Cyber Dojo Glossary

Master the Language of the Digital Battlefield

Every term defined with dojo discipline and warrior precision.

A

Access Control

The dojo gate — only the worthy enter.

Active Directory

The identity temple where all permissions are forged.

Adversary

The unseen opponent studying your weaknesses.

Attack Surface

Every doorway, window, and crack in your digital fortress.

Authentication

Proving you belong inside the dojo.

Authorization

Determining what techniques you're allowed to use.

Advanced Persistent Threat (APT)

A prolonged and targeted cyberattack where an intruder gains access and remains undetected for an extended period.

Air Gap

Physical isolation of a network from all other networks to prevent data breaches.

Antivirus

Software designed to detect and destroy computer viruses.

Asset Management

Tracking and managing all hardware, software, and data assets to reduce security risks.

B

Backdoor

A hidden entrance attackers carve into your systems.

Behavioral Analytics

Studying digital movements the way a sensei studies footwork.

Botnet

An army of compromised machines controlled by a silent warlord.

Breach

When the enemy crosses your threshold.

Brute Force Attack

Repeated strikes hoping one lands.

Blue Team

Defensive security team that protects the organization from cyber threats.

Bug Bounty

A reward program for finding and reporting software vulnerabilities.

Business Continuity

Planning and preparation to ensure business operations continue during and after a cyber incident.

C

C2 (Command & Control)

The enemy's war room.

CISA KEV

The scroll of known exploited vulnerabilities.

Cloud Security

Guarding your assets floating above the battlefield.

Credential Stuffing

Attackers testing stolen keys on every lock.

Critical Vulnerability

A broken gate hinge waiting to be kicked in.

Cyber Hygiene

Daily kata that keep your defenses sharp.

Certificate Authority

Trusted entity that issues digital certificates for secure communications.

CISA

Cybersecurity and Infrastructure Security Agency - federal agency defending U.S. cyber infrastructure.

CMMC

Cybersecurity Maturity Model Certification - DoD framework for contractors.

Compromise Assessment

Thorough investigation to determine if systems have been breached.

Cryptography

The art of securing information through mathematical algorithms.

CVE

Common Vulnerabilities and Exposures - standardized identifier for known security vulnerabilities.

D

Dark Web

The shadow market where stolen secrets are traded.

Data Exfiltration

When attackers steal your scrolls.

Defense in Depth

Layered armor — never rely on one shield.

DDoS

Overwhelming your dojo with endless noise.

Detection Engineering

Crafting traps for unseen intruders.

Disaster Recovery

Process of restoring systems and data after a catastrophic event.

DNS Security

Protecting Domain Name System from attacks and manipulation.

E

EDR/XDR

Sensors on every limb of your digital body.

Encryption

Turning your data into unreadable warrior code.

Endpoint

Every device that touches your network.

Exploit

A precise strike against a known weakness.

Email Gateway

Security solution that filters malicious emails before they reach users.

Exfiltration

Unauthorized transfer of data from a computer or network.

F

Firewall

The outer wall of your cyber fortress.

Forensics

Reconstructing the enemy's movements after the battle.

Framework (NIST/CMMC)

The scrolls of discipline guiding your defenses.

FISMA

Federal Information Security Management Act - framework for federal information security.

Fuzzing

Testing technique that provides invalid, unexpected, or random data as inputs to find vulnerabilities.

G

Governance

The rules that keep your dojo honorable and compliant.

Gap Analysis

Identifying weaknesses in your stance.

GDPR

General Data Protection Regulation - EU data privacy law.

H

Hashing

One-way transformation of data — a sealed scroll.

Honeypot

A trap disguised as treasure.

Human Firewall

Training your people to block attacks with awareness.

HIPAA

Health Insurance Portability and Accountability Act - protects sensitive patient health information.

Hunting (Threat)

Proactively searching for threats that evaded automated detection.

I

IAM

Controlling who enters which chamber of the dojo.

Incident Response

The rapid counterstrike after an intrusion.

Indicator of Compromise (IOC)

Footprints left by the enemy.

Insider Threat

A traitor within the dojo walls.

Identity Governance

Framework for managing digital identities and access rights.

IDS/IPS

Intrusion Detection/Prevention Systems - monitors and blocks malicious network activity.

Information Security

Practice of protecting information from unauthorized access, use, disclosure, disruption, or destruction.

ISO 27001

International standard for information security management systems.

J

JWT

A signed token proving identity in the digital realm.

K

Key Rotation

Changing the locks before attackers find the keys.

Keylogger

Malicious program that records keystrokes to steal passwords and sensitive data.

Kill Chain

Framework describing stages of a cyber attack from reconnaissance to data theft.

L

Lateral Movement

Attackers slipping from room to room inside your network.

Least Privilege

No warrior carries more weapons than needed.

Log Management

Collection, storage, and analysis of security logs for threat detection.

M

Malware

The enemy's poison.

MFA

Two-step verification — the double-locked gate.

MITRE ATT&CK

The encyclopedia of enemy tactics.

MDR

Your 24/7 cyber guardians.

Monitoring

Constant vigilance — the dojo never sleeps.

Man-in-the-Middle (MitM)

Attack where adversary intercepts communications between two parties.

Managed Security

Outsourced monitoring and management of security systems.

Microsegmentation

Dividing network into small, isolated segments to contain breaches.

N

NVD

The national ledger of vulnerabilities.

Network Segmentation

Dividing the dojo into secure chambers.

NAC

Network Access Control - restricts unauthorized devices from joining the network.

NIST

National Institute of Standards and Technology - develops cybersecurity frameworks and guidelines.

O

OSINT

Intelligence gathered from public scrolls.

Orchestration

Automating your defensive kata.

OAuth

Open standard for access delegation commonly used for token-based authentication.

P

Patch Management

Repairing armor before battle.

Penetration Testing

Controlled combat to reveal weaknesses.

Phishing

Deception disguised as trust.

Privilege Escalation

An attacker leveling up inside your systems.

PCI DSS

Payment Card Industry Data Security Standard - requirements for organizations handling credit cards.

Purple Team

Collaborative security team combining red team (offense) and blue team (defense) approaches.

Q

Quarantine

Isolating infected endpoints.

R

Ransomware

Hostage-taking malware demanding tribute.

Risk Assessment

Evaluating your stance before the fight.

Response Time

The speed of your counterstrike.

Red Team

Offensive security team that simulates real-world attacks to test defenses.

Remediation

Process of fixing security vulnerabilities and weaknesses.

Rootkit

Malware designed to provide unauthorized root or administrative access.

S

SIEM

The watchtower collecting every signal.

SOC

The command center of your cyber dojo.

Social Engineering

Manipulating human trust — the softest target.

Supply Chain Attack

Striking through your allies.

Surface Reduction

Minimizing openings in your armor.

SAML

Security Assertion Markup Language - standard for exchanging authentication data.

Sandboxing

Isolated environment for safely executing and analyzing suspicious code.

Security Awareness

Training programs to educate employees about cybersecurity threats and best practices.

Security Posture

Overall cybersecurity strength of an organization.

SOC 2

Service Organization Control 2 - audit for service providers storing customer data.

SSL/TLS

Protocols for encrypting data transmitted over networks.

T

Threat Actor

The opponent studying your patterns.

Threat Intelligence

Knowing the enemy before they strike.

Tokenization

Replacing sensitive data with harmless symbols.

TTPs

The enemy's tactics, techniques, and procedures.

Threat Hunting

Proactive search for cyber threats hiding within networks.

Threat Modeling

Process of identifying and prioritizing potential threats to a system.

Two-Factor Authentication

Security process requiring two different authentication factors to verify identity.

U

User Awareness Training

Teaching warriors to recognize deception.

UEBA

User and Entity Behavior Analytics - detects threats by identifying abnormal behavior.

V

Vulnerability

A crack in your stance.

Vulnerability Management

The discipline of constant improvement.

Virtual Patching

Security policy that prevents exploitation of a vulnerability without modifying the vulnerable code.

VPN

Virtual Private Network - encrypted connection over a public network.

W

Watering Hole Attack

Poisoning a trusted gathering place.

Whaling

Targeting high-value leaders.

Web Application Firewall (WAF)

Firewall that filters, monitors, and blocks HTTP traffic to and from a web application.

X

XSS

Injecting malicious scripts into trusted pages.

Y

YARA Rules

Pattern-matching spells for malware hunters.

Z

Zero Day

A fresh vulnerability with no defense yet.

Zero Trust

Trust nothing. Verify everything.

Zombie Process

A dead process still haunting the system.

Zero-Day Exploit

Attack that occurs on the same day a vulnerability becomes known, before a patch is available.