definition":"An Access Control List (ACL) is a list of permissions that determine who can access a specific resource in a computer network. It is used to grant or deny access to files, folders, printers, and other network resources.","__v":0},{"_id":"64e746958a02d4280fa4e81f","term":"BYOD","definition":"Bring Your Own Device is the term given for devices that are owned by an employee but are usually used for work-related activities. For example, an employee uses their personal device to access emails. A BYOD policy outlines what type of devices are acceptable, what behaviour is acceptable, as well as any necessary steps to secure the device (for example, requiring anti-virus) ","resources":{"videos":[],"roomCodes":[],"articles":["https://www.fortinet.com/resources/cyberglossary/byod"]},"__v":0},{"_id":"64e79f8f9f4b7ac7acb887df","term":"SSDLC","definition":"SSDLC (Secure Software Development Life Cycle) is an extension of DevOps practices, focused on building secure products.","resources":{"roomCodes":["securesdlc","introductiontodevsecops"],"videos":[],"articles":[]},"__v":0},{"_id":"64e7a016edd9771497e74b67","term":"DevOps","definition":"DevOps is a set of practices, tools, and a cultural philosophy that automate and integrate the processes to build software.","resources":{"videos":[],"roomCodes":["securesdlc","introductiontodevsecops","sdlc"],"articles":[]},"__v":0},{"_id":"64e7a0de61e95584abb57f4f","term":"Jenkins","definition":"Jenkins is an open-source automation server widely used in DevOps for building, testing, and deploying software applications. ","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"611236b3f2adaf00481f1d4a","resources":{"videos":[],"roomCodes":["pentestingfundamentals"],"articles":[]},"term":"ROE","definition":"The Rules of Engagement is a document that gives permission to a penetration tester, defining the targets that the engagement applies to and the behaviours/techniques that","__v":0},{"_id":"61645029365c0b004135edb4","resources":{"videos":[],"roomCodes":["nmap01"],"articles":[]},"term":"UDP","definition":"User Datagram Protocol (UDP) is a connectionless protocol; UDP does not require a connection to be established. UDP is suitable for protocols that rely on fast queries, such as DNS, and for protocols that prioritise real-time communications, such as audio/video conferencing and broadcast.","__v":0},{"_id":"618900fde66fed005f940982","resources":{"videos":[],"roomCodes":[],"articles":["https://en.wikipedia.org/wiki/DomainKeys_Identified_Mail"]},"term":"DKIM","definition":"DKIM (DomainKeys Identified Mail) is an email security standard designed to make sure messages aren't altered in transit between the sending and recipient servers.","__v":0},{"_id":"6239955fbd2e7e0054e3ea0b","resources":{"videos":[],"roomCodes":["introtoav"],"articles":[]},"term":"AV","definition":"Antivirus software is a program or set of programs that are designed to prevent, search for, detect, and remove software viruses, and other malicious software like worms, trojans, adware, and more.","__v":0},{"_id":"62750e0ab1fe4b0044cc6028","resources":{"roomCodes":["principlesofsecurity","unifiedkillchain","securesdlc"],"videos":[],"articles":["https://owasp.org/www-community/Threat_Modeling_Process#stride"]},"term":"STRIDE","definition":"Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service (DoS), and Elevation of Privilege","__v":1},{"_id":"627826ec1c0dcd00497cff90","resources":{"videos":[],"roomCodes":["introductiontodevsecops"],"articles":[]},"term":"Chewba-QA","definition":"A hairy, bear-like creature that performs Quality Analysis in DevOps","__v":0},{"_id":"633078021449f300637cba1d","resources":{"videos":[],"roomCodes":["sigma"],"articles":[]},"term":"YAML","definition":"YAML Ain't Markup Language is a data serialisation language that is human-readable and useful for managing data.","__v":0},{"_id":"646de75cad0aa7006099a770","resources":{"roomCodes":[],"videos":[],"articles":[]},"term":"Git","definition":"Git is a distributed version control system used for tracking changes in files and coordinating work among multiple contributors. It provides efficient branching, merging, and collaboration capabilities for software development projects.","__v":0},{"_id":"64e74355218eb84610cba28f","term":"AES","definition":"The Advanced Encryption Standard (AES) is a symmetric block encryption algorithm. It can use cryptographic keys of sizes 128, 192, and 256 bits.","resources":{"videos":[],"roomCodes":["cryptographyintro"],"articles":[]},"__v":0},{"_id":"64e745f0edd9771497d15a7c","term":"MD5","definition":"Message Digest 5 (MD5) is a cryptographic hash function that takes any input and produces a 128-bit hexadecimal number. The output of an MD5 hash function is called a digest. MD5 digests are often used to verify the integrity of files or data; however, MD5 is no longer considered secure and should not be used for sensitive applications.","resources":{"videos":[],"roomCodes":["cryptographyintro"],"articles":[]},"__v":0},{"_id":"64e74a0336f997cedf158939","term":"SSH","definition":"Secure Shell (SSH) refers to a cryptographic network protocol used in secure communication between devices. SSH encrypts data using cryptographic algorithms, such as Advanced Encryption System (AES) and is often used when logging in remotely to a computer or server.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e74e65eef2dc167fc1d4f3","term":"IETF","definition":"The Internet Engineering Task Force (IETF) is a standards organization for the Internet and is responsible for the technical standards that comprise the Internet protocol suite.","resources":{"roomCodes":[],"videos":[],"articles":["https://www.ietf.org"]},"__v":0},{"_id":"64e773881bf2b9500848db26","term":"ASM","definition":"A low-level programming language that uses symbolic code as a direct representation of machine code. It enables a programmer to write instructions that the computer's processor can execute directly. Each line corresponds to a specific machine operation, often based on a sequence of numbers, letters, and symbols. \n","resources":{"roomCodes":["win64assembly"],"videos":[],"articles":[]},"__v":0},{"_id":"64e8ad0e53cdb22f81a23a0e","term":"HUMINT","definition":"Human Intelligence (HUMINT) is a form of  “on the ground”  information gathering using human sources to collect information. In the context of Threat Intelligence, this can include infiltrating and engaging with threat actors on underground crime networks, forums and marketplaces, chat platforms, and other target environments, to include the dark web.","resources":{"videos":[],"roomCodes":[],"articles":["https://www.crowdstrike.com/cybersecurity-101/threat-intelligence/human-intelligence-humint/"]},"__v":0},{"_id":"61645060e4117a005ace093a","resources":{"videos":[],"roomCodes":["nmap01"],"articles":[]},"term":"TCP","definition":"Transmission Control Protocol (TCP) is a connection-oriented protocol requiring a TCP three-way-handshake to establish a connection. TCP provides reliable data transfer, flow control and congestion control. Higher-level protocols such as HTTP, POP3, IMAP and SMTP use TCP","__v":0},{"_id":"6218bfc78fcb3f00447ec621","resources":{"videos":[],"roomCodes":[],"articles":["https://docs.microsoft.com/en-us/windows/security/identity-protection/user-account-control/user-account-control-overview"]},"term":"UAC","definition":"User Account Control (UAC) helps prevent malware from damaging a PC and helps organizations deploy a better-managed desktop. With UAC, apps and tasks always run in the security context of a non-administrator account, unless an administrator specifically authorizes administrator-level access to the system. UAC can block the automatic installation of unauthorized apps and prevent inadvertent changes to system settings.","__v":0},{"_id":"62750cecb78789004b27b598","resources":{"videos":[],"roomCodes":["unifiedkillchain","principlesofsecurity","opencti"],"articles":["https://attack.mitre.org/"]},"term":"MITRE","definition":"MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK)","__v":1},{"_id":"62a2a0137a1f81004b9040ae","resources":{"videos":[],"roomCodes":["windowslocalpersistence"],"articles":["https://www.cyberark.com/resources/threat-research-blog/explain-like-i-m-5-remote-desktop-protocol-rdp"]},"term":"RDP","definition":"Remote Desktop Protocol is a protocol used to establish remote graphical sessions over the network.","__v":1},{"_id":"62bc382a6c18910043aac133","resources":{"videos":[],"roomCodes":["securesdlc"],"articles":[]},"term":"PASTA","definition":"PASTA is short for Process for Attack Simulation and Threat Analysis; it is a risk-centric threat modelling framework.","__v":0},{"_id":"62f47b7dce2eef00601daa0c","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"TGT","definition":"In Kerberos, a Ticket Granting Ticket (TGT) serves as a user's proof of authentication and allows a user to request service tickets from the KDC, which can then be used to connect to services across the network.","__v":0},{"_id":"63308d0a09a13a004a779a29","resources":{"videos":[],"roomCodes":["sigma"],"articles":[]},"term":"UUID","definition":"Universal Unique Identifier is a 128-bit value used to uniquely identify an object, entity or information within a particular system or knowledge database.","__v":0},{"_id":"638613b83b67c80048e19b80","resources":{"roomCodes":["sigma","identificationandscoping","introtosiem"],"videos":[],"articles":[]},"term":"SIEM","definition":"Security Information and Event Management system that is used to aggregate security information in the form of logs, alerts, artifacts and events into a centralized platform that would allow security analysts to perform near real-time analysis during security monitoring.","__v":9},{"_id":"642e8d35447b58005471d677","resources":{"roomCodes":["soar"],"videos":[],"articles":[]},"term":"SOAR","definition":"SOAR stands for Security Orchestration, Automation, and Response. It is a solution that helps organisations to streamline and automate their security operations, including incident management, threat intelligence, and vulnerability response.","__v":0},{"_id":"644265431bf74a004abeeffc","resources":{"roomCodes":[],"videos":[],"articles":["https://www.synopsys.com/glossary/what-is-continuous-development.html"]},"term":"CD","definition":"Continuous Deployment is a software development term for deploying code to production environments automatically without any interaction from a human. For example, the automation of tests and then deployment of the code.","__v":0},{"_id":"64e742e56dfea0da31bc0b4f","term":"BIOS","definition":"The Basic Input/Output System (BIOS) is a boot firmware that provides runtime services for the operating system (OS). The BIOS starts, checks specific hardware components, and loads the OS depending on boot priority.","resources":{"videos":[],"roomCodes":["operatingsystemsecurity"],"articles":[]},"__v":0},{"_id":"64e7501436f997cedf176ab7","term":"IoT","definition":"IoT (Internet of Things) refers to the network of physical objects, or \"things\", that are embedded with sensors and software which allow them to collect and exchange data over the Internet. These objects can include various devices, from everyday household items like thermostats, refrigerators, and lightbulbs, to industrial equipment, vehicles, and more.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e77c84738754697bbcd5bf","term":"KAPE","definition":"Kroll Artifact Parser and Extractor. A tool created by Eric Zimmerman used to parse and extract forensic artifacts from a system.","resources":{"roomCodes":["kape"],"videos":[],"articles":["https://www.kroll.com/en/insights/publications/cyber/kroll-artifact-parser-extractor-kape"]},"__v":0},{"_id":"64e79941a640cc112776a1fd","term":"ICS","definition":"ICS denotes systems responsible for overseeing and conducting functions that support critical infrastructure, such as water, power, transportation, and manufacturing.","resources":{"roomCodes":["attackingics1"],"videos":[],"articles":[]},"__v":0},{"_id":"64e79fcfe5c55d828a646881","term":"Pipelines","definition":"Are a set of automated processes and tools that allows both developers and operations professionals to build and deploy code to a production environment.","resources":{"videos":[],"roomCodes":["securesdlc","introductiontodevsecops","sdlc"],"articles":[]},"__v":0},{"_id":"64e8ac06125601bcbffe3727","term":"NTLM","definition":"Windows New Technology LAN Manager (NTLM) is a suite of security protocols offered by Microsoft to authenticate users’ identity and protect the integrity and confidentiality of their activity.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://www.crowdstrike.com/cybersecurity-101/ntlm-windows-new-technology-lan-manager/"]},"__v":0},{"_id":"64e8e3d8e459c280dcde52e2","term":"PPID","definition":"In the context of operating systems, PPID stands for Parent Process ID. It refers to the process ID of the parent process that spawned the particular process. PPIDs indicate the hierarchy and relationship of all running processes in a system, which also describes how every process is connected to one another.","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"615d564e35c04300493a800d","resources":{"videos":[],"roomCodes":["protocolsandservers2"],"articles":[]},"term":"PKI","definition":"Public Key Infrastructure (PKI) makes it possible for different entities to communicate securely over a network. Consequently, we can protect the confidentiality and integrity of the communications, among other aspects.","__v":0},{"_id":"649fd9fc7f997b0060e470c3","resources":{"roomCodes":["introtoshells"],"videos":[],"articles":[]},"term":"RCE","definition":"Remote Code Execution (RCE) is a vulnerability that allows an attacker to run arbitrary code on a remote system. If exploited successfully, it often leads to full system compromise.","__v":0},{"_id":"64e7498483a17b86aa183d67","term":"OWASP","definition":"The Open Web Application Security Project is a nonprofit foundation focused on understanding web technologies and exploitations and provides resources and tools designed to improve the security of software applications.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e8a79f2c8f9c09493c49ac","term":"NFAT","definition":"Network forensic analysis tools (NFAT) typically provide the same functionality as packet sniffers, protocol analyzers, and SEM software in a single product. Whereas SEM software concentrates on correlating events among existing data sources (which typically include multiple network traffic related sources), NFAT software focuses primarily on collecting, examining, and analyzing network traffic. NFAT software also offers additional features that further facilitate network forensics.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-86.pdf"]},"__v":0},{"_id":"64e8ac8b53cdb22f81a212af","term":"POP3","definition":"Post Office Protocol Version 3 (POP3) is an alternative protocol for receiving emails that downloads emails from the server to a local device. Using POP3, a recipient cannot access their emails again from a different device because they are stored locally and then deleted from the email server.","resources":{"videos":[],"roomCodes":[],"articles":["https://www.cloudflare.com/learning/email-security/what-is-imap/"]},"__v":0},{"_id":"64e8d61a32480a50b6f95077","term":"SSRF","definition":"Server Side Request Forgery (SSRF) is a web vulnerability where an attacker manipulates a vulnerable application to make requests to internal or external resources on behalf of the server. This can lead to data exposure, unauthorised access to internal systems, or service disruptions.","resources":{"videos":[],"roomCodes":["ssrfqi"],"articles":[]},"__v":0},{"_id":"6218c0528fcb3f00447eca34","resources":{"videos":[],"roomCodes":[],"articles":["https://docs.microsoft.com/en-us/troubleshoot/windows-client/deployment/dynamic-link-library"]},"term":"DLL","definition":"A DLL file, short for Dynamic Link Library, is a library that contains code and data that can be used by more than one program at the same time. For example, in Windows operating systems, the Comdlg32 DLL performs common dialog box related functions. Each program can use the functionality that is contained in this DLL to implement an Open dialog box. It helps promote code reuse and efficient memory usage.","__v":0},{"_id":"64009c6166c68e00432960cd","resources":{"roomCodes":["threatemulationintro","cyberkillchain"],"videos":[],"articles":[]},"term":"Social engineering","definition":"The manipulation of individuals to divulge sensitive information, through various forms of communication","__v":1},{"_id":"646fe68042700e0052345215","resources":{"roomCodes":[],"videos":[],"articles":["https://en.wikipedia.org/wiki/Data_loss_prevention_software"]},"term":"DLP","definition":"Data Loss Prevention (DLP) software detects potential data breaches/data ex-filtration transmissions and prevents them by monitoring,[1] detecting and blocking sensitive data while in use (endpoint actions), in motion (network traffic), and at rest (data storage).","__v":0},{"_id":"64bf9f6db15120004abd1681","resources":{"videos":[],"roomCodes":["iaaaidm","auditingandmonitoringse"],"articles":[]},"term":"IAAA","definition":"IAAA stands for Identification, Authentication, Authorization, and Accountability. It is a security principle that is used to protect systems and data. IAAA ensures that only authorized users can access a system and that their actions can be tracked.","__v":0},{"_id":"64e71a51afe601e784c78577","term":"Zone Transfer","definition":"The process of replicating DNS zone data from one DNS server to another, which needs to be secured to prevent unauthorized access.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e74463f47cb479f503c224","term":"LUKS","definition":"Linux Unified Key Setup (LUKS) is a cryptographic disk encryption standard for Linux systems. It uses symmetric and asymmetric encryption to protect data on encrypted disks and partitions. LUKS is a versatile encryption method that can be used to encrypt any block device, including hard drives, USB drives, and even entire operating systems.","resources":{"videos":[],"roomCodes":["cryptographyintro"],"articles":[]},"__v":0},{"_id":"64e74501eef2dc167fbe900e","term":"GPG","definition":"GPG stands for GNU Privacy Guard. It is a free and open-source encryption software that uses public-key cryptography. GPG can be used to encrypt files and messages, and to sign files and messages. Encryption makes it so that only the intended recipient can decrypt the file or message while signing makes it so that the recipient can verify that the file or message was sent by the person it claims to be from.","resources":{"videos":[],"roomCodes":["cryptographyintro"],"articles":[]},"__v":0},{"_id":"64e7477705f02e403993318c","term":"VPN","definition":"A Virtual Private Network is a way to create a secure \"tunnel\" between two networks. For example, you use a VPN on TryHackMe to access the private network on which the machines operate. VPNs are also commonly used for an employee to log into their workplace when they are not on site (such as working from home or travelling for business matters).\n\nVPNs are also used where networks (such as coffee shops) do not provide encryption, and are a great way of preventing others from reading your network traffic.","resources":{"videos":[],"roomCodes":[],"articles":["https://www.cisco.com/c/en_uk/products/security/vpn-endpoint-security-clients/what-is-vpn.html"]},"__v":0},{"_id":"64e774621bf2b95008490f19","term":"TrueCrypt","definition":"TrueCrypt is a discontinued software application used for on-the-fly encryption (OTFE). It can create a virtual encrypted disk within a file or encrypt a partition or the entire storage device. TrueCrypt was originally designed to protect sensitive data on computers and prevent unauthorized access.","resources":{"videos":[],"roomCodes":["memoryforensics"],"articles":[]},"__v":0},{"_id":"64e77a78de0a9972744cc71e","term":"Dynamic Analysis","definition":"The process of analyzing malware by running it in a controlled environment like a sandbox.","resources":{"videos":[],"roomCodes":["basicdynamicanalysis","advanceddynamicanalysis","intromalwareanalysis"],"articles":[]},"__v":0},{"_id":"64e77ac3d1e839ab60861843","term":"Static Analysis","definition":"The process of analyzing malware without executing it, but in a controlled environment.","resources":{"videos":[],"roomCodes":["intromalwareanalysis","staticanalysis1"],"articles":[]},"__v":0},{"_id":"64e77b0b9f4b7ac7acb1301d","term":"VPC","definition":"A virtual private cloud (VPC) is an isolated, private cloud inside of a public cloud environment. VPCs are granted to users of cloud providers so that their resources aren't accessible by other users in the same public cloud.","resources":{"videos":[],"roomCodes":[],"articles":["https://en.wikipedia.org/wiki/Virtual_private_cloud"]},"__v":0},{"_id":"64e77e4a36f997cedf2090cf","term":"ZTNA","definition":"Zero Trust Network Architecture. ","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e7a0ac61e95584abb57e1a","term":"CI/CD","definition":"CI/CD stands for Continuous Integration/Continuous Delivery. They are a set of practices and principles that enable automated software releases. ","resources":{"videos":[],"roomCodes":["securesdlc","introductiontodevsecops","sdlc"],"articles":[]},"__v":0},{"_id":"64e8e5d153cdb22f81b093b1","term":"Sysmon","definition":"Sysmon refers to System Monitor, which is a Windows system service and device driver developed by Microsoft that is designed to monitor and log various events happening within a Windows system. ","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"62012000acfcde00497bd25d","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"IPS","definition":"Intrusion Prevention System (IPS) is a device or application that detects and stops intrusions attempts proactively. They are usually deployed in front of the protected asset and block any potential threat from reaching their target.","__v":0},{"_id":"62254cef89c58e004911095d","resources":{"videos":[],"roomCodes":["introtoc2"],"articles":["https://hstechdocs.helpsystems.com/manuals/cobaltstrike/current/userguide/content/topics/beacon-object-files_main.htm"]},"term":"BOF","definition":"Beacon Object Files (BOF) is a set of compiled code written in a C-language that interacts with the Windows API to enable additional functionality within a C2 agent.","__v":0},{"_id":"62bc3fef21035e0049387552","resources":{"videos":[],"roomCodes":["securesdlc"],"articles":[]},"term":"IAST","definition":"Interactive Application Security Testing combines SAST and DAST and scans source code as well as running applications","__v":0},{"_id":"64e777a17f998be83480bc3c","term":"PE","definition":"A file format for executables, object code, DLLs, FON Font files, and others used in 32-bit and 64-bit versions of Windows operating systems. The PE format is a data structure that encapsulates the information necessary for the Windows OS to manage the wrapped executable code.","resources":{"videos":[],"roomCodes":["dissectingpeheaders"],"articles":[]},"__v":0},{"_id":"64e77bfc125601bcbfacd3a0","term":"SPL","definition":"Search Processing Language. A processing language used for searching in Splunk","resources":{"videos":[],"roomCodes":["splunkdashboardsandreports","splunkexploringspl"],"articles":[]},"__v":0},{"_id":"64e8a8ede7aecb247be0fa23","term":"PCI DSS","definition":"Payment Card Industry Digital Security Standard (PCI DSS). An information security standard administered by the Payment Card Industry Security Standards Council that is for organizations that handle branded credit cards from the major card schemes.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://csrc.nist.gov/glossary/term/payment_card_industry_data_security_standard"]},"__v":0},{"_id":"64e8aa0f32480a50b6e45143","term":"TAP","definition":"A network TAP (Test Access Point)is a simple device that connects directly to the cabling infrastructure. Instead of two switches or routers connecting directly to each other, the network TAP sits between the two devices and all data flows through the TAP. Using an internal splitter, the TAP creates a copy of the data for monitoring while the original data continues unimpeded through the network. \n\nIn Microsoft terms TAP, or Temporary Access Pass, is a time-limited or limited-use passcode that can be used by users for bootstrapping new accounts, account recovery, or when other auth methods are unavailable.","resources":{"roomCodes":["networkminer"],"videos":[],"articles":["https://www.gigamon.com/resources/resource-library/white-paper/to-tap-or-to-span.html"]},"__v":0},{"_id":"64e8d460cd7efb33de57bb20","term":"SQLi","definition":"SQL Injection (SQLi) is a type of cyber attack where malicious SQL (Structured Query Language) code is injected into a vulnerable application's input fields. This can manipulate the application's database queries, potentially granting unauthorised access to the database or allowing attackers to retrieve, modify, or delete data.","resources":{"roomCodes":["sqlinjectionlm","weaponizingvulnerabilities","webframeworkscodereview"],"videos":[],"articles":[]},"__v":0},{"_id":"61e69ccfac681d005cafd42f","resources":{"videos":[],"roomCodes":[],"articles":["https://www.calyptix.com/intrusion-detection-and-prevention-systems-ids-ips-overview/"]},"term":"NBA","definition":"Network Behaviours Analysis (NBA) sensors and programs examine network traffic to identify security threats that generate unusual traffic flows, such as distributed denial of service (DDoS) attacks, certain forms of malware and policy violations","__v":0},{"_id":"622fa403b98bd10048c44940","resources":{"videos":[],"roomCodes":[],"articles":["https://old.zeek.org/manual/2.5.5/logs/index.html"]},"term":"UID","definition":"As a connection is processed by Zeek/Bro, a unique identifier is assigned to each session. This unique identifier is generally included in any log file entry associated with that connection and can be used to cross-reference different log files","__v":0},{"_id":"62782e27609053005bad0dbe","resources":{"videos":[],"roomCodes":["introductiontodevsecops"],"articles":[]},"term":"X Fighter Dev","definition":"Part time space pilot, full time DevOps Engineer","__v":1},{"_id":"646fe53e42700e00523446ec","resources":{"roomCodes":[],"videos":[],"articles":["https://en.wikipedia.org/wiki/Dynamic_Host_Configuration_Protocol"]},"term":"DHCP","definition":"The Dynamic Host Configuration Protocol (DHCP) is a network management protocol used on Internet Protocol (IP) networks for automatically assigning IP addresses and other communication parameters to devices connected to the network using a client–server architecture.","__v":0},{"_id":"64e74681e7009dab48941121","term":"SHA-256","definition":"Secure Hash Algorithm 256 bits (SHA-256) is a cryptographic hash function that takes any input and produces a 256-bit hexadecimal number. SHA-256 is often used to verify the integrity of files or data and to create digital signatures. SHA-256 is considered very secure and is widely used in applications such as Bitcoin and blockchain technology.","resources":{"roomCodes":["cryptographyintro"],"videos":[],"articles":[]},"__v":0},{"_id":"64e747d262a00b02f5ce2e2a","term":"IDOR","definition":"Insecure direct object references (IDOR) are a type of access control vulnerability that arises when an application uses user-supplied input to access objects directly. The term IDOR was popularized by its appearance in the OWASP 2007 Top Ten.","resources":{"roomCodes":["idor","webframeworkscodereview"],"videos":[],"articles":[]},"__v":0},{"_id":"64e74af605f02e40399451e5","term":"War driving","definition":"War driving refers to the reconnaissance of neighbourhoods for Wi-Fi wireless networks, often by driving around in a vehicle equipped with a Wi-Fi-enabled device and mapping these networks.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e7562400e4a3ac7f72b62c","term":"Kerberos","definition":"Kerberos is a computer network authentication protocol that operates based on tickets, allowing nodes to securely prove their identity to one another over a non-secure network.\n\nIt primarily aims at a client-server model and provides mutual authentication, where the user and the server verify each other's identity.\n\nThe Kerberos protocol messages are protected against eavesdropping and replay attacks, and it builds on symmetric-key cryptography, requiring a trusted third party.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e7754de459c280dc8ae65d","term":"Packers","definition":"Tools that compress and encrypt executable files. It compresses the target executable and embeds it within a new executable file that serves as a wrapper or container. This dramatically reduces the size of the file, making it ideal for easy distribution and installation. ","resources":{"videos":[],"roomCodes":["antireverseengineering"],"articles":[]},"__v":0},{"_id":"64e77623e459c280dc8b06d4","term":"Ghidra","definition":"A software reverse engineering framework developed by the National Security Agency (NSA) in the United States. Comprising of a suite of software analysis tools. Ghidra disassembles executables into code that humans can understand.","resources":{"videos":[],"roomCodes":["antireverseengineering"],"articles":[]},"__v":0},{"_id":"64e7796a7f998be8348144e8","term":"API","definition":"API, which stands for Application Programming Interface, is a set of rules and protocols for building software and applications. An API allows different software programs to communicate with each other. It defines methods of communication between various components, including the kinds of requests that can be made, how they're made, the data formats that should be used, and conventions to follow.","resources":{"videos":[],"roomCodes":["owaspapisecuritytop105w"],"articles":[]},"__v":0},{"_id":"64e77a46a9c2de4135655faf","term":"THM","definition":"TryHackMe is an online cyber security training platform to help individuals and teams break into and up skill in cyber security. The site you are on right now.","resources":{"videos":[],"roomCodes":["tutorial"],"articles":[]},"__v":0},{"_id":"64e798798b4c23ab369296ed","term":"AMSI","definition":"The Antimalware Scan Interface, a Windows API that passes script content to the registered antivirus or EDR for inspection at runtime, in plaintext, after deobfuscation and before execution.","resources":{"roomCodes":["runtimedetectionevasion"],"videos":[],"articles":[]},"__v":0},{"_id":"64e8a71cbbfd0c738277cb9b","term":"NTA","definition":"Network traffic analysis (NTA) is a method of monitoring network availability and activity to identify anomalies, including security and operational issues","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://www.rapid7.com/fundamentals/network-traffic-analysis/"]},"__v":0},{"_id":"64e8ac2e738754697b07855c","term":"SSO","definition":"Single sign-on (SSO) is a session and user authentication service that permits a user to use one set of login credentials -- for example, a username and password -- to access multiple applications. SSO can be used by enterprises, small and midsize organizations, and individuals to ease the management of multiple credentials.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://www.techtarget.com/searchsecurity/definition/single-sign-on"]},"__v":0},{"_id":"64e8ace853cdb22f81a22bec","term":"OSINT","definition":"Open source intelligence (OSINT) is the act of gathering and analyzing publicly available data for intelligence purposes.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://www.crowdstrike.com/cybersecurity-101/osint-open-source-intelligence/"]},"__v":0},{"_id":"62750ec5b78789004b27e9f2","resources":{"roomCodes":["unifiedkillchain","securesdlc"],"videos":[],"articles":["https://docs.microsoft.com/en-us/windows-hardware/drivers/driversecurity/threat-modeling-for-drivers#the-dread-approach-to-threat-assessment"]},"term":"DREAD","definition":"A system used by microsoft to assess risk to computer security threats","__v":1},{"_id":"6408661e4ada700048d6e748","resources":{"roomCodes":["activedirectoryhardening"],"videos":[],"articles":[]},"term":"GPO","definition":"Group Policy Object (GPO) is a feature in Windows Server that allows administrators to control user and computer settings across the network. It provides a centralised way to manage and configure operating systems, applications, and user settings.","__v":0},{"_id":"64e71a326aa93cda3b59855f","term":"Zero Trust Architecture","definition":"A security model that treats every entity (user, device, application) as potentially untrusted and requires continuous verification before granting access.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e746e65ad38e626b74d8fc","term":"Firewall","definition":"A security tool, hardware or software that is used to filter network traffic by stopping unauthorized incoming and outgoing traffic.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e757a5616167350afb86bc","term":"NTP","definition":"NTP (Network Time Protocol) is a networking protocol designed to synchronize the clocks of computers over a network. It uses a designated reference time source, such as an atomic or GPS clock, to coordinate the system time for all networked devices. It ensures that all computers within the network have the same accurate time, which is crucial for various applications, including logging, security, and data integrity.","resources":{"videos":[],"roomCodes":["identificationandscoping"],"articles":[]},"__v":0},{"_id":"64e7743834f0d30560bf8d2a","term":"S3","definition":"Simple Storage Service (S3) is a service provided by Amazon Web Services (AWS) that allows you to store data in a scalable and reliable way. Data is stored on buckets, which act as a folder in the cloud where you can store files, applications, backup information or anything you need.","resources":{"videos":[],"roomCodes":[],"articles":["https://aws.amazon.com/s3/"]},"__v":0},{"_id":"64e778557f998be83480e196","term":"XSS","definition":"A type of security vulnerability typically found in web applications. It allows attackers to inject malicious scripts into web pages viewed by other users. These scripts can then steal sensitive information, like user's cookies, session tokens, or other sensitive data. ","resources":{"videos":[],"roomCodes":["xss"],"articles":[]},"__v":0},{"_id":"64e8ab1cc45114e09cb71a94","term":"Proxy","definition":"A proxy server is a system or router that provides a gateway between users and the internet. Therefore, it helps prevent cyber attackers from entering a private network. It is a server, referred to as an “intermediary” because it goes between end-users and the web pages they visit online.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://www.fortinet.com/resources/cyberglossary/proxy-server"]},"__v":0},{"_id":"620e5683a872f90054021593","resources":{"videos":[],"roomCodes":["redteamnetsec"],"articles":[]},"term":"DoS","definition":"Denial of Service (DoS) is an attack on the target's availability to make the target service/system unavailable to legitimate users.","__v":0},{"_id":"621d063245de7c00423d2b0a","resources":{"videos":[],"roomCodes":[],"articles":["https://www.gartner.com/en/information-technology/glossary/endpoint-protection-platform-epp"]},"term":"EPP","definition":"An endpoint protection platform (EPP) is a solution deployed on endpoint devices to prevent file-based malware attacks, detect malicious activity, and provide the investigation and remediation capabilities needed to respond to dynamic security incidents and alerts.","__v":0},{"_id":"6225504469a78e0043260a93","resources":{"videos":[],"roomCodes":["introtoc2"],"articles":[]},"term":"C2","definition":"Command and Control (C2) Infrastructure are a set of programs used to communicate with a victim machine. This is comparable to a reverse shell, but is generally more advanced and often communicate via common network protocols, like HTTP, HTTPS and DNS.","__v":0},{"_id":"623840851f64fa0043d9d077","resources":{"roomCodes":[],"videos":[],"articles":[]},"term":"MISP","definition":"Malware Information Sharing Platform is an open-source threat information platform used to facilitate the collection and sharing of threat information.","__v":1},{"_id":"623841545703cb00611645d8","resources":{"roomCodes":["intromalwareanalysis","intelcreationandcontainment"],"videos":[],"articles":[]},"term":"IOC","definition":"Indicator of Compromise is a forensic artifact observed on a network or in an operating system that, with high confidence, indicates a computer intrusion. ","__v":2},{"_id":"62782de84f52a700426e86d9","resources":{"videos":[],"roomCodes":["introductiontodevsecops"],"articles":[]},"term":"SEC3PO","definition":"A DevSecOps engineer / part Android","__v":0},{"_id":"62b0f3e92de864004c67b694","resources":{"videos":[],"roomCodes":["wiresharkthebasics",""],"articles":["https://en.wikipedia.org/wiki/Coordinated_Universal_Time"]},"term":"UTC","definition":"Coordinated Universal Time or UTC is the primary time standard by which the world regulates clocks and time","__v":0},{"_id":"62bc40621c52260054f4546a","resources":{"videos":[],"roomCodes":["securesdlc"],"articles":[]},"term":"SDL","definition":"Microsoft's SDL is a collection of mandatory security activities grouped by the traditional software development lifecycle phases.","__v":0},{"_id":"62bc40821c52260054f455af","resources":{"videos":[],"roomCodes":["securesdlc"],"articles":[]},"term":"SAMM","definition":"he Software Assurance Maturity Model (SAMM) is an open framework to help organisations formulate and implement a software security strategy tailored to the organisation's specific risks","__v":0},{"_id":"6365fc23fc0f4e005f94f921","resources":{"roomCodes":[],"videos":[],"articles":["https://github.com/MBCProject/mbc-markdown/blob/master/yfaq/README.md"]},"term":"MBC","definition":"The Malware Behavior Catalog (MBC) is a catalog of malware objectives and behaviors, created to support malware analysis-oriented use cases, such as labeling, similarity analysis, and standardized reporting.","__v":1},{"_id":"64009cf6df1a900969c06e9c","resources":{"videos":[],"roomCodes":["threatemulationintro"],"articles":[]},"term":"watering hole attack","definition":"An attack where a legitimate website frequently visited by a target is compromised and geared towards infecting visitors with malware.","__v":1},{"_id":"64e74f63fa6d938f7094610b","term":"RFC","definition":"A Request for Comments (RFC) is a publication in a series from the principal technical development and standards-setting bodies for the Internet, most prominently the Internet Engineering Task Force (IETF).","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"64e77b27de0a9972744cde1e","term":"Vulnerability Assessment","definition":"Scanning of a system or network for known vulnerabilities","resources":{"videos":[],"roomCodes":["securityengineerintro"],"articles":[]},"__v":0},{"_id":"64e77ff361e95584abaf3181","term":"XSRF","definition":"Cross-site request forgery (also known as CSRF) is a web security vulnerability that allows an attacker to induce users to perform actions that they do not intend to perform. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.","resources":{"videos":[],"roomCodes":[],"articles":["https://learn.microsoft.com/en-us/aspnet/core/security/anti-request-forgery?view=aspnetcore-7.0"]},"__v":0},{"_id":"64e8a80a43f28a4d1a76c24b","term":"IH","definition":"Incident Handling (IH). The mitigation of violations of security policies and recommended practices.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://csrc.nist.gov/glossary/term/incident_handling"]},"__v":0},{"_id":"64e8d5a700f4cb5e7789d5d8","term":"Command Injection","definition":"Command Injection is a vulnerability that occurs when an attacker manipulates input fields to inject malicious commands into a vulnerable application. This can lead to unauthorised execution of arbitrary commands on the targeted server, potentially resulting in data breaches, system compromise, or unintended operations.","resources":{"roomCodes":["oscommandinjection","webframeworkscodereview"],"videos":[],"articles":[]},"__v":0},{"_id":"618900b9ed54560042769341","resources":{"videos":[],"roomCodes":[],"articles":["https://en.wikipedia.org/wiki/Sender_Policy_Framework"]},"term":"SPF","definition":"Sender Policy Framework (SPF) is an email authentication method designed to detect forging sender addresses during the delivery of the email.","__v":0},{"_id":"62750a6b901d880052a12b45","resources":{"videos":[],"roomCodes":["unifiedkillchain"],"articles":["https://www.unifiedkillchain.com/"]},"term":"UKC","definition":"Unified Kill Chain","__v":0},{"_id":"62782eb24f52a700426e8eb9","resources":{"videos":[],"roomCodes":["introductiontodevsecops"],"articles":[]},"term":"S2D2","definition":"A robot working as a System Administrator","__v":2},{"_id":"62794096e98329004a1ef3a6","resources":{"videos":[],"roomCodes":["cyberkillchainzmt"],"articles":[]},"term":"IRC","definition":"Internet Relay Chat","__v":0},{"_id":"62bc3f775d6f9f0042f2bd63","resources":{"videos":[],"roomCodes":["securesdlc"],"articles":[]},"term":"SAST","definition":"Static Application Security Testing for scanning code","__v":0},{"_id":"63109121750f8a0060216223","resources":{"videos":[],"roomCodes":[],"articles":["https://en.wikipedia.org/wiki/RIPEMD"]},"term":"RIPEMD","definition":"RIPEMD (RIPE Message Digest) is a family of cryptographic hash functions developed in 1992 (the original RIPEMD) and 1996 (other variants). There are five functions in the family: RIPEMD, RIPEMD-128, RIPEMD-160, RIPEMD-256, and RIPEMD-320, of which RIPEMD-160 is the most common.","__v":0},{"_id":"6330769a1195740042526489","resources":{"roomCodes":["soar","jrsecanalystintrouxo","securityoperations"],"videos":[],"articles":[]},"term":"SOC","definition":"Security Operations Center (SOC) is a team of IT security professionals tasked with monitoring, preventing , detecting , investigating, and responding to threats within a company’s network and systems.","__v":0},{"_id":"633079b01449f300637cc3fe","resources":{"videos":[],"roomCodes":["sigma"],"articles":[]},"term":"JSON","definition":"JavaScript Object Notation is an open standard file and data interchange format that uses human-readable text to store and transmit data objects consisting of attribute–value pairs and arrays.","__v":0},{"_id":"6343d91613a524005fddc355","resources":{"videos":[],"roomCodes":["tshark"],"articles":["https://en.wikipedia.org/wiki/Internet_Assigned_Numbers_Authority"]},"term":"IANA","definition":"The Internet Assigned Numbers Authority (IANA) is a standards organization that oversees global IP address allocation, autonomous system number allocation, root zone management in the Domain Name System (DNS), media types, and other Internet Protocol-related symbols and Internet numbers","__v":0},{"_id":"64009c185eafc700607d32d1","resources":{"videos":[],"roomCodes":["threatemulationintro"],"articles":[]},"term":"spear-phishing","definition":"This involves sending of targeted emails to specific individuals or groups within an organisation, often with a malicious attachment or link.","__v":1},{"_id":"64e7432483a17b86aa14d9a6","term":"GRUB","definition":"GRUB stands for Grand Unified Bootloader. It is available from the GNU project and is a common bootloader shipped with many Linux distributions.","resources":{"videos":[],"roomCodes":["linuxfundamentalspart1"],"articles":[]},"__v":0},{"_id":"64e76ed36dfea0da31cab9ad","term":"EC2","definition":"Elastic Compute Cloud (EC2) is a service provided by Amazon Web Services (AWS) that allows you to rent virtual PCs on the cloud. The machines can be used just as any regular PC, and their specs can be dimensioned according to your specific needs.","resources":{"videos":[],"roomCodes":[],"articles":["https://aws.amazon.com/ec2/"]},"__v":0},{"_id":"64e8aaa8cbcb47d94c51472f","term":"SPAN","definition":"A SPAN port (sometimes called a mirror port) is a software feature built into a switch or router that creates a copy of selected packets passing through the device and sends them to a designated SPAN port. Using software, the administrator can easily configure or change what data is to be monitored. Since the primary purpose of a switch or router is to forward production packets, SPAN data is given a lower priority on the device. The SPAN also uses a single egress port to aggregate multiple links, so it is easily oversubscribed.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://www.gigamon.com/resources/resource-library/white-paper/to-tap-or-to-span.html"]},"__v":0},{"_id":"615d66b5076a4b004913cbc8","resources":{"roomCodes":["identificationandscoping"],"videos":[],"articles":[]},"term":"IDS","definition":"Intrusion Detection System (IDS) is a system that detects unauthorised network and system intrusions. Examples include detecting unauthorised devices connected to the local network and unauthorised users accessing a system or modifying a file.","__v":1},{"_id":"616442cfb5e5ff005488ec6f","resources":{"videos":[],"roomCodes":["passiverecon","activerecon"],"articles":[]},"term":"FTP","definition":"File Transfer Protocol (FTP) is a protocol designed to help the efficient transfer of files between different and even non-compatible systems. It supports two modes for file transfer: binary and ASCII (text).","__v":0},{"_id":"61e69e26a5caf40043f7c9a7","resources":{"videos":[],"roomCodes":[],"articles":["https://www.sciencedirect.com/topics/computer-science/network-intrusion-detection-system"]},"term":"NIPS","definition":"Network Intrusion Prevention System (NIPS) is a network security solution, although HIPS protects hosts. It monitors all network traffic for suspect activity and either allows or disallows the traffic to pass. For a NIPS to work properly, it needs to be positioned in-line on the network segment so that all traffic traverses through the NIPS. The implementation of a NIPS is similar to a NIDS with one exception: because a NIPS has two NICS, a network TAP, switch, or hub is not required.","__v":1},{"_id":"620117cb0290cf0050f38314","resources":{"videos":[],"roomCodes":["redteamfirewalls"],"articles":[]},"term":"MTU","definition":"Maximum Transmission Unit","__v":0},{"_id":"620e5690523586005f9769f6","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"DDoS","definition":"Distributed Denial of Service (DDoS) attacks the target's availability. It is \"distributed\" because it is launched from many sources, usually a botnet.","__v":0},{"_id":"62bc3fac5d6f9f0042f2bf86","resources":{"videos":[],"roomCodes":["securesdlc"],"articles":[]},"term":"SCA","definition":"Software Composition Analysis is an application security methodology in which development teams can quickly track and analyze any open source component","__v":0},{"_id":"636bcd07101447005fc6e29e","resources":{"videos":[],"roomCodes":["mitre","registrypersistencedetection"],"articles":["https://attack.mitre.org/"]},"term":"ATT&CK","definition":"The Adversarial Tactics, Techniques, and Common Knowledge or MITRE ATT&CK is a guideline for classifying and describing cyberattacks and intrusions. ","__v":0},{"_id":"640865513cf9130053f967f2","resources":{"roomCodes":["activedirectoryhardening"],"videos":[],"articles":[]},"term":"AD","definition":"Active Directory is a directory service developed by Microsoft for Windows domain networks. It stores information about network objects such as computers, users, and groups. It provides authentication and authorisation services, and allows administrators to manage network resources centrally.","__v":0},{"_id":"644a2466a34d4100626fafec","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"ICT","definition":"ICT stands for Information and Communication Technology and refers to the use of digital technologies to access, process, and communicate information.","__v":0},{"_id":"644a24b145406300579443ce","resources":{"roomCodes":[],"videos":[],"articles":[]},"term":"MFA","definition":"MFA stands for multi-factor authentication and is a security process that requires users to provide two or more forms of identification before accessing an account or system. This enhances security by adding an additional layer of protection against unauthorised access.","__v":0},{"_id":"64e719456faa74bf96dfa1cb","term":"Zeek","definition":"Zeek (formerly Bro) is the world's leading platform for network security monitoring. Flexible, open source, and powered by defenders. ","resources":{"videos":[],"roomCodes":["zeekbro","zeekbroexercises"],"articles":[]},"__v":0},{"_id":"64e74cd3e2e2b85fe60faade","term":"Wardialing","definition":"This is an action of using technology to automatically scan a range of phone numbers in order to reveal connected devices such as computers, modems, and office appliances.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64e778f87f998be834812118","term":"NOP","definition":"NOP, or No Operation, is an assembly language instruction that does nothing during the execution cycle of a program. It is commonly used for timing purposes, debugging, to occupy space that will be replaced with active instructions later, or to prevent certain processor optimizations. Despite doing nothing, NOP instructions still consume CPU cycles while being processed.","resources":{"videos":[],"roomCodes":["antireverseengineering"],"articles":[]},"__v":0},{"_id":"64e77b6dd1e839ab60862b4e","term":"VAPT","definition":"Vulnerability Assessment and Penetration Testing. Testing of a system or network for vulnerabilities, and trying to penetrate into a system or network.","resources":{"videos":[],"roomCodes":["securityengineerintro"],"articles":[]},"__v":0},{"_id":"64e8d52e00f4cb5e7789c689","term":"RFI","definition":"Remote File Inclusion (RFI) is a cyber attack where an attacker exploits a vulnerability in a web application to include malicious files from a remote server. By injecting URLs into input fields, attackers can execute arbitrary code on the target server, leading to potential system compromise or unauthorised access.","resources":{"roomCodes":["skynet"],"videos":[],"articles":[]},"__v":0},{"_id":"64e8e7e2092ea851706567c5","term":"LNK","definition":"Files with a .lnk file extension refers to \"link files\" or \"desktop shortcuts\". These files are often used to point to a file or folder from another location, making it convenient to access frequently used files and folders.  ","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"611235e5e09729005d3dc94a","resources":{"videos":[],"roomCodes":[],"articles":[]},"term":"MITM","definition":"A Man in the Middle attack involves an individual placing themselves in-between a communication process to intercept traffic","__v":0},{"_id":"615d54572cc0d70060f6501e","resources":{"videos":[],"roomCodes":["protocolsandservers","protocolsandservers2"],"articles":[]},"term":"MDA","definition":"Mail Delivery Agent. The MDA is responsible for delivering the email messages from a Mail Transport Agent (MTA) to the email client.","__v":0},{"_id":"616442892b6c25005f6595cc","resources":{"videos":[],"roomCodes":["passiverecon","activerecon"],"articles":[]},"term":"HTTP","definition":"Hypertext Transfer Protocol (HTTP) is the protocol that specifies how a web browser and a web server communicate. Your web browser requests content from the TryHackMe web server using the HTTP protocol as you go through this room.","__v":0},{"_id":"61e69d2194e8be0055b5e3c0","resources":{"videos":[],"roomCodes":[],"articles":["https://www.calyptix.com/intrusion-detection-and-prevention-systems-ids-ips-overview/"]},"term":"WIPS","definition":"Wireless Intrusion Prevention System (WIPS) analyze the radio spectrum throughout a wireless network to detect and report intrusion, network policy violations, and unauthorized use","__v":0},{"_id":"622ff8612ebb160049b9db71","resources":{"videos":[],"roomCodes":["intromalwareanalysis"],"articles":[]},"term":"entropy","definition":"The measure of randomness of data in a file is known as entropy. Entropy is very useful in identifying compressed and packed malware. Packed or compressed files usually have a high entropy.","__v":1},{"_id":"62c1bc6d99543f005510945e","resources":{"videos":[],"roomCodes":["cve202226134"],"articles":[]},"term":"URI","definition":"Uniform Resource Identifier","__v":0},{"_id":"6308d06488a9100051c1f4df","resources":{"videos":[],"roomCodes":["wiresharktrafficanalysis"],"articles":["https://en.wikipedia.org/wiki/NetBIOS"]},"term":"NETBIOS","definition":"NetBIOS is an acronym for Network Basic Input/Output System. It provides services related to the session layer of the OSI model allowing applications on separate computers to communicate over a local area network. ","__v":0},{"_id":"63308bfc91ca0e0049e46175","resources":{"videos":[],"roomCodes":["sigma"],"articles":["https://learn.microsoft.com/en-us/windows/win32/wmisdk/wmi-start-page"]},"term":"WMI","definition":"Windows Management Instrumentation (WMI) is the infrastructure for management data and operations on Windows-based operating systems. It is used to automate administrative tasks on remote computers and supply management data to other parts of the operating system and products.","__v":0},{"_id":"6373ae6da5e6630047e80622","resources":{"videos":[],"roomCodes":["aoc2022loganalysis"],"articles":[]},"term":"APT","definition":"An advanced persistent threat (APT) is a stealthy threat actor, typically a nation state or state-sponsored group, which gains unauthorized access to a computer network and remains undetected for an extended period.","__v":0},{"_id":"640865923cf9130053f96cde","resources":{"roomCodes":["activedirectoryhardening"],"videos":[],"articles":[]},"term":"DC","definition":"A domain controller is a server that manages security authentication requests in a Windows Server network. It stores user account information and controls access to resources on the network. It is a critical component for managing and securing a network infrastructure.","__v":0},{"_id":"646fe5d1cfbb9800441ed00f","resources":{"roomCodes":[],"videos":[],"articles":["https://en.wikipedia.org/wiki/Server_Message_Block"]},"term":"SMB","definition":"Server Message Block (SMB) is a communication protocol originally developed in 1983 by Barry A. Feigenbaum at IBM and intended to provide shared access to files and printers across nodes on a network of systems running IBM's OS/2. It also provides an authenticated inter-process communication (IPC) mechanism.","__v":0},{"_id":"64e749212f13d7289b2d06ff","term":"CSRF","definition":"Cross-site request forgery (also known as CSRF) is a web security vulnerability that allows an attacker to induce users to perform actions that they do not intend to perform. It allows an attacker to partly circumvent the same origin policy, which is designed to prevent different websites from interfering with each other.","resources":{"videos":[],"roomCodes":[],"articles":["https://portswigger.net/web-security/csrf"]},"__v":0},{"_id":"64e757f83a2ae4c8c7da382b","term":"Nmap","definition":"Nmap (Network Mapper) is a open-source tool used for network discovery and security auditing. It also assists in the exploration of network hosts and services, providing information about open ports, operating systems, and other details.","resources":{"videos":[],"roomCodes":["vulnversity"],"articles":[]},"__v":0},{"_id":"64e797e7a9c2de41356db26f","term":"SIGSEGV","definition":"This Linux signal occurs when a program attempts to access a memory position that is unavailable or lacks the necessary permissions.","resources":{"roomCodes":["cve202338408"],"videos":[],"articles":[]},"__v":0},{"_id":"64e7a06e9f4b7ac7acb8cc57","term":"VCS","definition":"A version control system (VCS) tracks changes to a file or set of files over time. Examples include GitHub, GitLab etc","resources":{"videos":[],"roomCodes":["securesdlc","introductiontodevsecops","sdlc"],"articles":[]},"__v":0},{"_id":"64e8acba53cdb22f81a21645","term":"SQL","definition":"Structured query language (SQL) is a programming language for storing and processing information in a relational database. A relational database stores information in tabular form, with rows and columns representing different data attributes and the various relationships between the data values. You can use SQL statements to store, update, remove, search, and retrieve information from the database. You can also use SQL to maintain and optimize database performance.","resources":{"videos":[],"roomCodes":["networkminer"],"articles":["https://aws.amazon.com/what-is/sql/"]},"__v":0},{"_id":"64ef0c0e71405fd17fe759f0","term":"Metasploit","definition":"Metasploit is an open-source penetration testing framework that helps security professionals find and exploit vulnerabilities in computer systems. It includes a database of known vulnerabilities and tools and scripts for exploiting them.","resources":{"videos":[],"roomCodes":["metasploitintro"],"articles":[]},"__v":0},{"_id":"64ef0c2e71405fd17fe75ab9","term":"Burp Suite","definition":"Burp Suite is an integrated platform for performing security testing of web applications. It includes various tools for scanning, fuzzing, intercepting, and analysing web traffic. It is used by security professionals worldwide to find and exploit vulnerabilities in web applications.","resources":{"videos":[],"roomCodes":["burpsuitebasics"],"articles":[]},"__v":0},{"_id":"64ef0c68a5b0d7af02c08399","term":"Hydra","definition":"Hydra is a free and open-source password-cracking tool. It can try numerous passwords till the correct password is found. It can be used to crack passwords for various network services, including SSH, Telnet, FTP, and HTTP.","resources":{"videos":[],"roomCodes":["hydra"],"articles":[]},"__v":0},{"_id":"64ef0ce3a5b0d7af02c094cd","term":"DirBuster","definition":"DirBuster is a free and open-source web application security scanner. It can be used to find hidden directories and files on web servers. It can use various techniques to brute-force directories and files, including dictionary attacks, brute-force attacks, and hybrid attacks.","resources":{"videos":[],"roomCodes":["toolsrus"],"articles":[]},"__v":0},{"_id":"64ef0d1671405fd17fe76f4b","term":"SQLMap","definition":"SQLMap is a free and open-source penetration testing tool that automates finding and exploiting SQL injection vulnerabilities on web applications. It can extract data from databases, execute commands on the underlying operating system, and even take control of the target server.","resources":{"videos":[],"roomCodes":["sqlmap"],"articles":[]},"__v":0},{"_id":"64ef0d3571405fd17fe7731e","term":"ZAP","definition":"Zed Attack Proxy (ZAP) is a free and open-source web application security scanner. It is a powerful tool that penetration testers and security professionals can use to test the security of web applications.\n\nZero-hour auto purge (ZAP) in Microsoft Defender for Office 365 retroactively detects and neutralises malicious phishing, spam, or malware messages that were delivered to cloud mailboxes. ","resources":{"roomCodes":["learnowaspzap"],"videos":[],"articles":[]},"__v":0},{"_id":"64ef0d6271405fd17fe77cd3","term":"Splunk","definition":"Splunk is a platform for collecting, storing, and analysing machine data. It provides various tools for analysing data, including search, correlation, and visualisation. It is a powerful tool that organisations of all sizes can use to improve their IT operations and security posture.","resources":{"videos":[],"roomCodes":["splunk101"],"articles":[]},"__v":0},{"_id":"64ef0d857b16ef43330dba72","term":"Elastic SIEM","definition":"Elastic SIEM is a security information and event management (SIEM) platform that helps organisations collect, analyse, and respond to security threats. It can collect data from various sources, including logs, events, network traffic, and cloud metadata. It can use machine learning to identify and prioritise threats. It can automate response actions, such as blocking malicious traffic or isolating infected hosts.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"64ef0da3a5b0d7af02c0aaa5","term":"Wazuh","definition":"Wazuh is a free and open-source security platform that provides threat detection, integrity monitoring, incident response, and compliance capabilities. Wazuh can collect data from various sources, including logs, events, network traffic, and cloud metadata. It can automate response actions, such as blocking malicious traffic or isolating infected hosts.","resources":{"videos":[],"roomCodes":["wazuhct"],"articles":[]},"__v":0},{"_id":"64ef0dc2a5b0d7af02c0adb9","term":"John the Ripper","definition":"John the Ripper is a free and open-source password-cracking tool. It can crack passwords stored in various formats, including hashes, passwords, and encrypted private keys. It can be used to test passwords' security and recover lost passwords.","resources":{"videos":[],"roomCodes":["johntheripper0"],"articles":[]},"__v":0},{"_id":"64ef0ea8a5b0d7af02c0c15f","term":"ELK","definition":"ELK stands for Elasticsearch, Logstash, and Kibana. These are three open-source tools that are commonly used together to collect, store, analyse, and visualise data.","resources":{"videos":[],"roomCodes":["investigatingwithelk101"],"articles":[]},"__v":0},{"_id":"64ef0eb77b16ef43330dcd50","term":"Elasticsearch","definition":"Elasticsearch is a distributed, scalable, and highly available search engine. It is used to store and index data so that it can be quickly searched and analysed.","resources":{"videos":[],"roomCodes":["investigatingwithelk101"],"articles":[]},"__v":0},{"_id":"64ef0ec48b99edee95dd91af","term":"Logstash","definition":"Logstash is a tool for collecting and processing data from a variety of sources. It can be used to collect logs from applications, servers, and other systems. It can also be used to parse and transform data before it is stored in Elasticsearch.","resources":{"videos":[],"roomCodes":["investigatingwithelk101"],"articles":[]},"__v":0},{"_id":"64ef0edca5b0d7af02c0cdef","term":"Kibana","definition":"Kibana is a web-based visualisation tool for exploring data stored in Elasticsearch. It can be used to create interactive dashboards and charts that help users to understand data.","resources":{"videos":[],"roomCodes":["investigatingwithelk101"],"articles":[]},"__v":0},{"_id":"651b3573bedf53bd16563656","term":"NTPD","definition":"The ntpd program is an operating-system daemon that sets and maintains a computer system's system time in synchronization with Internet-standard time servers. It is a complete implementation of the Network Time Protocol (NTP) version 4, but retains compatibility with versions 1, 2, and 3 as defined by RFC 1059, RFC 1119, and RFC 1305, respectively. ","resources":{"videos":[],"roomCodes":["loguniverse"],"articles":["https://en.wikipedia.org/wiki/Ntpd"]},"__v":0},{"_id":"651b362e148e334139239d35","term":"SSHD","definition":"sshd (OpenSSH Daemon) is the daemon program for ssh(1). Together these programs replace rlogin(1) and rsh(1), and provide secure encrypted communications between two untrusted hosts over an insecure network.","resources":{"videos":[],"roomCodes":["loguniverse"],"articles":["https://linux.die.net/man/8/sshd"]},"__v":0},{"_id":"651b3669cc836adac88bf1a3","term":"CPU","definition":"A central processing unit (CPU)—also called a central processor or main processor—is the most important processor in a given computer. Its electronic circuitry executes instructions of a computer program, such as arithmetic, logic, controlling, and input/output (I/O) operations. This role contrasts with that of external components, such as main memory and I/O circuitry,[1] and specialized coprocessors such as graphics processing units (GPUs).","resources":{"roomCodes":["loguniverse","mbrgptanalysis"],"videos":[],"articles":["https://en.wikipedia.org/wiki/Central_processing_unit"]},"__v":0},{"_id":"651b3691cc836adac88bf73a","term":"RAM","definition":"Random-access memory (RAM; /ræm/) is a form of electronic computer memory that can be read and changed in any order, typically used to store working data and machine code.","resources":{"videos":[],"roomCodes":["loguniverse"],"articles":["https://en.wikipedia.org/wiki/Random-access_memory"]},"__v":0},{"_id":"6526e2c3ab6db669670d2f69","term":"CTO","definition":"Chief Technology Officer is the person that is responsible for an organisations technology. Working together with the CIO, they run a company's IT infrastructure.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"6526e2e1ceca3724cb0f9f61","term":"ML","definition":"Machine Learning is the term used to describe algorithms and functions used to get computers to think and act the way humans and nature do.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"653b633f1a9cff08ab339684","term":"CNN","definition":"Convolutional Neural Networks (CNNs) are incredible ML structures that have the ability to extract features that can be used to train a neural network. In essence, CNNs are normal neural networks that simply have the feature-extraction process as part of the network itself.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"655dc93e635190762891ae88","term":"IPFIX","definition":"Internet Protocol Flow Information Export (IPFIX) is an IETF protocol, as well as the name of the IETF working group defining the protocol. It was created based on the need for a common, universal standard of export for Internet Protocol flow information from routers, probes and other devices that are used by mediation systems, accounting/billing systems and network management systems to facilitate services such as measurement, accounting and billing. The IPFIX standard defines how IP flow information is to be formatted and transferred from an exporter to a collector.","resources":{"videos":[],"roomCodes":[],"articles":["https://en.wikipedia.org/wiki/IP_Flow_Information_Export"]},"__v":0},{"_id":"655dc9a1635190762891b537","term":"NetFlow","definition":"NetFlow, a network protocol developed for Cisco routers by Cisco Systems, is widely used to collect metadata about the IP traffic flowing across network devices such as routers, switches and hosts. The traffic flow data informs a company’s IT professionals as to how much traffic there is, where it’s coming from and going to, and the paths being used.","resources":{"roomCodes":[],"videos":[],"articles":["https://www.ibm.com/topics/netflow"]},"__v":0},{"_id":"6571ff9105b4e3bd7ffac2d4","term":"DevSecOps","definition":"Fosters the same culture and principles as Devops with the addition of security into the development process, ensuring security is integrated from an early stage.","resources":{"videos":[],"roomCodes":["securesdlc","introductiontodevsecops","sdlc"],"articles":[]},"__v":0},{"_id":"65933194f1fdf5612cca152a","term":"IPC","definition":"Inter-process Communication is the definition of the mechaism that allows processes to communicate and share data between each other","resources":{"roomCodes":["containervulnerabilitiesDG"],"videos":[],"articles":["https://www.ibm.com/support/pages/interprocess-communication-ipc-overview"]},"__v":0},{"_id":"659336cc8b45b710947985a1","term":"CLI","definition":"The command-line interface, or CLI, allows users to interact with a computer by typing text-based commands. Rather than clicking icons or menus, users enter commands using a keyboard to perform tasks. CLIs are commonly used for their speed, flexibility, and control.","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"65a66de43d68c467c2945719","term":"Kubernetes","definition":"Kubernetes is a container orchestration system used for automating deployment, scaling and management of applications.","resources":{"videos":[],"roomCodes":["introtokubernetes"],"articles":[]},"__v":0},{"_id":"65a67057e9688d4cc2d03a29","term":"Container","definition":"Containers are packages of software that bundles up code, and all its dependencies so it can be run reliably in any environment.","resources":{"videos":[],"roomCodes":["virtualizationandcontainers","introtocontainerisation","containervulnerabilitiesDG"],"articles":[]},"__v":0},{"_id":"65a671145dd81f8dc5e28870","term":"Microservice","definition":"A microservice architecture refers to the software being broken up into smaller independent services which communicate using APIs.","resources":{"videos":[],"roomCodes":["introtokubernetes"],"articles":[]},"__v":0},{"_id":"65a98b2f7b3babd902d71ba2","term":"ESI","definition":"Electronically Stored Information (ESI) is a broad concept that includes public or private information stored in an electronic or digital medium, such as data available from computers (including email), CD-ROM discs, DVDs, Internet, cloud storage, personal digital assistants (PDAs), smart phones, tablets, GPS systems, satellites, and drones. ESI includes writings, drawings, graphs, charts, photographs, sound recordings, images, video recordings, data compilations, computer-aided design files such as blueprints or maps, metadata, equipment/process control and data logging system files, and any other data that is stored electronically.","resources":{"videos":[],"roomCodes":["exploringwinincidentsurface"],"articles":["https://www.nist.gov/glossary-term/4786"]},"__v":0},{"_id":"65b225051d3904fb16fb2ea7","term":"Windows PowerShell ISE","definition":"The Windows PowerShell Integrated Scripting Environment (ISE) is a host application for Windows PowerShell. In the ISE, you can run commands and write, test, and debug scripts in a single Windows-based graphic user interface. The ISE provides multiline editing, tab completion, syntax coloring, selective execution, context-sensitive help, and support for right-to-left languages. Menu items and keyboard shortcuts are mapped to many of the same tasks that you would do in the Windows PowerShell console. For example, when you debug a script in the ISE, you can right-click on a line of code in the edit pane to set a breakpoint.","resources":{"videos":[],"roomCodes":["exploringwindowsincidentsurface"],"articles":["https://learn.microsoft.com/en-us/powershell/scripting/windows-powershell/ise/introducing-the-windows-powershell-ise?view=powershell-7.4"]},"__v":0},{"_id":"65b8f0bcddeafae4e0b1722e","term":"POI","definition":"Person of Interest: a person being monitored, sought, or questioned concerning a criminal investigation or security operation, especially as a potential suspect.","resources":{"videos":[],"roomCodes":["dfirprocesslegalconsiderations"],"articles":[]},"__v":0},{"_id":"65bf1965d4c61ba4f4036e01","term":"CORS","definition":"Cross-origin resource sharing (CORS) is a mechanism for integrating applications. CORS defines a way for client web applications that are loaded in one domain to interact with resources in a different domain.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"65bf197f4ec817918cba437f","term":"SOP","definition":"Same-origin policy is a critical security mechanism that restricts how a document or script loaded by one origin can interact with a resource from another origin. It helps isolate potentially malicious documents, reducing possible attack vectors.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"65bf19a54ec817918cba5be7","term":"ACAO","definition":"The Access-Control-Allow-Origin header is included in the response from one website to a request originating from another website, and identifies the permitted origin of the request. A web browser compares the Access-Control-Allow-Origin with the requesting website's origin and permits access to the response if they match.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"65c0cb094ec817918c229e1e","term":"SaaS","definition":"Software as a Service (SaaS) is a method of providing software to users. This software/application will run in the cloud and users will pay to use it via subscription (as a service) rather than buying it.","resources":{"videos":[],"roomCodes":["devsecops","cloudbasediac"],"articles":[]},"__v":0},{"_id":"65c241018f16f162d1aa3a75","term":"CSP","definition":"A Cloud Service Provider is a company which offers scalable cloud computing resources on demand. The cloud resources CSPs offer include computing power, data storage and applications.","resources":{"roomCodes":["introtoiac","cloudbasediac"],"videos":[],"articles":[]},"__v":0},{"_id":"65c6870667cff63d2de16ce3","term":"Meterpreter","definition":"Meterpreter is a Metasploit attack payload that provides an interactive shell from which an attacker can explore the target machine and execute code. It is typically deployed using in-memory DLL injection to reside entirely in memory.","resources":{"videos":[],"roomCodes":["linuxfilesystemanalysis"],"articles":[]},"__v":0},{"_id":"65ce376cd192aea8dbb6c5f1","term":"PSS","definition":"Pod Security Standards (used in Kubernetes) define 3 different policies that broadly cover the security spectrum: privileged, baseline and restricted.","resources":{"videos":[],"roomCodes":["introtokubernetes"],"articles":[]},"__v":0},{"_id":"65ce37b1395b58334b9f0016","term":"PSA","definition":"Pod Security Admission (used in Kubernetes) enforces Pod Security Standards (PSS).","resources":{"videos":[],"roomCodes":["introtokubernetes"],"articles":[]},"__v":0},{"_id":"6620f693e780b373347a407b","term":"AKS","definition":"Azure Kubernetes Service (AKS) is a managed Kubernetes service from the Azure Cloud Service Provider. ","resources":{"videos":[],"roomCodes":["clusterhardening"],"articles":[]},"__v":0},{"_id":"6620f6cce780b373347a49cb","term":"EKS","definition":"Elastic Kubernetes Service (AKS) is a managed Kubernetes service from the Amazon Web Services Cloud Service Provider. ","resources":{"videos":[],"roomCodes":["clusterhardening"],"articles":[]},"__v":0},{"_id":"6620f770255dc5ba2986d57e","term":"CIS","definition":"CIS (Centre for Internet Security) is a non-profit organisation that helps collect and define standards that can be implemented as preventative measures against cyber attacks","resources":{"videos":[],"roomCodes":["clusterhardening"],"articles":[]},"__v":0},{"_id":"6620f83852b4c186d81d3251","term":"STIG","definition":"Security Technical Information Guidelines (STIG) is a configuration standard consisting of cybersecurity requirements for a specific product (e.g. Kubernetes) provided by DISA (US Department of Defence Systems Agency). ","resources":{"videos":[],"roomCodes":["clusterhardening"],"articles":[]},"__v":0},{"_id":"6620f89af4adb0015b50fb63","term":"Cluster Hardening","definition":"The process of securing a Kubernetes cluster following best security practices.","resources":{"videos":[],"roomCodes":["clusterhardening"],"articles":[]},"__v":0},{"_id":"66506814c0e0c3b0bfebd489","term":"REST","definition":"REST (representational state transfer) is a software architectural style that was created to guide the design and development of the architecture for the World Wide Web. REST defines a set of constraints for how the architecture of a distributed, Internet-scale hypermedia system, such as the Web, should behave. The REST architectural style emphasises uniform interfaces, independent deployment of components, the scalability of interactions between them, and creating a layered architecture to promote caching to reduce user-perceived latency, enforce security, and encapsulate legacy systems.","resources":{"videos":[],"roomCodes":["xxeinjection"],"articles":[]},"__v":0},{"_id":"6650682b2d9352be2597ac30","term":"SOAP","definition":"SOAP (formerly an acronym for Simple Object Access Protocol) is a messaging protocol specification for exchanging structured information in the implementation of web services in computer networks. It uses XML Information Set for its message format, and relies on application layer protocols, most often Hypertext Transfer Protocol (HTTP), although some legacy systems communicate over Simple Mail Transfer Protocol (SMTP), for message negotiation and transmission.","resources":{"videos":[],"roomCodes":["xxeinjection"],"articles":[]},"__v":0},{"_id":"6659a9ea1e321452229ead49","term":"RBAC","definition":"RBAC refers to access to resources being restricted on a role basis in an organisation. Can be used in (but not limited to) Kubernetes to restrict access to cluster resources.","resources":{"roomCodes":["introtokubernetes","k8sbestsecuritypractices","k8sruntimesecurity"],"videos":[],"articles":[]},"__v":0},{"_id":"66703590618dc3d7a4e53c63","term":"KQL","definition":"KQL can refer to Kusto Query Language in the context of Azure, and Kibana Query Language in the context of Elastic. Both are query languages used to explore and process data based on search terms and filters.","resources":{"roomCodes":["investigatingwithelk101"],"videos":[],"articles":["https://learn.microsoft.com/en-us/azure/data-explorer/kusto/query/#what-is-a-kusto-query","https://www.elastic.co/guide/en/kibana/current/kuery-query.html"]},"__v":0},{"_id":"667960769fad126767dced82","term":"ORM","definition":"Object-Relational Mapping (ORM) is a programming technique that allows developers to interact with a database using an object-oriented paradigm","resources":{"roomCodes":["orminjection"],"videos":[],"articles":[]},"__v":0},{"_id":"667c117742d10411f352fca3","term":"HQL","definition":"Hibernate Query Language (HQL) is a powerful, object-oriented query language similar to SQL but designed specifically for Hibernate ORM framework. HQL abstracts the database-specific SQL and allows developers to write queries using the entity objects defined in the Hibernate mappings, rather than directly interacting with the database tables.","resources":{"roomCodes":["orminjection"],"videos":[],"articles":[]},"__v":0},{"_id":"6687c95e7d36893eff0df502","term":"Service Mesh","definition":"A Service Mesh is a dedicated infrastructure layer used to control and manage service-to-service communication in a Microservices Architecture.","resources":{"videos":[],"roomCodes":["microservicearchitectures"],"articles":[]},"__v":0},{"_id":"6687c9a37d36893eff0e00da","term":"Sidecar","definition":"A process or service which runs in parallel (and supports) a primary application.","resources":{"videos":[],"roomCodes":["microservicearchitectures"],"articles":[]},"__v":0},{"_id":"66a253e0feda811d027890a0","term":"EXIF","definition":"Images store metadata (date and time, camera settings, GPS coordinates, etc.) within them.  This metadata of image files is stored in a standardized format known as Exchangeable Image File Format (EXIF). ","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"66a9cabad4db39e7ba5d2e78","term":"PKCE","definition":"PKCE (Proof Key for Code Exchange) is an extension to the OAuth 2.0 authorization framework. It is designed to provide an additional layer of security for public clients, such as mobile and JavaScript-based applications, which are unable to securely store client secrets. PKCE is particularly useful in mitigating authorization code interception attacks.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"672a4464175be288481a7ed7","term":"IAM","definition":"Identity and Access Management (IAM) is a framework/process for controlling and securing digital identities and user access in organisations.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"672b3694a03a270c612e924e","term":"DAIR","definition":"Dynamic Approach to Incident Response is a framework used to handle the Incident Response process. It is mapped on the NIST Incident Response Lifecycle","resources":{"roomCodes":["threathuntingwithyara"],"videos":[],"articles":[]},"__v":0},{"_id":"677a92a84ef15c60c3bf19c0","term":"RSA","definition":"RSA is a method for encrypting data using two keys: one to lock (encrypt) and another to unlock (decrypt) it, relying on the difficulty of factoring large number.","resources":{"roomCodes":["insecurerandomness"],"videos":[],"articles":[]},"__v":0},{"_id":"677a92da3c7a86f71ee313e7","term":"ECC","definition":"ECC is a way to encrypt data using smaller keys while still providing strong security. It is based on the math of elliptic curves.","resources":{"roomCodes":["insecurerandomness"],"videos":[],"articles":[]},"__v":0},{"_id":"677e2e6e69841930f92f82cc","term":"AES-GCM","definition":"AES-GCM (Advanced Encryption Standard - Galois/Counter Mode) is an authenticated encryption algorithm that combines the AES encryption with the GCM mode of operation. It provides both confidentiality (encryption) and integrity (authentication) by generating an authentication tag to verify the authenticity of the encrypted data","resources":{"videos":[],"roomCodes":["paddingoracles"],"articles":[]},"__v":0},{"_id":"677e2edb0100dac9910650ca","term":"AES-CCM","definition":"AES-CCM (Advanced Encryption Standard - Counter with CBC-MAC) is an authenticated encryption mode that combines AES encryption with the Counter (CTR) mode for confidentiality and the CBC-MAC (Cipher Block Chaining Message Authentication Code) for integrity. It ensures both data encryption and authentication, protecting against tampering and providing data authenticity.","resources":{"videos":[],"roomCodes":["paddingoracles"],"articles":[]},"__v":0},{"_id":"67aa51c328a2f43d40b30ed9","term":"IdP","definition":"An Identity Provider (IdP) is a system that authenticates users’ identities and authorizes their access to various applications and services by managing and verifying digital credentials.","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"67acc7d90041cb4379d50711","term":"EXT","definition":"The EXT file system (Extended File System) is a family of journaling file systems used in Linux, designed for efficient data storage and retrieval. It includes multiple versions—EXT, EXT2, EXT3, and EXT4—each improving performance, reliability, and features like journaling and extended attributes.","resources":{"roomCodes":["extanalysis"],"videos":[],"articles":[]},"__v":0},{"_id":"67ad17fd46c48986c9b88c9f","term":"PIM","definition":"Privileged Identity Management (PIM): This is a service in Microsoft Entra ID that helps organizations manage, control, and monitor access to important resources","resources":{"roomCodes":[],"videos":[],"articles":["https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure"]},"__v":0},{"_id":"67c4db4cd77ee51f629b74ff","term":"MTLS","definition":"It's a version of the TLS security protocol that authenticates both the client and the server in a network connection. The \"m\" stands for Mutual TLS.","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"67c4dbb02b7c8f2461e323b2","term":"CA","definition":"A CA, or Certificate Authority, is a trusted organisation that verifies the digital identity of entities like websites, individuals, or companies by issuing digital certificates.","resources":{"roomCodes":["publickeyinfrastructure"],"videos":[],"articles":[]},"__v":0},{"_id":"67c8e79740206e899c77a570","term":"TOTP","definition":"Time-based one-time password (TOTP) is an open standard that specifies how one-time password (OTP) codes are generated.","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"67ed33a8a0d8245f2e9289a5","term":"ITSM","definition":"IT Service Management (ITSM) tools help track and automate incidents and change management processes. SOC teams can use ITSM tools like Jira or ServiceNow to manage security incidents or engineering projects.","resources":{"roomCodes":["socl1alerttriage"],"videos":[],"articles":[]},"__v":0},{"_id":"6818ebadc9ac3f3cecf3777b","term":"JAR","definition":"A JAR (Java ARchive) file is a compressed package that bundles Java classes, metadata, and resources into a single file for distribution and execution.","resources":{"videos":[],"roomCodes":["customtoolingviaburp"],"articles":[]},"__v":0},{"_id":"681b93a7fc981b4af1343b1b","term":"SLA","definition":"Service Level Agreement (SLA) is a document signed between a service provider (e.g. SOC team) and its customer defining the uptime and quality requirements.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"681b93b6ea097b363a499a1a","term":"MTTD","definition":"Mean Time to Detect (MTTD) is the average time it takes for an organization to identify a security threat, incident, or a technical problem.","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"681b93cb1469d4e9782e7dc5","term":"MTTA","definition":"Mean Time to Acknowledge (MTTA) is the average time between the initial alert and the service provider (e.g. SOC L1 analysts) taking action.","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"681b93de75be7ebc46addd7a","term":"MTTR","definition":"Mean Time to Response (MTTR) is the average time between the initial alert and response to it (e.g. malware removal, password reset, or system restore).","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"6841870f6123cb34479f0e14","term":"File system","definition":"The on-disk data structures and logic an OS uses to organise, name, store and retrieve files (e.g. FAT32, NTFS, ext4).","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"6842c5a0eae6995ed219ff06","term":"Boot Sector","definition":"First sector of a disk partition that contains the BIOS Parameter Block, bootstrap code, and volume metadata.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"6842c5ca27303ee9b24e91aa","term":"Imaging","definition":"The process of creating an exact, bit-by-bit copy of digital storage media.","resources":{"videos":[],"roomCodes":["forensicimaging"],"articles":[]},"__v":0},{"_id":"6842c66abdbd7c9d4e341934","term":"LNK File","definition":"This is a shortcut reference file to an actual file or application found on a Windows system.","resources":{"videos":[],"roomCodes":["windowsapplications","windowsuseractivity","expregistryforensics"],"articles":[]},"__v":0},{"_id":"6842c6b9da0b11a44d212ef2","term":"File Carving","definition":"The process of reconstructing files directly from raw data using the file headers/footers.","resources":{"videos":[],"roomCodes":["filecarving"],"articles":[]},"__v":0},{"_id":"6842ceb89489d63c8247a377","term":"System profiling","definition":"The process of analysing an operating system through identifying its behaviour using configuration information, application data, hardware performance and user data.","resources":{"videos":[],"roomCodes":["linuxliveanalysis"],"articles":[]},"__v":0},{"_id":"6842cf537f447c6a4e9ae475","term":"Cronjob","definition":"A scheduled task defined on a Linux system to execute automatically based on predefined parameters such as time intervals or user actions.","resources":{"videos":[],"roomCodes":["linuxprocessanalysis"],"articles":[]},"__v":0},{"_id":"6842d4468df14c7832f744b1","term":"Chain of custody","definition":"Process of documenting the complete journey of evidence during a legal case lifetime, from the collection to final presentation in court.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"6842d556fdea5c5ae759df4f","term":"Honeypot","definition":"A system designed to lure adversaries, monitor their activities and provide alerts to the security team for analysis.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"6842d65d8a118c4c6edaddb0","term":"Sandbox","definition":"Hardware or software dedicated for isolating untrusted applications or services from critical system resources and other programs to prevent harmful actions or malware from negatively affecting the system.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"6842d6b73d65f984be01f3d9","term":"Slack space","definition":"The leftover storage on a disk when a file does not need all the space it has been allocated.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"6842e646e21953034afb50d0","term":"File header","definition":"A unique sequence of binary at the start of a file identifying its format","resources":{"videos":[],"roomCodes":["filecarving"],"articles":[]},"__v":0},{"_id":"685e91cb0eabefb73b99d5a9","term":"FGSM","definition":"Fast Gradient Sign Method is a white-box adversarial attack that perturbs data classification in AI models.","resources":{"videos":[],"roomCodes":["defendingaiattacks"],"articles":[]},"__v":0},{"_id":"68651fb200616f1bc8039925","term":"AI","definition":"Artificial Intelligence is technology that enables computers and machines to simulate human behaviour, like learning and reasoning.","resources":{"videos":[],"roomCodes":["defadversarialattacks"],"articles":[]},"__v":0},{"_id":"686679e60eaf917c8e1bfcbb","term":"PGD","definition":"Projected Gradient Descent is an adversarial attack used to cause a machine learning model to make incorrect predictions.","resources":{"videos":[],"roomCodes":["defadversarialattacks"],"articles":[]},"__v":0},{"_id":"68ef5a1b2b75b1ecb302062e","term":"TLS","definition":"Transport Layer Security is a cryptographic protocol that secures communications over a network. It provides authentication through the use of certificates, integrity by detecting tampering and confidentiality by encrypting the data.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"690cd0d68cf809f5b000b8ed","term":"Artificial intelligence","definition":"A field of computer science focused on creating systems that can perform tasks that usually need human thinking, such as learning, reasoning, and problem-solving.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"690cd1975d61f6c2dc781b01","term":"CoT","definition":"CoT (Chain of Thought) is a  method in artificial intelligence where a model explains its reasoning step by step to conclude, helping improve accuracy and clarity in problem-solving .","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"692594d698dc18159c56780e","term":"PLC","definition":"A programmable logic controller (PLC) or programmable controller is an industrial computer that has been ruggedized and adapted for the control of manufacturing processes, such as assembly lines, machines, robotic devices, or any activity that requires high reliability, ease of programming, and process fault diagnosis.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"692fe3ce951445ac6268ce86","term":"CloudTrail","definition":"AWS CloudTrail is a service that enables auditing, security monitoring, and operational troubleshooting by recording API calls and user activity in your AWS account.","resources":{"videos":[],"roomCodes":["awsdefenseanirstory"],"articles":[]},"__v":0},{"_id":"692fe49ea766d8906575f5e9","term":"FlowLogs","definition":"AWS Flow Logs is a service that captures information about IP traffic flowing to and from network interfaces in your AWS environment, such as within a Virtual Private Cloud (VPC) or a Transit Gateway","resources":{"videos":[],"roomCodes":["awsdefenseanirstory"],"articles":[]},"__v":0},{"_id":"692fe4c274ec2224b7e95fc1","term":"GuardDuty","definition":"AWS GuardDuty is an intelligent threat detection service that continuously monitors your AWS accounts and workloads for malicious activity.","resources":{"videos":[],"roomCodes":["awsdefenseanirstory"],"articles":[]},"__v":0},{"_id":"692fe4e5f682b0925abb8d4d","term":"CloudWatch","definition":"AWS CloudWatch is a monitoring service that collects and tracks metrics, collects and monitors log files, and sets alarms for AWS resources and applications.","resources":{"videos":[],"roomCodes":["awsdefenseanirstory"],"articles":[]},"__v":0},{"_id":"692fe5229a556846becdd44e","term":"IGW","definition":"Internet Gateway, a component in cloud computing that acts as a bridge between a virtual private cloud (VPC) and the public internet. ","resources":{"videos":[],"roomCodes":["awsdefenseanirstory"],"articles":[]},"__v":0},{"_id":"692fe54a4a8b1cd9ac93b549","term":"Lambda","definition":"AWS Lambda is a compute service that runs code without the need to manage servers.","resources":{"videos":[],"roomCodes":["awsdefenseanirstory"],"articles":[]},"__v":0},{"_id":"692fe579c7ed0a6cbce84f57","term":"AMI","definition":"An AWS Amazon Machine Image (AMI) is a template used to launch virtual servers, called EC2 instances, in Amazon Web Services. ","resources":{"videos":[],"roomCodes":["awsdefenseanirstory"],"articles":[]},"__v":0},{"_id":"692fe5e427a4d546f29f7566","term":"NACL","definition":"Network Access Control List  is a security feature that acts as a stateless firewall for controlling traffic in and out of a network's subnets.","resources":{"videos":[],"roomCodes":["awsdefenseanirstory"],"articles":[]},"__v":0},{"_id":"6943d55853eb522068864e53","term":"CloudFront","definition":"Amazon CloudFront is a global Content Delivery Network (CDN) service by AWS that speeds up website/app content delivery (images, videos, APIs) to users by caching it at \"edge locations\" worldwide, serving it from the nearest server for lower latency, higher speeds, and better security, protecting against attacks like DDoS.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"698e80f787966ec12ee2bb60","term":"Test Term 123","definition":"This is a test definition for the term.\n","resources":{"videos":[],"roomCodes":["testroom1","testroom2"],"articles":[]},"__v":0},{"_id":"699a3c77806c4458581b2728","term":"LDAP","definition":"Lightweight Directory Access Protocol (LDAP) is an open protocol used to access and manage directory services like Active Directory. Applications use LDAP to authenticate users by verifying their credentials directly against a domain controller.","resources":{"roomCodes":["detectingadinitialaccess"],"videos":[],"articles":[]},"__v":0},{"_id":"699a3cab46410ee72174e867","term":"ADFS","definition":"Active Directory Federation Services (ADFS) is a Microsoft service that provides single sign-on (SSO) authentication across organizational boundaries. It uses claims-based authentication to allow users to access external applications using their AD credentials without exposing passwords to third-party systems.","resources":{"roomCodes":["detectingadinitialaccess"],"videos":[],"articles":[]},"__v":0},{"_id":"69a7de359e1a52c3dc50a86c","term":"SNS","definition":"Amazon Simple Notification Service is a fully managed, high-throughput pub/sub messaging service.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"69a7de58d030bbe10be1aa80","term":"EventBridge","definition":"Amazon EventBridge is a serverless, event-driven service that enables you to connect applications using data from your own systems, SaaS applications, and AWS services.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"69aeb8ce4740d23198760325","term":"IIS","definition":"Internet Information Services (IIS) is Microsoft's web server platform built into Windows Server. It hosts websites, web applications, and services such as Exchange OWA, SharePoint, and ADFS. IIS logs HTTP requests in W3C format, recording client IPs, requested URIs, status codes, and user agents.","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"69aeb8d98ca4586e991f6df2","term":"OWA","definition":"Outlook Web Access (OWA) is the browser-based email interface for Microsoft Exchange Server. It allows users to access their mailbox, calendar, and contacts through a web browser without needing a desktop email client. OWA runs on IIS and authenticates users against Active Directory.","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"69aeb8d94e29c7a037776fa1","term":"NPS","definition":"Network Policy Server (NPS) is Microsoft's implementation of a RADIUS server in Windows Server. It centralizes authentication, authorization, and accounting for network access, acting as an intermediary between network access devices (such as VPN gateways, wireless access points, and switches) and Active Directory.","resources":{"roomCodes":[],"videos":[],"articles":[]},"__v":0},{"_id":"69b3fedebdf813e548f1a75b","term":"ES|QL","definition":"Elasticsearch Query Language (ES|QL) is a piped query language used in the Elastic Stack to search and analyse data stored in Elasticsearch. It allows analysts to filter, transform, and aggregate data using a single streamlined syntax.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"69b3ff2e05f1575db0f35121","term":"ECS","definition":"The Elastic Common Schema (ECS) is an open-source standard that defines consistent field names for data in Elasticsearch. It normalises logs from different sources so analysts can correlate events without rewriting queries.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"69b3ff5a89c75216300b52ab","term":"EQL","definition":"Event Query Language (EQL) is a query language developed by Elastic for analysing event-based data. It allows analysts to identify relationships between events and detect patterns such as parent-child processes or multi-step attacks.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"69b434447f711ace0812ea7f","term":"DAN","definition":"DAN (Do Anything Now) is a roleplay-based jailbreak technique that instructs an AI model to adopt an unrestricted persona unconstrained by its safety guidelines.","resources":{"videos":[],"roomCodes":["jailbreaking"],"articles":[]},"__v":0},{"_id":"69b43b647abcdaa32846f431","term":"RAG","definition":"RAG (Retrieval-Augmented Generation) is a technique that enhances AI model responses by retrieving relevant external information at query time and feeding it into the model's context alongside the prompt.","resources":{"videos":[],"roomCodes":["prompt defences"],"articles":[]},"__v":0},{"_id":"69b43d54fa6d481aa3a365a8","term":"BERT","definition":"BERT (Bidirectional Encoder Representations from Transformers) is a pre-trained language model by Google that understands context by processing text in both directions simultaneously.","resources":{"videos":[],"roomCodes":["promptdefences"],"articles":[]},"__v":0},{"_id":"69bac7b5e9b658aac479ab67","term":"LLM","definition":"LLM (Large Language Model): A type of AI model trained on vast amounts of text data that generates human-like responses by predicting the most likely next token in a sequence.","resources":{"videos":[],"roomCodes":["promptengineering"],"articles":[]},"__v":0},{"_id":"69bc0fc8fc08dd81297fac33","term":"FIFO","definition":"A data processing principle where the first item added to a queue is the first to be removed.","resources":{"videos":[],"roomCodes":["llmsecurity"],"articles":[]},"__v":0},{"_id":"69bc0fdf7d25635234dacf8b","term":"DoW","definition":"DoW (Denial of Wallet): An attack that deliberately floods a pay-per-use API with requests to run up significant costs for the victim.","resources":{"videos":[],"roomCodes":["llmsecurity"],"articles":[]},"__v":0,"excludedCompanyIds":["650d731c8bcc9e953cafe9ee"]},{"_id":"69c261804cc8815c597675f8","term":"Sensitive Information Disclosure (LLM02)","definition":"Exposure of private or proprietary data through LLM outputs or system architecture.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c261a4832dd8320eec3975","term":"Parametric Memory","definition":"Information is compressed inside model weights during training.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c261b758e27c1958390ea2","term":"Non-Parametric Context","definition":"Data is retrieved at runtime from external sources such as vector databases.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c261c784ff82af4954a02e","term":"Context Window","definition":"The combined prompt contains user input, retrieved documents, and system instructions.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c261df8758e59377a4fb69","term":"Augmented Prompt","definition":"The full input is sent to the LLM, including the user query, retrieved documents, and system instructions.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c261f32cb3b0f18eba0774","term":"Top-k Retrieval","definition":"A similarity search configuration that returns the “k” most similar document chunks to a query.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c27327fe416b33ea3da545","term":"Metadata Pre-Filtering","definition":"Restricting which vectors are eligible for retrieval before the similarity search.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c273378a0e4acec8759719","term":"Similarity Search","definition":"A mathematical method that retrieves documents based on closeness in the similarity of vector space, not on authorisation or policy.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"69c273498e6fa37a4db7ec21","term":"Logging-Based Data Boundary Failure","definition":"A disclosure pattern where sensitive data becomes accessible through logging systems that have broader access than the original data source.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c27396bccd05b2aca3ac15","term":"Inference-Based Disclosure","definition":"A situation where sensitive information is revealed indirectly through patterns, outputs, or system behaviour — even if plaintext data is not directly shown.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c273a57c7897d19c8f4ff5","term":"Embedding Inversion","definition":"An attempt to reconstruct text from stored vectors.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c273b6e823bd1e4c476658","term":"Membership Inference","definition":"Determining whether a specific record exists in a dataset without reconstructing it.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c273c83ba6aadd9c418c37","term":"Segmentation","definition":"Logical or physical separation of data between tenants, roles, or departments.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c273d97c7897d19c8f508a","term":"Per-Tenant Index","definition":"A dedicated vector index assigned to a single tenant.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c273eb279092fa41828fa7","term":"Namespace","definition":"A logical grouping of vectors inside a vector database.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c273fbd0be6d4f63395d9e","term":"Row-Level Security (RLS)","definition":"Database-level enforcement that restricts access to specific records.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c2740e498f7ca8e24dbdbd","term":"Deterministic Enforcement","definition":"Security controls that operate before computation rather than relying on advisory prompts","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c27423fa68b1daeb51a7f9","term":"Redaction","definition":"Removal or masking of sensitive data before indexing or storage.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c274367ce0b065a6b2356c","term":"Allowlist Filtering","definition":"Restricting retrieval to explicitly authorised documents.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c274487ce0b065a6b235b2","term":"Data Retention Policy","definition":"Rules governing how long data remains stored and retrievable.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c2745a9e5b2ca291a96731","term":"Structured Logging","definition":"Logging metadata fields instead of raw text payloads.","resources":{"videos":[],"roomCodes":["sensitiveinformationdisclosure"],"articles":[]},"__v":0},{"_id":"69c274682452180747972761","term":"Monitoring Signal","definition":"Observable pattern indicating abnormal system behaviour.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"69c3c8915f79b7c9e586c882","term":"RAG (Retrieval-Augmented Generation)","definition":"A system where a language model retrieves external documents at inference time to help generate responses.","resources":{"videos":[],"roomCodes":["ragsecurityfundamentals"],"articles":[]},"__v":0},{"_id":"69c3c8a2df72d8a0824e06d6","term":"LLM (Large Language Model)","definition":"A machine learning model trained to generate text based on patterns learned from large datasets.","resources":{"videos":[],"roomCodes":["ragsecurityfundamentals"],"articles":[]},"__v":0},{"_id":"69c40d576c7e68769460bf67","term":"Data Poisoning","definition":"The intentional manipulation of training or update data to influence a model’s behaviour.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c40d69bb49d6a24a25b12f","term":"Model Poisoning","definition":"Poisoning that targets the model itself, such as weights or components, rather than just the raw data.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c40d7d6c7e68769460bfbc","term":"Training Data","definition":"The data is used to teach model patterns and relationships during learning.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c40d91ebf0bceee0c0eb99","term":"Integrity","definition":"The assurance that data and system behaviour have not been tampered with.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c40da46c7e68769460e2f6","term":"Embedding","definition":"A high-dimensional numerical representation of text that captures semantic meaning rather than exact words.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c40dc512ca4e19256c5c71","term":"Vector Space","definition":"A mathematical space where embeddings are positioned based on similarity. Documents with similar meaning are located closer together.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c40dd3d0ba07e61fab85f2","term":"Cosine Similarity","definition":"A mathematical function that measures how close two vectors are by comparing their direction. Higher values indicate greater similarity.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c40df4d0ba07e61fab8724","term":"Ingestion Pipeline","definition":"An automated process that collects, parses, and indexes documents into a system’s knowledge base.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c40e0112ca4e19256ca841","term":"Chunking","definition":"The process of splitting large documents into smaller text segments before embedding.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c40e0e12ca4e19256ca87c","term":"Embedding Generation","definition":"The conversion of text chunks into high-dimensional numerical vectors.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c40e1d3d64bbbeb77a1b7c","term":"Indexing","definition":"Storing embeddings in a vector database to enable similarity search.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c40e2c055aa81bb7eeb32a","term":"Scheduled Re-indexing","definition":"Automated jobs that periodically reprocess and update stored embeddings.","resources":{"videos":[],"roomCodes":["datapoisoninginragsystems"],"articles":[]},"__v":0},{"_id":"69c563b47e17254aac1ed468","term":"GGUF","definition":"GGUF (commonly expanded as GPT-Generated Unified Format) is a binary file format for storing and running large language models on consumer hardware. Developed by Georgi Gerganov as the successor to the earlier GGML format, it packages model weights and metadata into a single self-contained file, eliminating the compatibility issues of its predecessor. GGUF supports quantisation, a compression technique that reduces model size by lowering the precision of stored values, making large models runnable on standard laptops and desktops. It is the dominant format for sharing open-weight LLMs locally and is widely used by tools including llama.cpp, Ollama, and LM Studio.","resources":{"roomCodes":[],"videos":[],"articles":["https://github.com/ggml-org/ggml/blob/master/docs/gguf.md"]},"__v":0},{"_id":"69c5919ea48ff0f309078309","term":"GRPC","definition":"A high-performance binary protocol used for fast communication between services. Many AI inference servers use gRPC alongside HTTP because it handles large tensor data more efficiently. Standard HTTP scanners cannot interpret gRPC traffic.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c591d9a48ff0f309079d46","term":"GRPC Reflection","definition":"A feature that lets a client query a gRPC server for its full API schema without prior knowledge. If left enabled in production, anyone who connects can dump every available function call and its expected input format.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c591f20ca8f6ae5e892d2f","term":"Protobuf (Protocol Buffers)","definition":"The data format used by gRPC. Protobuf schemas define the exact structure, field names, and data types for every request and response. A dumped protobuf schema tells you exactly how to talk to the service.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c5920d0ca8f6ae5e892d3e","term":"Grpcurl","definition":"A command-line tool for interacting with gRPC services. Think of it as curl but for gRPC endpoints. It can list services, describe schemas, and send requests if reflection is enabled.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c59225db4e1e2919f1d1e8","term":"JA3/JA4","definition":"TLS fingerprinting methods that create a hash from the way a client says hello during a TLS handshake. Different software (Chrome, Python requests, curl) produces different hashes. Security teams use these to identify automated tooling versus human browsers.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c59242e3adefe0c8aff35e","term":"JA4H","definition":"A variant of JA4 that fingerprints HTTP client behaviour in addition to TLS. Useful for detecting shared automation tools even when attackers rotate IP addresses.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c5925ee3adefe0c8aff366","term":"NSE (Nmap Scripting Engine)","definition":"A framework within Nmap that runs scripts during scans to gather additional information. Scripts like http-title and http-headers extract additional details from discovered services that basic port scanning misses.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c59271e3adefe0c8aff370","term":"Server Header","definition":"An HTTP response header that identifies the web server software and version handling the request.","resources":{"roomCodes":["aisystemreconnaissance"],"videos":[],"articles":[]},"__v":0},{"_id":"69c592867559262ad93e189e","term":"Reverse Proxy","definition":"A server that sits in front of backend services and handles incoming requests on their behalf. When properly configured, it strips identifying headers and error details from AI services before they reach external clients.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c592a7a48ff0f309079d5d","term":"Artifact URI","definition":"The storage path where MLflow saves model files after training. Usually points to cloud storage services such as S3, GCS, or Azure Blob Storage. Finding this URI during enumeration reveals where the organisation keeps its model weights.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c592bf916172637c77f336","term":"Model Registry","definition":"A centralised repository that stores trained model files along with version history, stage labels (Production, Staging, Archived), and metadata about who created each version. MLflow, Vertex AI, and SageMaker all include model registries.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c592f2a48ff0f309079d78","term":"Registered Model","definition":"A named model entry in the registry. Each registered model can have multiple versions, and each version has its own artefact URI, creator, and deployment stage.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c5930e7559262ad93e18de","term":"Lifecycle Stage","definition":"The current status of an MLflow experiment. \"Active\" means the experiment is in use. \"Deleted\" means it was removed but may still be recoverable.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c5932a7559262ad93e18e8","term":"Tensor","definition":"A multi-dimensional array of numbers that AI models use as input and output. When a Triton config specifies an input shape of [1, 47] with dtype FP32, it means the model expects 47 floating-point values as input.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c5933ee3adefe0c8aff38e","term":"FP32 / INT64 / INT8","definition":"Data type labels for tensor values. FP32 means 32-bit floating point. INT64 means 64-bit integer. These tell you what kind of numbers the model expects and how much memory each value uses.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c59357e3adefe0c8aff39b","term":"Max Batch Size","definition":"The maximum number of requests a model server will process simultaneously. A batch size of 64 means the server can handle 64 inference requests in a single pass, revealing its capacity and throughput.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c5937da48ff0f30907ae66","term":"Platform (in Triton config)","definition":"Identifies which ML framework built the model. Values like \"pytorch_libtorch\" or \"onnxruntime\" tell you the exact framework, which is useful for crafting valid inference requests.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c593920300e37d77637544","term":"Prometheus","definition":"An open-source monitoring system that collects metrics from services. AI model servers expose /metrics endpoints in Prometheus text format, leaking model names, version numbers, latency, and GPU usage.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c593ab0300e37d77637559","term":"MLOKit","definition":"A CLI tool built by IBM X-Force Red for automated MLflow reconnaissance. It enumerates experiments, lists registered models, downloads model artefacts, and can poison model registries. Open source on GitHub.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c593c2e3adefe0c8b00a6d","term":"Swagger UI / OpenAPI","definition":"Auto-generated API documentation that FastAPI-based ML services create by default at /docs and /openapi.json. These expose the full request/response schema for every endpoint without requiring authentication.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c593e57559262ad93e19b9","term":"MITRE ATLAS","definition":"Adversarial Threat Landscape for AI Systems. A framework modelled after ATT&CK but specifically for AI and ML threats. Contains tactics (high-level objectives like Reconnaissance) and techniques (specific methods like Active Scanning).","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c59403a48ff0f30907ae76","term":"ATLAS Tactic","definition":"A high-level adversary objective. AML.TA0002 (Reconnaissance) is the tactic that covers all information-gathering activities against AI systems. Tactics describe what the attacker wants to achieve.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c5941a7559262ad93e19c1","term":"ATLAS Technique","definition":"A specific method used to accomplish a tactic. AML.T0000 (Active Scanning) and AML.T0048 (Discover ML Artefacts) are techniques under the Reconnaissance tactic. Techniques describe how the attacker performs the attack.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c59452db4e1e2919f1d2bb","term":"Dependency Confusion","definition":"An attack where an attacker registers a public package with the same name as an organisation's internal package. When the build system pulls from the public registry rather than the private one, the attacker's code executes in the target environment.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c59467db4e1e2919f1d2c7","term":"Typosquatting","definition":"Registering a package name that is a common misspelling of a legitimate package. If a developer types \"requets\" instead of \"requests\" in their requirements.txt, they pull the attacker's package instead.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c5947e916172637c77f359","term":"Pickle Deserialization","definition":"Python's pickle format can execute arbitrary code when a .pkl file is loaded. Malicious model files distributed through public hubs or compromised registries can exploit this to run code on the machine that loads them.","resources":{"roomCodes":["aisystemreconnaissance","webframeworkscodereview"],"videos":[],"articles":[]},"__v":0},{"_id":"69c594a6ce34e2b75e72aa8e","term":"OIDC (OpenID Connect)","definition":"An authentication protocol used to verify user identity. Kubeflow and other ML platforms should use OIDC to require authentication, but many deployments skip this and leave dashboards open.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c594ba95f961cc8d84d6b9","term":"DirectInternetAccess","definition":"A SageMaker notebook configuration option. When set to \"Enabled\", the notebook instance accepts inbound connections from the internet. 82% of organisations have at least one notebook configured this way.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c594d667510b458b4edb2a","term":"Nuclei","definition":"A template-driven vulnerability scanner from ProjectDiscovery. Uses YAML files to define what to scan for. Community templates exist for detecting exposed MLflow, Jupyter, and Triton instances.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c594fa67510b458b4f073b","term":"Agrus Scanner","definition":"A purpose-built scanner for detecting shadow AI infrastructure. Contains 50+ AI-specific probes and scans all 65,535 TCP ports rather than just checking default ports, catching AI services on non-standard ports.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c59543a57737c4b3657e90","term":"OAST (Out-of-band Application Security Testing)","definition":"A technique where attackers inject callback URLs into target systems. If the target makes an outbound request to the callback URL, it confirms the vulnerability is exploitable. ProjectDiscovery's Interact is a common OAST platform.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c59565a57737c4b3659c30","term":"CIDR (Classless Inter-Domain Routing)","definition":"A notation for defining IP address ranges. When SIEM logs show a Prometheus scrape from an IP address \"outside the monitoring CIDR\", it means the request originated from an IP address not in the approved range for monitoring tools.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c5957bc17ec2f90aa8ccb8","term":"Session Cookie","definition":"A token that web applications use to track authenticated users. MLflow API calls without a session cookie indicate scripted access rather than someone using the web interface, which is a sign of automated enumeration.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c5958e67510b458b4f0752","term":"Egress Filtering","definition":"Controlling what outbound connections a server can make. Prevents SSRF attacks in which an attacker forces an AI service to connect to external, attacker-controlled infrastructure.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c595a267510b458b4f075c","term":"Fine-grained Access Tokens","definition":"Tokens scoped to specific permissions and resources. After the Hugging Face breach, the recommendation was to replace broad-access tokens with fine-grained tokens that have read-only permissions and minimal scope.","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69c595b567510b458b4f0764","term":"Shadow AI","definition":"AI infrastructure deployed by data science teams without the knowledge or approval of the security team. These systems bypass standard security controls and are invisible to traditional asset inventories. ","resources":{"videos":[],"roomCodes":["aisystemreconnaissance"],"articles":[]},"__v":0},{"_id":"69cd371fdb4eb08194d5e009","term":"ATLAS","definition":"MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) is a knowledge base of adversarial tactics and techniques targeting machine learning systems. Modelled on the ATT&CK framework, it documents real-world and research-backed attacks across the AI attack lifecycle, from initial access and model theft to inference manipulation and data poisoning. Each entry is grounded in observed incidents or proof-of-concept research. Security teams use ATLAS to identify AI-specific attack surfaces, select defensive controls, and communicate AI risk in a structured vocabulary. It complements the OWASP LLM Top 10 by providing technique-level depth rather than vulnerability-category summaries.","resources":{"videos":[],"roomCodes":[],"articles":["https://atlas.mitre.org"]},"__v":0},{"_id":"69ce39323cb1c0a835abed45","term":"LoRA","definition":"LoRA (Low-Rank Adaptation) is a fine-tuning technique that adds a small number of trainable parameters to a pre-trained model instead of retraining all weights. It injects pairs of compact matrices into specific layers; only those matrices are updated during training, leaving the original model frozen. The output is a small adapter file that modifies the base model's behaviour when loaded alongside it. LoRA adapters are widely distributed on Hugging Face and enable task-specific specialisation without redistributing the full model. In supply chain terms, a tampered adapter can alter model behaviour while the base model passes all integrity checks.","resources":{"videos":[],"roomCodes":[],"articles":["https://arxiv.org/abs/2106.09685"]},"__v":0},{"_id":"69d00ca38fc9b1bf4c7db670","term":"Directory Listing","definition":"A web server feature that displays the contents of a directory when no index file is present, potentially exposing sensitive files.","resources":{"videos":[],"roomCodes":[],"articles":[]},"__v":0},{"_id":"69d0f85d3db09b4ae4f8a2d4","term":"SBOM","definition":"A Software Bill of Materials (SBOM) is a formal, itemised inventory of all components, dependencies, and metadata that make up a piece of software, used to provide transparency into what a software product contains and where its parts came from.","resources":{"roomCodes":["aimodelsdata"],"videos":[],"articles":["https://www.ntia.gov/sbom"]},"__v":0},{"_id":"69df27bf2eb3bdb572b3f8ba","term":"OT","definition":"Operational Technology (OT) refers to hardware and software systems used to monitor and control physical devices and processes in industries such as manufacturing, energy, transportation, and utilities. Unlike traditional IT systems, OT interacts directly with the physical world, making reliability and safety critical priorities.","resources":{"videos":[],"roomCodes":["introductiontotheworldofotics"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"69df27ed5aa102586ae05d9d","term":"SCADA","definition":"Supervisory Control and Data Acquisition (SCADA) is a system used to monitor and control industrial processes, often across large or geographically dispersed environments. It collects data from field devices like PLCs and provides centralized control and visibility for operators.","resources":{"videos":[],"roomCodes":["introductiontotheworldofotics"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"69df27f88b1100122b198957","term":"HMI","definition":"Human-Machine Interface (HMI) is a user interface that allows operators to interact with industrial control systems. It typically provides visual representations of processes, system status, and controls, enabling users to monitor operations and make adjustments when needed.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"69eb7b6cd12a5bf74b44bbea","term":"TTY","definition":"A TTY is a terminal interface that provides a proper input/output channel between a user and the operating system. The name comes from physical teletype machines, but today it refers to any terminal session with full line-discipline support, including signal handling (Ctrl+C, Ctrl+Z), character processing, and job control. Raw netcat shells lack a TTY, which is why interactive programs like sudo, su, and ssh fail to run in them.","resources":{"videos":[],"roomCodes":["shellsfundamentals"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"69eb7b8aaa4d661e23391ea9","term":"PTY","definition":"A PTY is a software-emulated TTY, a pair of virtual endpoints (master and slave) that behave like a real terminal without requiring physical hardware. When you run python3 -c 'import pty; pty.spawn(\"/bin/bash\")' or use socat's pty option, you are allocating a PTY. Programs cannot tell the difference between a PTY and a real terminal, so interactive tools that would otherwise refuse to run (text editors, password prompts, full-screen applications) work correctly in a PTY.\n\n","resources":{"videos":[],"roomCodes":["shellsfundamentals"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"69f377d6c6c8fd40231e0a46","term":"SPN","definition":"A unique identifier that maps a service instance to a service account in Active Directory. Kerberos uses the SPN to locate the correct account when issuing a service ticket, allowing clients to request authentication for a specific service.","resources":{"videos":[],"roomCodes":["introtoactivedirectoryauthentication"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"69f377f784a90eeb482da1fc","term":"KDC","definition":"The Kerberos service responsible for issuing tickets within a realm. In Active Directory, every domain controller runs the KDC role. It is made up of two components: the Authentication Service (AS), which issues the initial Ticket Granting Ticket (TGT), and the Ticket Granting Service (TGS), which issues service tickets based on a valid TGT.","resources":{"videos":[],"roomCodes":["introtoactivedirectoryauthentication"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"69f37815ce60ce08d00cdbfd","term":"TGS","definition":"As a service: the KDC component that issues service tickets to clients presenting a valid TGT.\nAs a ticket: the service ticket itself, used by the client to authenticate to a specific service identified by its SPN. The client sends the TGS ticket directly to the target service, which validates it without contacting the KDC.","resources":{"videos":[],"roomCodes":["introtoactivedirectoryauthentication"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"69f37b29ad7852b15d7f89ce","term":"LAMP","definition":"LAMP stands for Linux, Apache, MySQL, and PHP, a popular open-source stack used to host dynamic web applications, and one of the most common environments you'll encounter during web penetration tests.\n\n","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"69fb933501d32e73e85e7b58","term":"NTFS","definition":"NTFS (New Technology File System) is the default Windows file system that supports advanced features such as file permissions, encryption, compression.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a03396b3bfa5c47486eb395","term":"MERN","definition":"MERN (MongoDB, Express.js, React, Node.js) is a full JavaScript stack commonly found behind modern SaaS platforms and internal tools, making it one of the most frequently encountered stacks during a web application assessment.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a0dc79fa82a38838a8c6b05","term":"NDA","definition":"The Non-Disclosure Agreement (NDA) ensures that both parties protect confidential information exchanged during scoping discussions and throughout the engagement.","resources":{"roomCodes":["planningandscoping"],"videos":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a0dc7d08491445003bcba9a","term":"MSA","definition":"The Master Service Agreement (MSA) establishes the overarching legal relationship between the client and the testing firm. It covers liability and indemnification, intellectual property rights, dispute resolution mechanisms, and insurance requirements.","resources":{"roomCodes":["planningandscoping"],"videos":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a0dc7f1307cbc28a995c8e3","term":"SOW","definition":"The Statement of Work (SOW) is the engagement-specific document. Each penetration test gets its own SOW, which defines the systems to be tested (scope), the methodology and approach, the timeline and milestones, the deliverables (typically a report), and the cost.","resources":{"roomCodes":["planningandscoping"],"videos":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a1d5b5b2a2f75ad5ec97bba","term":"CSIRT","definition":"A Computer Security Incident Response Team (CSIRT) is a group responsible for receiving, analyzing, and responding to cyber security incidents within an organization.","resources":{"roomCodes":[],"videos":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a1d5c1c9c86c5bf78a9a342","term":"CERT","definition":"A Computer Emergency Response Team (CERT) is a group that handles cyber security incidents and coordinates responses, often at a national or organizational level.","resources":{"roomCodes":[],"videos":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a1d5c356f6a6fc809a559fc","term":"SERT","definition":"A Security Emergency Response Team (SERT) is a specialized group responsible for responding to security emergencies and coordinating incident handling efforts.","resources":{"roomCodes":[],"videos":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a1d5c51df3e6f6147189839","term":"IRT","definition":"An Incident Response Team (IRT) is a designated group of individuals responsible for managing and resolving security incidents within an organization.","resources":{"roomCodes":[],"videos":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a1e889dac54e65599436c9e","term":"UAL","definition":"The Unified Audit Log (UAL) is a Microsoft 365 log source that records user and admin activity across Exchange Online, SharePoint, Teams, and other Microsoft 365 services.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a1eac9341808af8e5680b01","term":"SIRT","definition":"A Security Incident Response Team (SIRT) is a group responsible for managing and coordinating an organiZation's response to security incidents.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a28287fa9254c752531d192","term":"Cloud Security Posture Management","definition":"CSPM (Cloud Security Posture Management) is a cybersecurity category that automates the identification, prioritization, and remediation of security risks and misconfigurations across multi-cloud environments. It continuously monitors your infrastructure to prevent breaches and maintain compliance with industry standards like HIPAA, GDPR, and PCI DSS.","resources":{"videos":[],"roomCodes":["defendercspm"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a2828f34bf26726490705fe","term":"CWP","definition":"Cloud Workload Protection (CWP) secures applications, virtual machines (VMs), containers, and serverless functions running in the cloud. It continuously scans for vulnerabilities, monitors runtime activity for malicious behavior, and prevents data breaches.","resources":{"roomCodes":[],"videos":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a2baa1be21813b932848625","term":"ARN","definition":"ARN is the Amazon Resource Name, a standardized, unique string used to identify resources across the entire AWS.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a2baa809baa19c2e86355ab","term":"IRSA","definition":"IRSA stands for IAM Role for Service Accounts, an Amazon EKS feature that allows Kubernetes applications to securely access AWS resources by using fine-grained AWS IAM permissions.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a2bc0899927bb4a4c86147f","term":"IaaS","definition":"IaaS stands for Infrastructue as a Service and means renting raw compute, storage, and networking over the internet.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a2bc0b1c687d47aa679a730","term":"PaaS","definition":"PaaS stands for Platform as a Service and provides an on-demand environment for developing, testing, and managing software applications.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a2bc0e36c1ab312d64755c1","term":"FaaS","definition":"FaaS stands for Function as a Service and provides serverless computing, where you manage and upload small, specific blocks of code.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a3059e837f3985b4648ae85","term":"GDPR","definition":"The General Data Protection Regulation (GDPR) is a regulation on information privacy in the European Union and the European Economic Area.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a30efe09ec4029de477832e","term":"PoLP","definition":"The Principle of Least Privilege, or PoLP for short, means granting only the minimum set of permissions needed for the minimum resources, for the minimum period of time.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a393628b4dbd389b5e8be76","term":"SSM","definition":"AWS Systems Manager (SSM) is a tool for configuring and managing cloud resources.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a3936999d52ee76e792cdc3","term":"Fargate","definition":"AWS Fargate is a serverless compute engine for containers. It allows you to run Docker containers without having to provision, configure, or manage your own virtual servers or container clusters.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a3a5c34c40abecd5c856774","term":"SSE-S3","definition":"AWS SSE-S3 (Server-Side Encryption with Amazon S3-Managed Keys) is a feature in Amazon S3 that automatically encrypts your data at rest using the Advanced Encryption Standard (AES-256).","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a3a5c51419df4cf629344a8","term":"SSE-KMS","definition":"AWS SSE-KMS (Server-Side Encryption with AWS Key Management Service) is a feature that automatically encrypts your data at rest using cryptographic keys managed through AWS KMS.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a3a5dc7a272d369582a9681","term":"EBS","definition":"AWS EBS (Elastic Block Store) is a raw block-level storage service that acts as a virtual hard drive for Amazon EC2 instances.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a3a5ddcc783e9d5ee7ca3a8","term":"EFS","definition":"AWS EFS (Amazon Elastic File System) is a fully managed, serverless network file storage service. ","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a3cc1d4fe4bf5e3b573a329","term":"IMDS","definition":"AWS IMDS (Instance Metadata Service) is a built-in RESTful service running on every EC2 instance. It allows applications and scripts running on the instance to securely access environment properties and retrieve temporary IAM credentials without hardcoding them.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a3cc211229f282345391415","term":"STS","definition":"AWS Security Token Service (STS) is a web service that enables you to request temporary, limited-privilege credentials for users, applications, or services to access AWS resources. ","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a3e7e55fea8a63bb1dcf3b0","term":"KMS","definition":"AWS Key Management Service (AWS KMS) is a fully managed AWS service that makes it easy to create, control, and manage cryptographic keys used to encrypt and digitally sign your data.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a3e7e7bd89b2015c6218b89","term":"SSE-C","definition":"AWS SSE-C (Server-Side Encryption with Customer-Provided Keys) is an Amazon S3 encryption method. It allows you to manage and supply your own encryption keys for your S3 objects.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a444acc173fdebe4f62a46d","term":"MSSP","definition":"An MSSP (Managed Security Service Provider) is a  third-party company that monitors, manages, and protects an organization's IT infrastructure from cyber threats.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a545476a139f308138e961c","term":"SSTI","definition":"SSTI (Server-Side Template Injection) is a vulnerability that occurs when user input is embedded into a server-side template engine in an unsafe way, causing the engine to parse and execute attacker-controlled template syntax instead of treating it as plain data. ","resources":{"roomCodes":["webframeworkspython","webframeworksjava"],"videos":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a568d357dcf00ecc767206e","term":"Directory Brute-Forcing","definition":"The technique of automatically requesting thousands of possible folder and file names from a wordlist against a web server to discover paths that aren't linked anywhere on the site's visible pages.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a568d35d44029d690564d50","term":"Wordlist","definition":"A plain text file containing one guess per line (such as folder or file names) used by brute-forcing tools like Gobuster instead of guessing names one at a time by hand.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a568d4d6bf05184afec3b7f","term":"Extension Fuzzing","definition":"A directory brute-forcing variant (Gobuster's -x flag) that appends one or more file extensions to every wordlist entry, turning a folder-name wordlist into file-name guesses like config.env or backup.zip.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a568d6bd5c15bcf35cdb16d","term":"Env File","definition":"A plain text configuration file, commonly named with a .env extension, used by web applications to store settings such as database credentials and admin passwords. Never meant to be publicly reachable, but readable like any other file if left in a web-accessible folder.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac05c331e215e3c3f855f","term":"Script Block Logging","definition":"A PowerShell logging feature that records the full, deobfuscated text of every script block PowerShell runs to Event ID 4104, whether typed at the console or run from a file.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac05d34287e049abd9fbb","term":"Module Logging","definition":"A PowerShell logging feature that records each cmdlet, function, and its bound parameters as Event ID 4103, giving a runtime trace of what executed even when the script was obfuscated.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac05d3c3a1cdece7b9b6b","term":"PowerShell Transcription","definition":"A policy that saves a full, readable text record of every command a PowerShell session runs and the output it returns, equivalent to running Start-Transcript automatically at session start.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac05e3a9e7fdd154eab67","term":"Constrained Language Mode","definition":"A PowerShell language mode that blocks access to .NET types, COM objects, and Win32 API calls that are not explicitly allowed, breaking most post-exploitation frameworks while still permitting basic automation.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac05f5f9042ff0c25da05","term":"WDAC","definition":"Windows Defender Application Control, a kernel-level application control feature that decides which code is allowed to run and can enforce Constrained Language Mode so user-mode PowerShell cannot override it.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac060f23fedfea2c03d0d","term":"PSReadLine","definition":"The PowerShell module that stores the literal command lines a user types interactively at the console in ConsoleHost_history.txt, a high-value artifact for reconstructing hands-on-keyboard activity.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac06034287e049abda174","term":"Prefetch","definition":"A Windows performance feature that writes a .pf file recording an executable's run count and last run times, used as forensic proof that a program such as powershell.exe executed.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac065331e215e3c3f9723","term":"Amcache","definition":"A registry hive that records metadata about executables the system has seen, including a SHA1 hash and the original file name, useful for spotting renamed binaries.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac066ff38df8b195a60b4","term":"ShimCache","definition":"Also called AppCompatCache, a cache in the SYSTEM hive that tracks executables the system encountered, proving a binary was present without proving it executed.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac06683922ed884223ab3","term":"BAM","definition":"The Background Activity Moderator, a registry key that records the last execution time of an executable tied to a specific user SID, the best execution artifact for attribution.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac067331e215e3c3f97de","term":"UserAssist","definition":"A per-user registry artifact in NTUSER.DAT that records a run count and last execution time for programs launched from the GUI, such as the Start menu or Explorer.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac06741187975116a2ee0","term":"WinRM","definition":"Windows Remote Management, the service behind PowerShell Remoting, listening on TCP 5985 (HTTP) and 5986 (HTTPS) and often used for lateral movement.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a5ac0673c80bd5da7170a5b","term":"Living off the land binary","definition":"A legitimate, signed, pre-installed tool such as powershell.exe that attackers abuse so their activity blends in with normal administration and evades traditional antivirus.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a7191cc8ec5d1108240526b","term":"GDB","definition":"Linux GNU Debugger is a portable debugger that runs on many Unix-like systems and works for many programming languages and allows you to see exactly what is happening inside an executable while it runs.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a7191fe1deea0b438fda98e","term":"GEF","definition":"Linux GNU Debugger Enhanced Features is a plug-in for GDB that adds advanced features for reverse engineering, binary code analysis, and exploit development.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a72ac9a3f3274133d8b45eb","term":"LOLBIN","definition":"A legitimate, signed, pre-installed tool such as powershell.exe that attackers abuse so their activity blends in with normal administration and evades traditional antivirus.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a72ad262ebcd40ba2de53f3","term":"LOLBAS","definition":"LOLBAS stands for Living Off the Land Binaries and Scripts. It refers to any binary or script that comes pre-installed in an Operative System that can be used by an attacker to perform activities while avoiding detection.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a72adb3be02ba288e6fcbee","term":"ClickFix","definition":"A social engineering attack that show the user a pop-up with instructions to copy and paste a malicious payload, all disguised as a fix for a vulnerability or problem the user needs to fix.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a74cdec58024d770655b033","term":"IEX","definition":"PowerShell alias for Invoke-Expression, which evaluates a string as PowerShell code. Central to downloading cradles, since it lets a remote script string execute in memory without ever being saved to disk.","resources":{"videos":[],"roomCodes":["filelessattacks"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a75d04c1a4021f13ee187da","term":"Next-token Prediction","definition":"The mechanism by which a large language model generates text. The model reads all preceding tokens, selects the single most probable next token, and repeats the process until the output is complete.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a7d554278d80e409191348a","term":"TDO","definition":"A Trusted Domain Object (TDO) is the Active Directory object that stores a trust relationship between two domains. It lives in the System container of each domain (CN=System, DC=<domain>) and records the partner domain, the trust's direction, type, and attributes, plus the encrypted trust password used to derive the inter-realm Kerberos key. Every trust creates two TDOs, one in each participating domain, and the two mirror each other's direction value.","resources":{"videos":[],"roomCodes":["activedirectorytrusttheory"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a829405bafc54cff78dbf2d","term":"SID","definition":"A Security Identifier (SID) is the unique value Windows and Active Directory use to identify a security principal such as a user, group, or computer. It has the form S-1-5-21-<domain identifier>-<RID>, where the domain identifier is shared across a domain and the relative identifier (RID) distinguishes each principal (for example, RID 519 is Enterprise Admins). Access checks use SIDs, not names, which is why injecting a privileged group's SID into a token grants that group's rights, and why SID filtering strips SIDs a trusted domain should not assert.","resources":{"videos":[],"roomCodes":["activedirectorytrusttheory"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a829422176679aee3c66ba8","term":"PAC","definition":"The Privilege Attribute Certificate (PAC) is a structure embedded in a Kerberos ticket that carries the account's authorisation data: the user's and their groups' SIDs, plus fields such as ExtraSids (originally for SID history). A domain controller reads the PAC to build the user's access token, so its contents decide what the user can access. That makes it a target for trust attacks: a forged golden ticket can place arbitrary SIDs in the PAC, and the trusting DC's SID-filtering check removes those that shouldn't survive the trust.","resources":{"videos":[],"roomCodes":["activedirectorytrusttheory"],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a85d8cbcd62454511388d9e","term":"RMM","definition":"RMM (Remote Monitoring and Management) is software used to remotely monitor, manage, and control endpoints and networks, typically used by IT teams.","resources":{"roomCodes":[],"videos":[],"articles":[]},"excludedCompanyIds":[],"__v":0},{"_id":"6a85d9228bd24d72ff2d4d20","term":"LSASS","definition":"LSASS (Local Security Authority Subsystem Service) is a Windows process that enforces security policy and handles user authentication, storing credentials in memory.","resources":{"videos":[],"roomCodes":[],"articles":[]},"excludedCompanyIds":[],"__v":0}]}