Cyber 101
Name that Port
What the Phish?
Hack Attack
Cyber Wild Card
100

The 3 pillars of the CIA Triad

Confidentiality

Integrity

Availability

100

Standard HTTP traffic normally uses this port.

Port 80

100

Fraudulent messages pretending to come from a trusted organization are sent to steal credentials.

What is Phishing

100

An attacker uses many compromised computers to overwhelm a website with traffic and make it unavailable.

DDOS (Deliberate Denial of Service)

100

"Department" of a centralized team or facility responsible for monitoring an organization's IT infrastructure around the clock to detect, analyze, and respond to cybersecurity threats

SOC (Security Operations Center)

200

A weakness in a system that could potentially be exploited by an attacker.

A vulnerability

200

Secure HTTPS traffic normally uses this port.

Port 443

200

An attacker creates a phishing message specifically for one person or organization rather than sending thousands of generic messages.

Spear Phishing

200

This malware encrypts a victim's files and demands payment to restore acsess

Ransomware

200

This Linux distribution is widely used for penetration testing and includes tools such as Nmap and Metasploit.

Kali Linux

300

This principle says users should receive only the permissions necessary to perform their job.

Least Privilege

300

This secure remote-access protocol normally uses TCP port 22.

What is SSH

300

A phishing attack specifically targeting executives or other high-ranking individuals.

Whaling

300

An attacker enters malicious database commands into an application’s input field.

SQL Injection

300

Digital Forensic Investigators calculate this cryptographic value to verify that digital evidence has not changed.

Hash Value (MD5 or SHA-256)

400

This security philosophy assumes no user or device should automatically be trusted, even when inside the network.

Zero trust

400

DNS normally uses this port for queries and can operate over UDP or TCP.

Port 53

400

A malicious phone call where the caller is attempting to impersonate someone the victim knows.

Vishing

400

This web attack injects malicious client-side scripts into pages viewed by other users.

XSS (Cross Site Scripting)

400

This popular network reconnaissance tool can discover hosts, scan ports, and identify running services.

NMAP

500

System used to monitor a company's network to determine if a bad actor has managed to infiltrate the network based on rules, patterns, and Network logs

IDS (Intrusion Detection System)

500

You discover inbound TCP connections to port 3389. This Windows remote-access protocol is probably being used.

Remote Desktop (RDP)

500

A malicious text message claims your bank account has been locked and provides a link to "verify" your account.

smishing

500

This 2017 ransomware outbreak spread around the world using the EternalBlue exploit.

WannaCry

500

This Windows authentication protocol replaced LM and NTLM in Active Directory environments and relies on tickets issued by a Key Distribution Center.

Kerberos 

M
e
n
u