The 3 pillars of the CIA Triad
Confidentiality
Integrity
Availability
Standard HTTP traffic normally uses this port.
Port 80
Fraudulent messages pretending to come from a trusted organization are sent to steal credentials.
What is Phishing
An attacker uses many compromised computers to overwhelm a website with traffic and make it unavailable.
DDOS (Deliberate Denial of Service)
"Department" of a centralized team or facility responsible for monitoring an organization's IT infrastructure around the clock to detect, analyze, and respond to cybersecurity threats
SOC (Security Operations Center)
A weakness in a system that could potentially be exploited by an attacker.
A vulnerability
Secure HTTPS traffic normally uses this port.
Port 443
An attacker creates a phishing message specifically for one person or organization rather than sending thousands of generic messages.
Spear Phishing
This malware encrypts a victim's files and demands payment to restore acsess
Ransomware
This Linux distribution is widely used for penetration testing and includes tools such as Nmap and Metasploit.
Kali Linux
This principle says users should receive only the permissions necessary to perform their job.
Least Privilege
This secure remote-access protocol normally uses TCP port 22.
What is SSH
A phishing attack specifically targeting executives or other high-ranking individuals.
Whaling
An attacker enters malicious database commands into an application’s input field.
SQL Injection
Digital Forensic Investigators calculate this cryptographic value to verify that digital evidence has not changed.
Hash Value (MD5 or SHA-256)
This security philosophy assumes no user or device should automatically be trusted, even when inside the network.
Zero trust
DNS normally uses this port for queries and can operate over UDP or TCP.
Port 53
A malicious phone call where the caller is attempting to impersonate someone the victim knows.
Vishing
This web attack injects malicious client-side scripts into pages viewed by other users.
XSS (Cross Site Scripting)
This popular network reconnaissance tool can discover hosts, scan ports, and identify running services.
NMAP
System used to monitor a company's network to determine if a bad actor has managed to infiltrate the network based on rules, patterns, and Network logs
IDS (Intrusion Detection System)
You discover inbound TCP connections to port 3389. This Windows remote-access protocol is probably being used.
Remote Desktop (RDP)
A malicious text message claims your bank account has been locked and provides a link to "verify" your account.
smishing
This 2017 ransomware outbreak spread around the world using the EternalBlue exploit.
WannaCry
This Windows authentication protocol replaced LM and NTLM in Active Directory environments and relies on tickets issued by a Key Distribution Center.
Kerberos