Bare Metal Cyber v0.2.3
Technical-Core Wiki Expansion
Two technical-core waves now provide 160 educational articles across networking, identity, Windows, cryptography, systems, threats, detection, forensics, web and API security, mobile security, and connected devices.
- Home
- Cyber Wiki
- Technical Core
New Curriculum
160 technical-core entries
AI Security & Emerging Technology
Automotive Cybersecurity
Automotive cybersecurity protects vehicle electronic systems, software, communications, data, update infrastructure, service tools, manufacturing, and cloud services while preserving safety, reliability, privacy, and long product lifecycles.
Embedded technology foundation · AdvancedEmbedded Systems Security
Embedded systems security protects purpose-built computing devices whose software, hardware, interfaces, timing, physical environment, and long support lifecycle are tightly coupled to a product or physical process.
Cyber-physical risk domain · AdvancedMedical Device Cybersecurity
Medical device cybersecurity manages the confidentiality, integrity, availability, authenticity, resilience, and safe operation of connected or software-enabled devices throughout design, clinical use, maintenance, vulnerability response, and retirement.
Cloud, Application Security & DevSecOps
API Authentication and Token Validation
API authentication and token validation establish which principal is calling an API and whether the presented credential is authentic, current, intended for that audience, and permitted to support the requested action.
Application architecture concept · AdvancedAPI Gateway Security
An API gateway is an intermediary that routes and mediates API traffic and may enforce authentication, rate limits, schema controls, observability, transformation, and policy; securing it requires consistent edge policy without assuming the gateway can replace backend authorization.
Application security concept · IntermediateBroken Object-Level Authorization
Broken Object-Level Authorization is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Cloud security concept · IntermediateContainer Runtime Security
Container Runtime Security is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Browser security control · AdvancedContent Security Policy
Content Security Policy is an HTTP response policy that tells supporting browsers which sources and execution patterns are permitted for scripts, styles, images, frames, connections, and other resources, reducing the impact of many content-injection flaws.
Web session-security concept · IntermediateCookies and Web Sessions
Cookies are browser-managed name-value records scoped by domain, path, security attributes, and lifetime; web applications often use them to carry a session identifier that binds requests to server-side authentication and authorization state.
Application security concept · IntermediateCross-Site Request Forgery
Cross-Site Request Forgery is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.
Application security concept · IntermediateCross-Site Scripting
Cross-Site Scripting is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.
Application security concept · IntermediateFile Upload Security
File Upload Security is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.
API security concept · AdvancedGraphQL Security
GraphQL security protects a typed query interface in which clients select fields and traverse relationships; the server must enforce authorization, resource limits, safe resolver behavior, and controlled schema exposure for every requested object and field.
Web protocol foundation · FoundationalHTTP Methods and Status Codes
HTTP methods express the intended action on a resource, while status codes communicate the outcome; secure applications enforce authorization and state rules for every method and return responses that are accurate without disclosing unnecessary detail.
Application security concept · IntermediateInsecure Deserialization
Insecure Deserialization is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.
Mobile security foundation · IntermediateMobile Application Architecture
Mobile application architecture combines device code, operating-system services, local storage, backend APIs, identity providers, push services, update channels, and third-party SDKs; security depends on how trust and data move across all of those components.
Application security concept · IntermediateREST API Security
REST API Security is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.
Application security concept · IntermediateSame-Origin Policy and Cross-Origin Resource Sharing
Same-Origin Policy and Cross-Origin Resource Sharing is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.
Cloud security concept · IntermediateSecure Access Service Edge
Secure Access Service Edge is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Application security concept · IntermediateServer-Side Request Forgery
Server-Side Request Forgery is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.
Web protocol foundation · FoundationalURLs, URIs, and HTTP Request Structure
A URI identifies a resource, a URL adds a method and location for reaching it, and an HTTP request carries a method, target, headers, and optional body that a server interprets within an application and trust context.
Real-time application security concept · AdvancedWebSocket Security
WebSocket security protects long-lived, bidirectional connections that begin with an HTTP upgrade and then carry application-defined messages outside the normal request-response pattern.
Cryptography & Data Protection
Advanced Encryption Standard (AES)
Advanced Encryption Standard (AES) is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Endpoint data-protection control · IntermediateBitLocker Drive Encryption
BitLocker is a Windows full-volume encryption capability that protects data at rest by binding volume keys to trusted startup conditions, recovery methods, and optional user authentication.
Cryptography and trust concept · IntermediateCertificate Chain Validation
Certificate Chain Validation is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Cryptography and trust concept · IntermediateCertificate Revocation Lists and OCSP
Certificate Revocation Lists and OCSP is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Cryptography and trust concept · IntermediateCertificate Signing Requests
Certificate Signing Requests is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Cryptography and trust concept · IntermediateCryptographic Hash Functions
Cryptographic Hash Functions is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Cryptography and trust concept · IntermediateDiffie-Hellman Key Exchange
Diffie-Hellman Key Exchange is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Cryptography and trust concept · IntermediateDigital Signatures
Digital Signatures is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Cryptography and trust concept · IntermediateElliptic Curve Cryptography
Elliptic Curve Cryptography is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Software authenticity control · AdvancedFirmware Signing
Firmware signing uses protected private keys and verified metadata to let a bootloader, device, installer, or update service determine that firmware was authorized by the product owner and has not been modified since signing.
Cryptography and trust concept · IntermediateFull-Disk Encryption
Full-Disk Encryption is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Cryptography and trust concept · IntermediateHardware Security Modules
Hardware Security Modules is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Cryptography and trust concept · IntermediateInitialization Vectors and Nonces
Initialization Vectors and Nonces is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Cryptography and trust concept · IntermediateKey Derivation Functions
Key Derivation Functions is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Mobile transport-security concept · AdvancedMobile Certificate Validation and Pinning
Mobile certificate validation verifies that a server certificate chains to a trusted authority, matches the intended service, is valid for the current time and policy, and has not been revoked or otherwise rejected; pinning adds a narrower application trust decision for selected keys or certificates.
Cryptography and trust concept · IntermediatePublic Key Infrastructure Operations
Public Key Infrastructure Operations is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Cryptography and trust concept · IntermediateRSA Cryptography
RSA Cryptography is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Cryptography and trust concept · IntermediateRoot and Intermediate Certificate Authorities
Root and Intermediate Certificate Authorities is a cryptographic or trust-management mechanism used to provide confidentiality, integrity, authenticity, non-repudiation, or secure key establishment.
Mobile data-protection concept · IntermediateSecure Mobile Data Storage
Secure mobile data storage keeps secrets and sensitive information out of inappropriate files, caches, backups, logs, screenshots, clipboards, notifications, and shared locations while using platform protection suited to the data and threat model.
Cryptography and trust concept · IntermediateTLS Handshake
TLS Handshake is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Identity & Access Management
802.1X Network Access Control
802.1X Network Access Control is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Identity and access concept · IntermediateAccess Tokens, ID Tokens, and Refresh Tokens
Access Tokens, ID Tokens, and Refresh Tokens is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Identity architecture concept · IntermediateActive Directory Domains, Trees, Forests, and Trusts
Active Directory organizes identities and resources into domains; related domains form trees, one or more trees form a forest, and trusts define which security principals may be recognized across boundaries.
Identity and access concept · IntermediateDiscretionary Access Control
Discretionary Access Control is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Identity and access concept · IntermediateFederation and Trust Relationships
Federation and Trust Relationships is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Service-account security concept · AdvancedGroup Managed Service Accounts
Group Managed Service Accounts are Active Directory accounts whose complex passwords are automatically managed and made available only to authorized hosts, reducing the need to store or manually rotate service credentials.
Connected-device identity concept · AdvancedIoT Device Identity
IoT device identity is the set of cryptographic and lifecycle mechanisms used to distinguish one physical or logical device from another, authenticate it to services and peers, and bind actions and data to an accountable device record.
Identity and access concept · IntermediateJust-in-Time Access
Just-in-Time Access is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Authentication protocol concept · AdvancedKerberos in Active Directory
Kerberos in Active Directory is a ticket-based authentication system in which domain controllers acting as key distribution centers issue time-limited tickets that let users and services prove identity without repeatedly transmitting passwords.
Mobile platform-security concept · FoundationalMobile App Permissions
Mobile app permissions authorize access to protected device capabilities and data such as location, camera, microphone, contacts, files, sensors, notifications, nearby devices, and background activity.
Mobile identity-security concept · AdvancedMobile Authentication and Authorization
Mobile authentication and authorization combine user, device, application, and backend trust decisions so a mobile client can establish an identity while servers enforce what that identity may do with each resource and transaction.
Legacy authentication protocol concept · AdvancedNTLM Authentication
NTLM is a Windows challenge-response authentication family retained for compatibility when Kerberos or modern authentication cannot be used; its weaker trust properties make dependency reduction an important defensive goal.
Identity and access concept · IntermediateOAuth 2.0 Authorization
OAuth 2.0 Authorization is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Identity administration concept · IntermediateOrganizational Units and Delegation
Organizational units are Active Directory containers used to organize objects, apply Group Policy, and delegate narrowly defined administrative tasks without granting broad domain privileges.
Identity and access concept · IntermediatePrivileged Access Workflows
Privileged Access Workflows is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Identity and access concept · IntermediateRADIUS and TACACS+
RADIUS and TACACS+ is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Identity and access concept · IntermediateRule-Based Access Control
Rule-Based Access Control is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Identity and access concept · IntermediateSAML Authentication
SAML Authentication is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Identity and access concept · IntermediateSCIM Provisioning
SCIM Provisioning is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Identity and access concept · IntermediateSession Management
Session Management is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Authentication architecture concept · IntermediateWindows Authentication
Windows authentication is the collection of local and domain mechanisms Windows uses to verify identities, establish logon sessions, obtain network credentials, and authorize access to operating-system and enterprise resources.
Privileged account management control · IntermediateWindows Local Administrator Password Solution
Windows Local Administrator Password Solution automatically generates, rotates, stores, and controls retrieval of unique local administrator passwords so a compromised password on one device cannot be reused across an entire fleet.
Networks & Protocols
Address Resolution Protocol (ARP)
Address Resolution Protocol (ARP) describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.
Network security concept · BeginnerDHCP Security
DHCP Security describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.
Network security concept · BeginnerDNS Resolution Process
DNS Resolution Process describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.
Network security concept · BeginnerDNS Security Extensions (DNSSEC)
DNS Security Extensions (DNSSEC) describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.
Network security concept · BeginnerDemilitarized Zones
Demilitarized Zones is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Network security concept · BeginnerForward Proxies
Forward Proxies is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Network security concept · BeginnerHTTP and HTTPS
HTTP and HTTPS describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.
Network security concept · BeginnerIPv6 Neighbor Discovery
IPv6 Neighbor Discovery is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Network security concept · BeginnerInternet Control Message Protocol (ICMP)
Internet Control Message Protocol (ICMP) describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.
Connected-device network control · IntermediateIoT Network Segmentation
IoT network segmentation places connected devices into controlled zones and communication paths according to function, trust, ownership, and consequence so compromise of one device does not provide unrestricted access to users, servers, management systems, or other devices.
Network security concept · BeginnerNetwork Address Translation (NAT)
Network Address Translation (NAT) is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Network security concept · BeginnerNetwork Segmentation and Microsegmentation
Network Segmentation and Microsegmentation is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Network security concept · BeginnerNetwork Time Protocol Security
Network Time Protocol Security describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.
Network security concept · BeginnerPort Address Translation (PAT)
Port Address Translation (PAT) is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Network security concept · BeginnerReverse Proxies
Reverse Proxies is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Network security concept · BeginnerSecure Shell (SSH)
Secure Shell (SSH) is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Network security concept · BeginnerSecure and Insecure Protocols
Secure and Insecure Protocols describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.
Network security concept · BeginnerSimple Network Management Protocol Security
Simple Network Management Protocol Security describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.
Network security concept · BeginnerSoftware-Defined Networking Security
Software-Defined Networking Security is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Network security concept · BeginnerStateful and Stateless Firewalls
Stateful and Stateless Firewalls is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Network security concept · BeginnerTCP Three-Way Handshake
TCP Three-Way Handshake describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.
Network security concept · BeginnerVirtual LANs (VLANs)
Virtual LANs (VLANs) is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Network security concept · BeginnerVirtual Private Network Protocols
Virtual Private Network Protocols describes how systems exchange, interpret, or protect information across a network. Security depends on both the protocol behavior and the way it is configured, authenticated, monitored, and constrained.
Network security concept · BeginnerWireless Authentication and Encryption
Wireless Authentication and Encryption is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Security Operations & Incident Response
Antivirus, EDR, and XDR
Antivirus, EDR, and XDR is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Detection-program assessment · AdvancedDetection Coverage and Gap Analysis
Detection coverage and gap analysis determines which priority adversary behaviors, misuse cases, control failures, and business risks are observable and actionable, and where missing telemetry, analytic logic, context, or response capacity leaves a gap.
Detection engineering practice · AdvancedDetection as Code
Detection as code manages analytic rules, queries, parsers, tests, documentation, and deployment through version-controlled engineering practices so detection changes are reviewable, reproducible, testable, and safely promoted.
Digital forensics discipline · AdvancedDisk Forensics
Disk forensics acquires and examines storage media and file-system artifacts to reconstruct user, application, operating-system, and adversary activity while preserving evidence integrity and provenance.
Endpoint monitoring concept · AdvancedEndpoint Detection and Response Telemetry
EDR telemetry records endpoint behavior such as process execution, modules, files, registry, users, network connections, scripts, drivers, security events, and response actions so analysts can detect and investigate activity in context.
Security operations practice · IntermediateFile Integrity Monitoring
File Integrity Monitoring is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Digital forensics method · AdvancedForensic Timeline Analysis
Forensic timeline analysis orders and correlates events from systems, files, identities, networks, applications, and people to explain what happened, when it happened, how confidently it is known, and where evidence is missing or contradictory.
Security data engineering concept · AdvancedLog Quality Engineering
Log quality engineering measures and improves whether security events are complete, accurate, timely, consistent, attributable, protected, and usable for the detections and investigations that depend on them.
Security operations process · IntermediateLog Source Onboarding
Log source onboarding is the controlled process of bringing a new event source into security monitoring with validated collection, parsing, timestamps, identifiers, access controls, retention, health checks, and documented analytic value.
Malware analysis technique · AdvancedMalware Sandboxing
Malware sandboxing executes or emulates suspicious code in a controlled environment to observe processes, files, registry changes, network activity, persistence, evasion, and other behavior without exposing production systems.
Security operations practice · IntermediateMemory Forensics
Memory Forensics is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.
Network monitoring concept · AdvancedNetwork Traffic Analysis
Network traffic analysis examines packet, flow, DNS, proxy, TLS, routing, and session metadata to understand communication patterns, identify suspicious behavior, and reconstruct activity across network trust boundaries.
Security operations practice · IntermediateNetwork Traffic Flow Records
Network Traffic Flow Records is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Security operations practice · IntermediatePacket Capture and PCAP Analysis
Packet Capture and PCAP Analysis is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.
Security operations practice · IntermediatePowerShell Security and Logging
PowerShell Security and Logging is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.
Detection-program process · AdvancedSIEM Use-Case Lifecycle
The SIEM use-case lifecycle manages a detection from threat and business requirement through data validation, analytic design, testing, deployment, triage, measurement, tuning, maintenance, and retirement.
Security operations planning concept · IntermediateSecurity Telemetry Strategy
A security telemetry strategy defines which events, states, and contextual data an organization must collect to prevent, detect, investigate, respond to, and learn from priority threat and failure scenarios.
Security operations practice · IntermediateSigma Rules
Sigma Rules is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.
Network detection concept · AdvancedSnort and Suricata Rules
Snort and Suricata rules describe network traffic conditions that an intrusion detection or prevention engine can alert on, record, reject, or otherwise handle using protocol, flow, content, metadata, and state-aware inspection.
Security operations practice · IntermediateSysmon
Sysmon is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Behavioral analytics concept · AdvancedUser and Entity Behavior Analytics
User and Entity Behavior Analytics models activity for users, devices, workloads, applications, and other entities to identify statistically or contextually unusual behavior that may indicate compromise, misuse, control failure, or operational change.
Security operations practice · IntermediateWindows Event Logs
Windows Event Logs is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.
Malware detection concept · AdvancedYARA Rules
YARA is a pattern-matching language used to classify files, memory, and other byte or text content by combining strings, metadata, modules, and Boolean conditions into reusable detection rules.
Systems, Endpoints & Infrastructure
Active Directory Fundamentals
Active Directory Fundamentals concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.
Systems security concept · IntermediateBIOS and UEFI Security
BIOS and UEFI Security concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.
Systems security concept · IntermediateEndpoint Application Control
Endpoint Application Control concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.
Systems security concept · IntermediateGroup Policy Security
Group Policy Security concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.
Systems security concept · IntermediateHost-Based Firewalls
Host-Based Firewalls is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Systems security concept · IntermediateInternet of Things Security
Internet of Things Security is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Connected-device lifecycle control · AdvancedIoT Secure Update Mechanisms
IoT secure update mechanisms let a device authenticate update metadata and payloads, verify integrity and authorization, install changes safely, resist rollback, recover from failure, and report update state throughout a long product lifecycle.
Hardware interface security concept · AdvancedJTAG and UART Security
JTAG and UART security controls debug, test, programming, and serial interfaces that can expose firmware, memory, boot state, credentials, consoles, and privileged device control when physically accessible.
Windows credential-protection concept · AdvancedLSASS and Credential Protection
The Local Security Authority Subsystem Service enforces local security policy, validates certain logons, creates access tokens, and handles credential material; protecting LSASS is central to limiting credential theft from Windows endpoints.
Systems security concept · IntermediateOperating System Fundamentals
Operating System Fundamentals concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.
Systems security concept · IntermediateProcesses, Services, and Daemons
Processes, Services, and Daemons is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Remote administration security concept · AdvancedRemote Desktop Security
Remote Desktop security protects Windows interactive administrative sessions by controlling who can connect, how endpoints authenticate, where credentials are exposed, which channels are redirected, and how activity is monitored and contained.
Systems security concept · IntermediateRemovable Media Security
Removable Media Security is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Systems security concept · IntermediateSecure Boot
Secure Boot concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.
Embedded platform-security control · AdvancedSecure Boot for Embedded Devices
Secure boot for embedded devices creates a chain of verified software from an initial trusted component through bootloader, operating system, firmware, and application so unauthorized code is not executed during startup.
Systems security concept · IntermediateSecure Configuration Management
Secure Configuration Management concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.
Systems security concept · IntermediateSecurity Baselines and Benchmarks
Security Baselines and Benchmarks is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Systems security concept · IntermediateSystem Hardening
System Hardening concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.
Systems security concept · IntermediateType 1 and Type 2 Hypervisors
Type 1 and Type 2 Hypervisors concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.
Windows privilege-boundary control · IntermediateUser Account Control
User Account Control limits routine use of administrative privileges by giving administrators a filtered standard token and requiring an elevation decision before a process receives the full administrative token.
Systems security concept · IntermediateVirtual Machine Security
Virtual Machine Security concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.
Windows platform-security control · AdvancedWindows Credential Guard
Windows Credential Guard uses virtualization-based security to isolate selected domain credentials from the normal operating system so that compromise of the host is less likely to expose reusable NTLM hashes and Kerberos ticket-granting tickets.
Host firewall control · IntermediateWindows Defender Firewall
Windows Defender Firewall is a stateful host firewall that applies profile-aware inbound and outbound rules to programs, services, ports, protocols, interfaces, users, and network conditions.
Windows configuration-security concept · IntermediateWindows Registry Security
The Windows Registry is a hierarchical configuration database whose keys and values influence operating-system, service, application, security, persistence, and user behavior; protecting it requires permission control, change monitoring, and recovery discipline.
Threats, Malware & Adversaries
AS-REP Roasting
AS-REP roasting targets Active Directory accounts that do not require Kerberos preauthentication, allowing an attacker to request an authentication response containing password-derived material and attempt offline password guessing.
Threat and attack concept · IntermediateAdvanced Persistent Threats
Advanced Persistent Threats is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Threat and attack concept · IntermediateBootkits
Bootkits describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Threat and attack concept · IntermediateCommand and Control Channels
Command and Control Channels is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Threat and attack concept · IntermediateCredential Stuffing
Credential Stuffing is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Active Directory credential-access technique · AdvancedDCSync
DCSync is an abuse of Active Directory replication rights in which an attacker makes a system act like a domain controller and requests password-derived credential data through normal directory replication protocols.
Threat and attack concept · IntermediateData Staging and Exfiltration
Data Staging and Exfiltration describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Threat and attack concept · IntermediateFileless Malware
Fileless Malware describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Credential attack technique · AdvancedKerberoasting
Kerberoasting is an attack technique in which an authenticated domain user requests Kerberos service tickets for service principal names and attempts to crack the ticket material offline to recover weak service-account passwords.
Threat and attack concept · IntermediateLiving-off-the-Land Techniques
Living-off-the-Land Techniques is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Threat and attack concept · IntermediateOn-Path Attacks
On-Path Attacks describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Credential replay technique · AdvancedPass-the-Hash
Pass-the-Hash is a credential replay technique in which an attacker uses a captured NTLM password hash to authenticate without learning or typing the original plaintext password.
Threat and attack concept · IntermediatePassword Attacks
Password Attacks describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Threat and attack concept · IntermediatePassword Spraying
Password Spraying describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Threat and attack concept · IntermediateReplay Attacks
Replay Attacks describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Threat and attack concept · IntermediateRootkits
Rootkits describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Threat and attack concept · IntermediateSession Hijacking
Session Hijacking is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Threat and attack concept · IntermediateSupply Chain Compromise
Supply Chain Compromise is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Vulnerabilities & Security Testing
Clickjacking
Clickjacking overlays or frames a legitimate interface so a user’s visible click lands on a hidden or disguised control, causing an unintended action in the user’s authenticated session.
Application vulnerability class · AdvancedCommand Injection
Command injection occurs when untrusted data is incorporated into an operating-system command or shell expression and changes the command’s intended structure, arguments, control flow, or executed program.
Embedded security testing practice · AdvancedFirmware Analysis
Firmware analysis examines the software image and supporting metadata that control an embedded device to identify architecture, components, configuration, secrets, services, update logic, vulnerabilities, and runtime behavior.
Security testing practice · AdvancedMobile Application Security Testing
Mobile application security testing evaluates architecture, storage, cryptography, authentication, network communication, platform interaction, code quality, resilience, privacy, backend APIs, and release integrity across supported mobile platforms.
Security testing practice · IntermediatePatches, Updates, and Upgrades
Patches, Updates, and Upgrades is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Application vulnerability class · IntermediatePath Traversal
Path traversal occurs when untrusted input influences a file or directory path and allows access outside the application’s intended storage boundary through relative segments, alternate encodings, symbolic links, or platform-specific path behavior.
Application vulnerability class · AdvancedXML External Entity Processing
XML External Entity risk arises when an XML parser resolves attacker-controlled external entities or related document features, potentially reading local resources, making server-side requests, disclosing data, or consuming excessive resources.