| No. | Item | Definition |
|---|---|---|
| 1. | account | User or service identity |
| 2. | Active Directory | Microsoft identity directory service |
| 3. | alert | Security notification needing review |
| 4. | anomaly | Activity outside normal pattern |
| 5. | artifact | Useful trace left by activity |
| 6. | asset | Valuable system or resource |
| 7. | authentication | Verifying identity |
| 8. | authorization | Granting allowed access |
| 9. | backdoor | Hidden method of access |
| 10. | backup | Saved copy of data |
| 11. | baseline | Normal activity reference point |
| 12. | beacon | Periodic callback to attacker |
| 13. | blocklist | Denied items list |
| 14. | botnet | Network of compromised devices |
| 15. | breach | Unauthorized access to data |
| 16. | brute force | Trying many password guesses |
| 17. | C2 | Command and control |
| 18. | certificate | Digital identity document |
| 19. | ciphertext | Encrypted unreadable data |
| 20. | confidentiality | Data kept from unauthorized access |
| 21. | containment | Limiting spread of an incident |
| 22. | correlation | Linking related events together |
| 23. | credential | Login secret or proof |
| 24. | DDoS | Distributed denial of service |
| 25. | detection | Finding malicious activity |
| 26. | DNS | Domain name lookup system |
| 27. | domain | Administrative network realm |
| 28. | EDR | Endpoint detection and response |
| 29. | Electronic messaging system | |
| 30. | endpoint | User device on a network |
| 31. | enumeration | Listing users, shares, services |
| 32. | eradication | Removing threat from environment |
| 33. | escalation | Passing issue to higher level |
| 34. | exfiltration | Unauthorized data removal |
| 35. | exploit | Code using a vulnerability |
| 36. | false positive | Benign event flagged malicious |
| 37. | firewall | Network traffic filtering system |
| 38. | forensics | Investigation of digital evidence |
| 39. | hardening | Reducing attack surface |
| 40. | hash | Fixed-length data digest |
| 41. | honeypot | Decoy system for attackers |
| 42. | host | Network-connected computer |
| 43. | HTTP | Web transfer protocol |
| 44. | HTTPS | Encrypted web transfer protocol |
| 45. | impact | Resulting harm or effect |
| 46. | incident | A confirmed security event |
| 47. | insider | Trusted person misusing access |
| 48. | integrity | Data remains accurate, unchanged |
| 49. | IOC | Indicator of compromise |
| 50. | IP | Internet Protocol address |
| 51. | keylogger | Tool that records keystrokes |
| 52. | kill chain | Stages of an attack |
| 53. | lateral movement | Attacker movement across systems |
| 54. | least privilege | Minimum necessary access |
| 55. | log | Recorded system or event data |
| 56. | malware | Malicious software |
| 57. | MFA | Multiple login verification factors |
| 58. | misconfiguration | Unsafe or incorrect setup |
| 59. | MITRE ATT&CK | Threat behavior knowledge base |
| 60. | noise | Irrelevant or low-value data |
| 61. | password | Secret used for login |
| 62. | patch | Software fix for a flaw |
| 63. | payload | Malicious code delivered by attack |
| 64. | persistence | Ability to remain on system |
| 65. | phishing | Fraudulent attempt to steal data |
| 66. | playbook | Standard response procedure |
| 67. | priority | Order of response importance |
| 68. | privilege escalation | Gaining higher access rights |
| 69. | quarantine | Isolate suspicious file or host |
| 70. | query | Request for specific data |
| 71. | ransomware | Malware that demands payment |
| 72. | RDP | Remote desktop protocol |
| 73. | reconnaissance | Information gathering before attack |
| 74. | recovery | Restoring normal operations |
| 75. | remediation | Fixing the root problem |
| 76. | response | Action after detection |
| 77. | rootkit | Malware hiding system compromise |
| 78. | runbook | Step-by-step operational guide |
| 79. | sandbox | Isolated environment for testing |
| 80. | severity | Seriousness level of issue |
| 81. | SIEM | Security information and event management |
| 82. | signature | Known pattern for detection |
| 83. | SMB | File sharing protocol |
| 84. | social engineering | Manipulating people for access |
| 85. | spoofing | Faking sender or source |
| 86. | SSH | Secure remote shell protocol |
| 87. | telemetry | Collected security event data |
| 88. | threat | Potential cause of harm |
| 89. | timeline | Ordered sequence of events |
| 90. | TLS | Transport Layer Security |
| 91. | token | Digital proof of identity |
| 92. | triage | Prioritizing alerts or incidents |
| 93. | trojan | Malware disguised as legitimate |
| 94. | TTP | Tactics, techniques, procedures |
| 95. | virus | Malware that infects files |
| 96. | VPN | Encrypted remote network connection |
| 97. | vulnerability | A weakness attackers can exploit |
| 98. | worm | Self-spreading malware |
| 99. | YARA | Pattern matching rule language |
| 100. | zero-day | Unknown unpatched vulnerability |

