Field kit

Glossary

Operator vocabulary

Clear definitions for terms you will meet in tools, lessons, and reports — with links back into the catalog and curriculum.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

56 terms

Active reconnaissance

Recon that sends packets to target systems (port scans, web crawling, DNS queries to authoritative servers you interact with directly).

Why it matters: Higher fidelity but noisier. Always ensure scope and rate limits match the RoE.

AS-REP Roasting

Attack against Kerberos accounts that do not require pre-authentication. The AS-REP can be cracked offline to recover the user password.

Why it matters: A single misconfigured account flag can expose a crackable blob without knowing a password first.

Attack path (AD graph)

A chain of relationships (group membership, ACLs, sessions, RDP rights, etc.) that connects a principal to a high-value target such as Domain Admin.

Why it matters: Real AD compromise is often multi-hop. Graph analysis finds paths humans miss; defenders should break paths, not only patch CVEs.

Authorization

Documented permission from a party with legal right to approve testing. Distinct from authentication (proving identity).

Why it matters: Technical ability never substitutes for authorization. Home labs, bug bounties, and client engagements each have different permission models.

Beacon

Periodic callback from a compromised host to C2 infrastructure to fetch tasks and return results.

Why it matters: Beacon timing, jitter, and destinations are detection features. Long-lived rare destinations from servers deserve scrutiny.

BOLA (Broken Object Level Authorization)

OWASP API Security term essentially equivalent to IDOR: missing object-level authorization on API endpoints.

Why it matters: Modern apps are API-first; BOLA is frequently the highest-impact API issue in bug bounties and pentests.

Buffer overflow

Memory safety bug where more data is written to a buffer than it can hold, potentially overwriting control data such as return addresses.

Why it matters: Classic exam and legacy software topic. Modern mitigations (ASLR, DEP/NX, stack canaries, safe languages) raise the bar substantially.

C2 (Command and Control)

Infrastructure and protocols used by operators (red or criminal) to remotely control compromised hosts and stage further actions.

Why it matters: Detecting C2 is core blue-team work. In labs, frameworks like Metasploit/Sliver demonstrate patterns — never point them at unauthorized systems.

Cross-Site Scripting (XSS)

Injecting script into pages viewed by other users. Types include reflected, stored, and DOM-based XSS.

Why it matters: Leads to session theft, defacement, and malware delivery in victim browsers. Context-aware encoding and CSP help.

CSRF (Cross-Site Request Forgery)

Forces an authenticated victim browser to send unwanted state-changing requests to a vulnerable app using the victim's cookies.

Why it matters: Anti-CSRF tokens, SameSite cookies, and avoiding cookie-only auth for APIs reduce risk.

CVSS

Common Vulnerability Scoring System — a standardized numerical scoring framework for vulnerability severity.

Why it matters: Useful common language, but environment context (auth requirements, reachability, data sensitivity) still requires analyst judgment.

Enumeration

Deep, protocol-aware discovery of users, shares, configs, and application details after basic scanning identifies services.

Why it matters: Most successful compromises come from careful enum, not exotic 0-days. Document everything for the report.

Finding (report)

A structured vulnerability or weakness write-up: title, severity, affected assets, evidence, impact, likelihood, and remediation.

Why it matters: Clients buy risk reduction, not tool output. Clear findings drive fixes; poor findings waste trust.

Foothold

Initial authorized access on a target system during a test — a shell, RDP session, valid account, or equivalent.

Why it matters: Post-ex starts here. Stabilize access carefully under RoE; avoid destructive persistence unless requested.

GTFOBins

Curated catalog of Unix binaries that can be abused for shell, file read/write, privesc, or other functions when mis-granted elevated rights.

Why it matters: Speeds Linux privesc analysis. Pair with careful validation — not every GTFOBins path works in every confinement context.

IDOR (Insecure Direct Object Reference)

Access control failure where changing an identifier (order ID, user ID, filename) grants access to another user's object without authorization checks.

Why it matters: Extremely common in APIs and a top real-world bug class. Easy to test carefully with two accounts.

JWT (JSON Web Token)

Compact token format often used for API auth, typically as header.payload.signature (Base64URL). Integrity depends on correct algorithm and secret/key handling.

Why it matters: Weak secrets, alg confusion, and overstuffed claims cause auth bypasses. Always verify signature validation and claim checks server-side.

Kerberoasting

Requesting Kerberos service tickets for accounts with SPNs and offline-cracking the ticket material to recover the service account password.

Why it matters: Weak service account passwords become domain footholds. Defenses: strong/gMSA passwords, AES, detection of unusual TGS patterns.

Kerberos

Ticket-based authentication protocol used by Active Directory. Clients obtain TGTs and service tickets (TGS) via the KDC (usually a domain controller).

Why it matters: Understanding TGTs, TGS, SPNs, and encryption types is required for AD assessments and for defending against ticket abuse.

Least privilege

Granting only the minimum permissions required for a user, service, or process to perform its function.

Why it matters: Limits damage from phished users, RCE bugs, and stolen tokens. Applies to OS rights, cloud IAM, and DB accounts.

LLMNR

Link-Local Multicast Name Resolution — a Windows fallback name resolution protocol used when DNS fails. Hosts multicast queries on the local segment.

Why it matters: Attackers can spoof LLMNR responses and capture or relay authentication material (often NTLM). Disabling LLMNR/NBT-NS is a common hardening step.

LOLBAS

Living Off the Land Binaries and Scripts — legitimate Windows binaries that can perform download, execute, or compile actions useful to attackers.

Why it matters: Attackers blend into admin tooling (certutil, mshta, bitsadmin, etc.). Defenders need allow/block strategies and behavioral detection, not just malware hashes.

mDNS

Multicast DNS (often via Bonjour/Avahi) resolves names on a local link without a unicast DNS server. Common for printers, Chromecasts, and IoT.

Why it matters: Great for inventorying devices on a LAN you own; also reveals hostnames and services that users did not realize were advertised.

MFA (Multi-Factor Authentication)

Requiring two or more independent factors (something you know, have, or are) to authenticate.

Why it matters: Stops many password-only attacks. Prefer phishing-resistant factors (security keys) for high-value accounts; watch for MFA bypass paths.

MITRE ATT&CK

A knowledge base of adversary tactics and techniques used to describe, detect, and emulate real-world attack behaviors.

Why it matters: Gives a shared language for operators, hunters, and reports. Map lab exercises to techniques to build detection coverage deliberately.

NBT-NS (NetBIOS Name Service)

Legacy Windows name resolution over UDP 137. Often coexists with LLMNR as a fallback when DNS is unavailable.

Why it matters: Like LLMNR, it enables poisoning attacks on local networks. Prefer DNS and disable legacy name resolution where possible.

Network segmentation

Dividing networks into zones with controlled traffic between them (VLANs, firewalls, security groups) so compromise of one zone does not freely reach others.

Why it matters: One of the highest-ROI defenses for homes and enterprises. Pair with identity controls; segmentation alone is not enough.

NTLM

A family of Windows authentication protocols and challenge-response mechanisms. Still widely present for compatibility even when Kerberos is preferred.

Why it matters: NTLM is relayable and phishable in many configurations. Prefer Kerberos, disable NTLM where feasible, and enforce signing/channel binding.

Offline hash cracking

Recovering plaintext from captured password hashes using dictionaries, rules, and masks on CPU/GPU without touching the live login service.

Why it matters: Once hashes leak, time favors the attacker with GPUs. Use strong unique passwords and modern KDFs (bcrypt/argon2/scrypt) for stored passwords.

OPSEC (Operations Security)

Practices that protect operational details — for red teams, reducing unnecessary detection; for everyone, protecting secrets and methodologies from misuse.

Why it matters: In professional tests, OPSEC is negotiated with the client (some want noisy purple tests). Never use OPSEC as an excuse for unauthorized activity.

OSINT

Open-Source Intelligence — gathering information from public sources (DNS, certs, social, code repos, search engines) without interacting invasively with the target.

Why it matters: Often reveals exposed assets and employee patterns before active scanning. Stay within laws and platform terms; no doxxing.

OWASP Top 10

A periodically updated awareness document listing the most critical web application security risks, currently referenced as the 2021 edition in many programs.

Why it matters: Common reporting taxonomy for web findings. Use it to structure tests, not as a complete checklist of all possible bugs.

Passive reconnaissance

Recon that avoids direct interaction with the target infrastructure, relying on third-party data and historical sources.

Why it matters: Lower risk of disruption and detection; good first step on production engagements.

Password spraying

Trying a small number of common passwords across many accounts to avoid per-account lockouts that pure brute force would trigger.

Why it matters: Effective against large directories with weak passwords. Defenses: MFA, smart lockout, banned-password lists, detection of low-and-slow failures.

Pivoting

Using a compromised host as a hop to reach otherwise inaccessible network segments, often via tunnels or proxy chains.

Why it matters: Internal networks are rarely flat in practice. Operators document topology; defenders watch for unusual tunnel listeners and multi-hop admin paths.

Privilege escalation

Moving from a lower-privileged context to a higher one (e.g., user to root/SYSTEM or to domain admin) via misconfig or vulnerability.

Why it matters: Many engagements require proving admin impact. Defenders should assume breach and limit local admin and attack paths.

Purple teaming

Collaborative exercises where offensive techniques are run with defenders actively detecting and improving controls in a feedback loop.

Why it matters: Turns red findings into durable detection and hardening. Ideal for home labs and mature organizations alike.

Reconnaissance

Information gathering phase before or during an engagement — passive (OSINT) or active (scanning) — to map attack surface.

Why it matters: Good recon prevents blind exploitation and reduces unnecessary noise. Passive-first is often kinder to production systems.

rockyou.txt

A large password dictionary derived from a historic breach, commonly used for offline cracking practice and baseline password audits.

Why it matters: If rockyou cracks a hash quickly, the password was weak. Never use leaked corp passwords outside authorized handling rules.

RTSP

Real Time Streaming Protocol — commonly used by IP cameras to control and deliver video streams (often on TCP 554).

Why it matters: Open or weakly authenticated RTSP is a frequent camera finding. Prove risk on owned devices, then enforce auth, firmware updates, and VLAN isolation.

Rules of Engagement (RoE)

Written constraints for a security test: scope (IPs, domains, apps), allowed techniques, testing windows, emergency contacts, data handling, and stop conditions.

Why it matters: Without RoE, even skilled testing can become unauthorized access. RoE protects the client, the tester, and bystanders.

Scope

The explicit set of systems, accounts, and techniques that are in bounds for testing. Everything else is out of scope by default.

Why it matters: Scope creep causes legal and operational risk. Discovering adjacent assets is useful — exploiting them without approval is not.

SecLists

A well-known collection of security testing wordlists and payloads maintained for practitioners and packaged on many pentest distros.

Why it matters: Standard paths make training materials reproducible. Know where lists live on Kali/Parrot and when not to use the largest ones.

Severity

A rating of how bad a finding is, combining impact and exploitability in context (not CVSS alone).

Why it matters: Wrong severity either panics stakeholders or buries critical issues. Calibrate to business context and exposure.

Shellcode

Compact machine code payload traditionally used to spawn a shell or stage a larger implant after exploitation of memory corruption bugs.

Why it matters: Understanding shellcode helps with exploit development labs and with detecting unbacked executable memory. Keep practice in controlled labs.

SMB

Server Message Block — Windows file/printer sharing and remote administration protocol, commonly on TCP 445 (and legacy 139).

Why it matters: Central to Windows lateral movement, share exposure, and ransomware paths. Signing, least privilege, and patching matter enormously.

SPN (Service Principal Name)

Identifier that maps a service instance to a domain account. Kerberos uses SPNs when requesting service tickets.

Why it matters: SPNs on user accounts are Kerberoast targets. Inventory SPNs during AD assessments and avoid unnecessary user-account SPNs.

SQL injection

Injection flaw where untrusted input is interpreted as SQL, allowing query logic change, data theft, or sometimes OS command execution via DB features.

Why it matters: Still appears in legacy and custom apps. Parameterized queries and least-privilege DB accounts are the durable fixes.

SSRF (Server-Side Request Forgery)

A vulnerability where the server makes HTTP or other requests based on attacker-influenced URLs, potentially reaching internal systems or cloud metadata.

Why it matters: SSRF turns the server into a proxy into trusted networks. Critical in cloud due to instance metadata services.

SUID (Set-user-ID)

Unix file permission bit that runs an executable with the file owner's privileges (often root) regardless of who launched it.

Why it matters: Misconfigured SUID binaries are classic Linux privesc. Inventory SUID files and remove unnecessary bits; check GTFOBins for abuse patterns.

UPnP

Universal Plug and Play — protocols that let devices discover each other and request router port mappings automatically.

Why it matters: Malware and buggy apps can open WAN ports without the owner noticing. Auditing UPnP mappings is a standard home-lab hardening step.

VLAN

Virtual LAN — logical separation of layer-2 broadcast domains on shared switching infrastructure, tagged with 802.1Q IDs.

Why it matters: Segmentation (e.g., IoT vs trusted workstations) limits blast radius. Misconfigured trunks and weak access controls undermine the model.

VLAN hopping (concept)

Techniques that attempt to reach frames in another VLAN, historically via switch spoofing or double tagging on misconfigured ports. Modern switched networks with correct access/trunk config largely mitigate classic variants.

Why it matters: Understand the concept to configure switches safely; do not assume VLANs are a hard security boundary without defense-in-depth. Test only on lab or authorized infrastructure.

Wordlist

A dictionary of candidate strings used for content discovery, password attacks, fuzzing, or username enumeration.

Why it matters: List quality and size trade coverage versus noise and lockout risk. Start small; escalate deliberately under RoE.

WPS

Wi-Fi Protected Setup — convenience feature for joining wireless networks, often via PIN or push-button.

Why it matters: PIN-based WPS has known practical attacks on many consumer APs. Disable WPS on networks you administer unless you fully trust the implementation.

Zero trust

Security model that assumes no implicit trust based on network location; access is continuously verified based on identity, device, and policy.

Why it matters: Motivates MFA, microsegmentation, and least privilege. Complementary to, not a replacement for, patching and monitoring.