Glossary

Welcome to the Glossary! Whether you're already familiar with some of these terms or you're just becoming acquainted, our top-level glossary is a great resource for learning all of the relevant goods. Scroll through the full list below, search by term, or select by individual letter.
SHOW ALL A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

JavaScript object notation (JSON)

A text-based, human-readable data interchange format used for representing simple data structures and objects in browser-based code.

Large Language Models (LLMs)

Models designed to understand language in a human-like fashion by training on massive amounts of text data to learn patterns, relationships, and contextual information in language, and then making judgments about them.

Look-alike Domain

A spoofed domain intended to fool users into thinking it’s the legitimate domain. The domain can look like the real domain but may have subtle differences, ex: “0” versus “o.”

Lure

An attack lure, often used in phishing campaigns, is a ploy where cybercriminals bait their targets to convince them to share sensitive information – either delivered through a phone call, text message, or email.

machine learning (ML)

The process by which a computer improves its own performance by continuously incorporating new data into an existing statistical model.

Mail-focused Security Orchestration, Automation, and Response (mSOAR)

This mail-focused type of software automates repetitive tasks and streamlines incident and threat response workflows, and most importantly, can be integrated into email security solutions to support security operations teams operations.

malware

A broad term that covers every type of software created to disable or damage computer systems. Viruses, worms, spyware, and ransomware are all forms of malware.

Man-in-the-Middle Attack (MITM)

This type of common cybersecurity attack involves external parties who insert themselves or eavesdrop on a communication between two targets with the goal of impersonating one of the parties.

managed detection and response (MDR)

A service that provides remotely delivered modern security operations center capabilities focused on quickly detecting, investigating, and actively mitigating incidents. Fortra’s Alert Logic product line delivers managed detection and response solutions. 

managed file transfer (MFT)

Software that encompasses all aspects of inbound and outbound file transfers while using industry-standard network protocols and encryption. Fortra’s GoAnywhere, Globalscape, and FileCatalyst product lines deliver MFT solutions.

managed file transfer as a service (MFTaaS)

A hosted managed file transfer solution using the vendor’s infrastructure. Why a SaaS Solution Can Benefit Your Company

managed security service (MSS)

Outsourced network security services.

managed security service provider (MSSP)

A vendor that provides outsourced monitoring and management of security devices and systems. Common services include managed firewall, intrusion detection, virtual private network, vulnerability scanning and anti-viral services.

managed service provider (MSP)

A vendor that delivers services, such as network, application, infrastructure and security, via ongoing and regular support and active administration on customers’ premises, in their MSP’s data center (hosting), or in a third-party data center.

Misdirected Emails

Also called Accidental Data Loss; This is when an email that is meant for a particular person or party is sent to the wrong person with body content or attachments that may contain personal data, such as PII.

multifactor authentication​​​​​​​ (MFA)

Electronic authentication method in which a user is granted access to a website or application only after presenting two or more pieces of identity authentication.

National Institute of Standards and Technology (NIST)

A physical sciences laboratory, and a nonregulatory agency of the U.S. Department of Commerce. The NIST promotes U.S. innovation and industrial competitiveness in the fields of technology, engineering, IT, and more. What is NIST?

Natural Language Processing (NLP)

A tool used in cyber threat intelligence which seeks to identify and analyze the motives and operations of threat actors by extracting valuable insights from textual data.

Neural Networks

These are useful in email security, where a broad range of file types, images, text, etc. are encounteredm to learn complex patterns and features automatically and capture subtleties and nuances that would be missed by feature-engineered models.

North American Electric Reliability Corporation - Critical Infrastructure Protection (NERC-CIP)

NERC Critical Infrastructure Protection (NERC-CIP) is a set of requirements designed to secure the assets required for operating North America's bulk electric system.

offensive security

Offensive security involves proactively testing an organization's defenses by simulating real-world attacks, such as through penetration testing, in order to identify and fix exploitable vulnerabilities.

Online Impersonation

A purposeful spoof of a brand, executive, or employee with intent to sway opinion or fool victims into performing an action.

Open PGP

A popular encryption standard that protects the privacy and integrity of sensitive files. Open PGP is an open-source offshoot of PGP that uses PGP as its foundation. Everything You Need to Know About Open PGP Encryption

open source

Software that comes with permission to use, copy, and distribute, either as-is or with modifications, and that may be offered either free or with a charge.

Open Web

The accessible, indexed portion of the internet that does not require special or secured access measures common to the deep web and dark web. Sites on the open web can be found on search engines and are used for everyday activities like shopping, streaming content, reading, social media, and more.

Open Worldwide Application Security Project (OWASP)

The Open Worldwide Application Security Project is an online community that produces freely-available articles, methodologies, documentation, tools, and technologies in the field of web application security. The OWASP provides free and open resources.

Password Cracking

Also referred to as Password Hacking; The process in which bad actors go through to hack, or get into computer systems illegally, in order to steal, corrupt, or illegitimately view personal data; in this case, by cracking passwords.

Paste Site

A website, used most often by multiple code developers, designed to allow the uploading and sharing of files, scripts, and code snippets. 

Payment Card Industry Data Security Standard (PCI DSS, PCI)

The comprehensive set of requirements designed to ensure that any company that processes, stores, or transmits credit card information does so by maintaining a secure environment. The requirements were established to help prevent payment data breaches and payment card fraud.

PCI Security Standards Council (PCI SSC)

PCI Security Standards Council (PCI SSC), made up of major payment companies, including Visa, MasterCard, American Express, Discover, and JCB, administers and manages the PCI DSS standard. However, enforcing the compliance of PCI DSS is the responsibility of the individual payment brands.

penetration testing

Also called pen testing. An attempt to evaluate the security of an IT infrastructure by safely trying to exploit vulnerabilities. Fortra’s Core Security Core Impact, Cobalt Strike, and IBM i product lines deliver pen testing solutions.    

personally identifiable information (PII)

Data that directly or indirectly identifies a specific individual, such as names, addresses, biometrics, and alphanumeric account numbers.

Phishing

A fraudulent attempt to obtain sensitive data such as usernames, passwords, and credit card details by disguising as a trustworthy entity through digital communications.

Phishing Simulation

This is a cybersecurity exercise that simulates a phishing attack for employees or users and tests to see if they can recognize and respond to it appropriately.

Phishing Website

A hoax website built to mimic reputable brands with the intention of misleading readers into giving up personal data such as usernames, passwords and financial information.  

platform as a service (PaaS)

A form of cloud computing in which a provider delivers hardware and software tools on its own infrastructure to users over the internet.