Resources
Glossary
Plain-language definitions for the terms used across this site, alphabetized for quick lookup.
- Attack Surface
- Every point where an unauthorized user could try to interact with or affect a system.
- Bridged Networking
- A virtual networking mode that puts a VM directly on the physical network, as if it were another device on your router.
- CTF (Capture the Flag)
- A competition format where participants solve security challenges to find hidden "flags," often used for hands-on learning.
- CVE
- Common Vulnerabilities and Exposures — a public reference ID assigned to a specific known vulnerability.
- Enumeration
- The process of gathering detailed information about a target's services after discovering they exist.
- Exploit
- Code or a technique that takes advantage of a specific vulnerability.
- Firewall
- A system that controls network traffic based on defined rules, typically blocking unwanted connections.
- Host-Only Network
- A virtual network shared only by VMs on the same physical host, with no path to the internet.
- Hypervisor
- Software (like VirtualBox or VMware) that creates and runs virtual machines.
- Metasploit Framework
- An open-source penetration-testing framework used to develop and run exploits against target systems.
- Misconfiguration
- A security weakness caused by incorrect or overly permissive settings, rather than a software bug.
- NAT (Network Address Translation)
- A networking mode that gives a VM outbound internet access routed through the host, without exposing it to inbound connections.
- Nmap
- A widely used network scanning tool for host discovery and port scanning.
- Payload
- The code that runs on a target after an exploit succeeds.
- Penetration Testing
- Authorized, simulated testing of a system's security to find weaknesses before real attackers do.
- Port
- A numbered network endpoint a service listens on, such as port 22 for SSH.
- Port Scanning
- Probing a range of ports on a target to determine which are open, closed, or filtered.
- Privilege Escalation
- Gaining a higher level of access than initially granted, such as moving from a standard user to root.
- Red Team / Blue Team
- Red team simulates attackers; blue team defends. Both roles are represented in the offensive/defensive framing used throughout this site.
- Service Banner
- Text a network service sends when a client connects, often revealing its name and version.
- TCP/UDP
- The two core transport protocols used for network communication; TCP is connection-based, UDP is not.
- Virtual Machine (VM)
- A full computer system running inside a file on a host machine, isolated from it.
- Vulnerability
- A weakness in a system that could be used to compromise its security.