| No. | Item | Definition |
|---|---|---|
| 1. | actor | person or group behind activity |
| 2. | adversary | attacker or hostile actor |
| 3. | alert | warning of possible threat |
| 4. | anomaly | something unusual or unexpected |
| 5. | artifact | trace left by activity |
| 6. | authentication | verifying identity |
| 7. | authorization | granting permitted access |
| 8. | autorun | automatic execution on start |
| 9. | backdoor | hidden access method |
| 10. | baseline | normal activity reference point |
| 11. | binary | compiled executable file |
| 12. | botnet | network of controlled devices |
| 13. | C2 | attacker command channel |
| 14. | campaign | coordinated series of attacks |
| 15. | certificate | digital identity document |
| 16. | cluster | related activity grouping |
| 17. | command | instruction entered for execution |
| 18. | compromise | unauthorized system breach |
| 19. | containment | limiting spread of compromise |
| 20. | credential | login secret or proof |
| 21. | detection | finding malicious activity |
| 22. | DLL | shared Windows code library |
| 23. | DNS | system translating domain names |
| 24. | domain | named internet location |
| 25. | dwell time | time attacker stays undetected |
| 26. | egress | outbound network movement |
| 27. | endpoint | user device on a network |
| 28. | enumeration | listing users, shares, services |
| 29. | eradication | removing malicious presence |
| 30. | escalation | gaining higher access rights |
| 31. | evasion | avoiding detection mechanisms |
| 32. | exfiltration | unauthorized data removal |
| 33. | exploit | code abusing a weakness |
| 34. | false negative | missed malicious event |
| 35. | false positive | benign event flagged malicious |
| 36. | firewall | network traffic filtering control |
| 37. | foothold | initial stable access point |
| 38. | forensics | analysis of digital evidence |
| 39. | hardening | making systems more secure |
| 40. | hash | fixed fingerprint of data |
| 41. | honeypot | decoy system for attackers |
| 42. | host | individual computer or server |
| 43. | hunter | person who searches actively |
| 44. | implant | malicious tool placed secretly |
| 45. | indicator | sign of suspicious activity |
| 46. | ingress | inbound network movement |
| 47. | insider | trusted person causing risk |
| 48. | intrusion | unauthorized entry into systems |
| 49. | investigation | examining suspicious activity |
| 50. | IOC | indicator of compromise |
| 51. | IP | network address number |
| 52. | keylogger | tool recording keystrokes |
| 53. | kill chain | stages of an attack |
| 54. | lateral movement | moving across compromised systems |
| 55. | log | record of system events |
| 56. | macro | automated document command set |
| 57. | malware | malicious software |
| 58. | masquerading | pretending to be legitimate |
| 59. | MFA | multiple login verification methods |
| 60. | misconfiguration | unsafe system setup |
| 61. | obfuscation | hiding code or intent |
| 62. | patch | update fixing a flaw |
| 63. | payload | malicious code delivered by attack |
| 64. | persistence | ability to remain on systems |
| 65. | phishing | fraudulent message to steal data |
| 66. | pivot | use one host to reach others |
| 67. | port | numbered communication endpoint |
| 68. | privilege | level of access rights |
| 69. | process | running program instance |
| 70. | quarantine | isolated suspicious file or host |
| 71. | ransomware | malware that demands payment |
| 72. | reconnaissance | gathering target information |
| 73. | registry | Windows configuration database |
| 74. | remediation | fixing damage and weaknesses |
| 75. | rootkit | stealthy system-hiding malware |
| 76. | sandbox | isolated testing environment |
| 77. | script | small interpreted program |
| 78. | service | background system program |
| 79. | session | active communication exchange |
| 80. | shellcode | small exploit-executing code |
| 81. | signature | pattern used to identify threats |
| 82. | spoofing | faking identity or source |
| 83. | startup | program launch at boot |
| 84. | target | intended victim system or user |
| 85. | telemetry | security data from systems |
| 86. | threat | potential cause of harm |
| 87. | traffic | data moving across networks |
| 88. | triage | prioritizing and assessing alerts |
| 89. | trojan | malware disguised as legitimate |
| 90. | TTP | tactics, techniques, and procedures |
| 91. | tunnel | hidden communication channel |
| 92. | URL | web resource address |
| 93. | victim | entity harmed by attack |
| 94. | virus | self-replicating malicious code |
| 95. | vulnerability | weakness attackers can exploit |
| 96. | watchlist | list of monitored items |
| 97. | worm | self-spreading malicious program |
| 98. | XDR | extended detection across sources |
| 99. | YARA | rule language for malware matching |
| 100. | zero-day | unknown unpatched vulnerability |

