| No. | Item | Definition |
|---|---|---|
| 1. | API | software interface for functions |
| 2. | artifact | observable trace left by activity |
| 3. | assembly | low-level programming language |
| 4. | backdoor | hidden access method into systems |
| 5. | beacon | periodic signal to command server |
| 6. | binary | compiled executable file |
| 7. | bot | infected device under remote control |
| 8. | botnet | network of compromised devices |
| 9. | breakpoint | pause point during debugging |
| 10. | C2 | command and control |
| 11. | callback | outbound contact to controller |
| 12. | clipper | malware replacing clipboard addresses |
| 13. | containment | limiting spread of an incident |
| 14. | credential | login information |
| 15. | crypter | tool that encrypts malware code |
| 16. | decompilation | turning binaries into higher code |
| 17. | detonation | controlled execution of suspicious file |
| 18. | disassembly | converting machine code to assembly |
| 19. | DLL | shared Windows code library |
| 20. | downloader | malware that fetches more malware |
| 21. | drive-by download | automatic download from a website |
| 22. | driver | software controlling hardware access |
| 23. | dropper | malware that installs other malware |
| 24. | ELF | common Unix executable format |
| 25. | entropy | measure of randomness in data |
| 26. | eradication | complete removal of malicious presence |
| 27. | evasion | techniques to avoid detection |
| 28. | exfiltration | unauthorized data removal |
| 29. | exploit | code abusing a vulnerability |
| 30. | fast flux | rapidly changing DNS technique |
| 31. | fileless | operating mainly without files |
| 32. | firmware | software embedded in hardware |
| 33. | forensics | investigation of digital evidence |
| 34. | handle | reference to a system object |
| 35. | hash | fixed-length file fingerprint |
| 36. | header | metadata at file beginning |
| 37. | heap | memory area for dynamic allocation |
| 38. | heuristic | rule based on suspicious behavior |
| 39. | hollowing | replacing code in a process |
| 40. | honeypot | decoy system for attackers |
| 41. | hook | intercepted function or event |
| 42. | implant | malicious code placed on target |
| 43. | injection | placing code into another process |
| 44. | IOC | indicator of compromise |
| 45. | IP | internet protocol address |
| 46. | kernel | core part of an operating system |
| 47. | keylogger | malware recording keystrokes |
| 48. | lateral movement | spreading across internal systems |
| 49. | loader | program that loads malicious code |
| 50. | macro | embedded script in documents |
| 51. | malvertising | malicious online advertising |
| 52. | malware | malicious software |
| 53. | MBR | master boot record area |
| 54. | MD5 | older hashing algorithm |
| 55. | memory | temporary data storage for programs |
| 56. | miner | malware mining cryptocurrency |
| 57. | mutex | lock object preventing conflicts |
| 58. | obfuscation | code made hard to understand |
| 59. | offset | distance from a reference point |
| 60. | opcode | machine instruction operation code |
| 61. | packing | compressing or hiding executable code |
| 62. | payload | malicious action delivered by malware |
| 63. | PE | Windows executable file format |
| 64. | persistence | ability to survive reboots |
| 65. | phishing | deceptive message stealing information |
| 66. | privilege escalation | gaining higher access rights |
| 67. | process | running instance of a program |
| 68. | quarantine | isolated storage for suspicious files |
| 69. | ransomware | malware that encrypts for payment |
| 70. | registry | Windows configuration database |
| 71. | remediation | steps to remove a threat |
| 72. | resource | embedded data inside executable |
| 73. | reverse engineering | analyzing how software works |
| 74. | rootkit | malware hiding deep in systems |
| 75. | sample | individual malware file or artifact |
| 76. | sandbox | isolated environment for testing |
| 77. | service | background system program |
| 78. | shellcode | small code used in exploitation |
| 79. | side-loading | loading malicious library via trust |
| 80. | signature | pattern used to detect malware |
| 81. | spearphishing | targeted phishing attack |
| 82. | spyware | software that secretly monitors users |
| 83. | telemetry | collected system activity data |
| 84. | thread | smallest scheduled execution unit |
| 85. | threat actor | person or group behind attacks |
| 86. | trace | record of execution steps |
| 87. | triage | quick initial threat assessment |
| 88. | trojan | malware disguised as legitimate software |
| 89. | TTP | tactics, techniques, and procedures |
| 90. | UEFI | modern firmware boot interface |
| 91. | URL | web address |
| 92. | virus | self-replicating malicious program |
| 93. | VM | virtual machine |
| 94. | vulnerability | weakness that can be exploited |
| 95. | watering hole | compromised site targeting victims |
| 96. | wiper | malware that destroys data |
| 97. | worm | self-spreading malicious program |
| 98. | YARA | pattern-matching rule language |
| 99. | zero-day | unknown unpatched vulnerability |
| 100. | zombie | compromised machine under control |

