Plain-English definitions

The security glossary, written by practitioners

Fifty-seven terms defined the way an experienced analyst would explain them to a colleague — precise, unhedged, and honest about where the industry uses a word loosely. No definition here exists to sell you something.

How to use this glossary

Definitions are written to be useful in an argument with a vendor, an auditor or a board. Where a term is genuinely contested — XDR is the obvious example — we say so rather than pretending consensus exists.

Terms link to the part of the Guardian platform or the research that treats them in depth, so a definition can become a decision.

Orientation

How these terms fit together in a real intrusion

Most glossary entries below describe one moment in the same story. This is the order they usually happen in, with the median timing Guardian Labs observed across 41,308 hands-on-keyboard intrusions in 2025.

guardian-labs / intrusion-lifecycle
Reconnaissance Initial access Execution Escalation Lateral movement Exfiltration Impact Days to weeks Phishing, valid accounts Fileless, LOTL Kerberoasting 41 min median Sanctioned channels Ransomware Detection window — where dwell time is decided Containment window — before impact becomes irreversible Every term in this glossary describes one of these stages, one of the controls that interrupts it, or one of the measurements defenders use to know whether they interrupted it in time. Source: Guardian Labs, 2026 Global Threat Landscape Report.

A to Z

Fifty-seven terms, defined

A

Advanced persistent threat (APT)
A well-resourced adversary — usually state-sponsored or state-tolerated — that maintains long-term covert access to a target in pursuit of strategic objectives such as espionage, intellectual property theft or pre-positioning in critical infrastructure. The defining characteristic is persistence and patience, not sophistication; many APT intrusions begin with an ordinary phishing email. See threat intelligence.
Attack surface
The complete set of points at which an unauthorised party could attempt to enter an environment or extract data from it: internet-facing services, applications, identities and their permissions, APIs, unmanaged devices and third-party connections. Attack surface grows continuously; the practical goal is knowing about it before an adversary does.
Attack path
A chain of individually low-severity weaknesses — an over-permissive role here, an unpatched host there, a forgotten trust relationship — that together form a route from an exposed entry point to a critical asset. Attack path analysis is valuable because it identifies the single change that breaks the largest number of paths, which is rarely the highest-scoring vulnerability on the list.

B

Botnet
A network of compromised devices under the remote control of a single operator, used for distributed denial-of-service attacks, credential stuffing, proxying malicious traffic through residential addresses, or distributing further malware. Consumer routers and IoT devices dominate modern botnets because they are numerous, rarely patched and almost never monitored.
Breakout time
The interval between an adversary compromising their first host and their first successful lateral move to a second system. It is the defender's real budget: detect and contain inside it and you have an isolated compromise, miss it and you have an enterprise incident. Guardian Labs measured a median of 41 minutes in 2025, down from 98 minutes in 2021.
Business email compromise (BEC)
Fraud in which an adversary impersonates or takes over a trusted mailbox — a finance executive, a supplier, a lawyer mid-transaction — to induce a payment or a data transfer. BEC typically involves no malware and no malicious link, which is why attachment scanning and link rewriting rarely stop it and why identity signals matter more than email content.

C

Command and control (C2)
The infrastructure and channel an adversary uses to issue instructions to compromised systems and retrieve results. Contemporary C2 hides inside legitimate services — collaboration platforms, cloud storage, content delivery networks, DNS — so blocking by destination reputation is largely obsolete and detection has shifted to beacon timing, volume and process lineage.
Credential stuffing
Automated replay of username and password pairs stolen from one breach against unrelated services, exploiting the fact that people reuse passwords. It is distinguishable from brute force because every credential tried is already valid somewhere, so lockout thresholds and complexity policies do nothing to stop it.
Cloud security posture management (CSPM)
Continuous evaluation of cloud configuration against a security baseline — public storage buckets, over-permissive roles, disabled audit logging, unencrypted volumes — with drift detection and remediation guidance. Posture management is necessary and insufficient: it describes how an environment is configured, never what is currently executing inside it. See cloud security.

D

Data loss prevention (DLP)
Controls that identify sensitive data by content, context or lineage and then restrict how it moves — blocking an upload, encrypting a message, quarantining a file, revoking a share. The success of a DLP programme is determined almost entirely by classification accuracy; a perfect enforcement engine acting on bad labels produces noise and workarounds. See data protection.
Defence in depth
An architectural principle of layering independent controls so that the failure or bypass of any single one does not result in compromise. The important word is independent: five controls that share the same blind spot, the same telemetry source or the same administrative credential are one control wearing five badges.
Dwell time
The total period an adversary is present in an environment before being detected and evicted, measured from initial compromise to verified containment. It is the single most predictive variable in eventual incident cost, because almost every expensive consequence — data staged, backups mapped, credentials harvested — accumulates during it.

E

Endpoint detection and response (EDR)
Continuous recording of endpoint activity — process execution, file and registry changes, network connections, script content — combined with behavioural detection and remote response such as process termination, file quarantine and host isolation. EDR answers "what happened on this machine, in order"; prevention-only antivirus cannot. See endpoint security.
Exploit
Code or a technique that takes advantage of a specific vulnerability to cause unintended behaviour, usually code execution or privilege escalation. The distinction matters in prioritisation: a vulnerability is a flaw that might be usable, an exploit is proof that it is, and a weaponised exploit in a commodity toolkit is a different risk entirely.
Exfiltration
The unauthorised transfer of data out of an environment. Modern exfiltration deliberately uses sanctioned channels — corporate cloud sync clients, developer tooling, collaboration platforms, DNS — precisely because those paths are permitted, encrypted and rarely inspected. Volume anomalies against a per-identity baseline usually detect it faster than destination blocking.

F

False positive
A detection that fires on benign activity. The real cost is not the wasted minutes; it is that sustained false-positive rates train analysts to dismiss a detection class, which is how a genuine alert gets closed as noise. Detection quality should always be reported as a pair — true positive rate and false positive rate — never as a coverage count.
Fileless malware
Malicious activity that executes in memory or through built-in scripting and administration tooling without ever writing an executable to disk. It defeats any control that depends on scanning files, which is why behavioural detection and in-memory inspection became mandatory rather than advanced capabilities.

G

Golden ticket attack
Forgery of a Kerberos ticket-granting ticket using the compromised KRBTGT account hash, allowing an adversary to impersonate any principal in an Active Directory domain — including domain administrators — with tickets the domain controller will accept as legitimate. Recovery requires rotating the KRBTGT password twice, and until that happens the adversary retains domain-wide access regardless of password resets elsewhere.

H

Hardening
Systematically reducing an asset's attack surface before it comes under attack: removing unnecessary services and software, disabling legacy protocols, closing default accounts, enforcing secure configuration and applying least privilege. Hardening is unglamorous and reliably outperforms detection tooling bought to compensate for its absence.
Honeypot
A deliberately exposed decoy — a system, service, credential or document — whose only purpose is to be touched by an adversary. Because no legitimate user has any reason to interact with it, interaction is exceptionally high-confidence evidence of compromise. Well-placed decoy credentials in a directory are among the cheapest high-fidelity detections available.

I

Indicator of compromise (IOC)
An observable artefact that suggests an intrusion has occurred: a file hash, domain, IP address, mutex or registry key. IOCs are precise and cheap for an adversary to change — a new hash costs a recompile — so detection built solely on indicators ages within days. They remain valuable for retrospective hunting across historical telemetry.
Identity threat detection and response (ITDR)
Detection and containment focused on the identity layer: credential theft, session token replay, privilege escalation paths, directory manipulation and abuse of federation trust. Response actions are identity-native — revoke a session, force re-authentication, disable a token, roll a key — rather than host-native. See identity protection.
Incident response (IR)
The disciplined process of preparing for, detecting, containing, eradicating and recovering from a security incident, followed by structured lessons learned. The preparation phase determines the outcome of all the others; organisations that first write their plan during an incident reliably lose days. See our incident response service.

J

Jump server
A hardened, heavily monitored intermediate host through which all administrative access to a sensitive segment must pass. It concentrates privileged activity where it can be recorded and controlled — and, by the same logic, makes itself the single most valuable target in the environment, which is why session recording and independent monitoring of the jump host are not optional.

K

Kerberoasting
An attack in which any authenticated domain user requests Kerberos service tickets for accounts carrying a service principal name, then cracks those tickets offline to recover the service account password. It requires no elevated privilege to attempt and generates almost no unusual activity, which is why long random service account passwords and managed service accounts matter more than detection here.
Kill chain
A model describing the ordered stages of an intrusion, from reconnaissance through weaponisation, delivery, exploitation, installation and command and control to actions on objectives. Its enduring defensive value is simple: the adversary must complete every stage, while the defender only has to break one.

L

Lateral movement
An adversary's progression from an initially compromised system to other hosts, accounts or services in pursuit of their objective, typically using valid credentials and legitimate remote administration protocols. It is the moment an isolated compromise becomes an enterprise incident, and the reason breakout time is the metric that matters most.
Living off the land (LOTL)
Tradecraft that uses legitimate, pre-installed tooling — PowerShell, WMI, certutil, ssh, scheduled tasks, cloud command line interfaces — instead of custom malware. Because every binary used is signed, expected and already present, LOTL activity is indistinguishable from administration by artefact alone; only sequence, context and behaviour separate them.

M

MITRE ATT&CK
A publicly maintained knowledge base of adversary tactics, techniques and procedures observed in real intrusions, organised so that defenders and vendors can describe behaviour with a shared vocabulary. Used well, it is a coverage measurement framework; used badly, it is a heat map coloured in to reassure a board.
Multi-factor authentication (MFA)
Authentication requiring evidence from two or more independent categories: something known, something held, something inherent. The category distinction is what matters — a password plus a one-time code delivered to the same compromised session is one factor with extra steps. Phishing-resistant forms bind the credential to the origin; push approvals and codes do not, and are defeated routinely.
Managed detection and response (MDR)
A service in which an external team operates detection, triage, investigation and response on a customer's behalf, usually around the clock, with a defined escalation path and explicit containment authority. The authority is the differentiator: a service that can only notify you at 03:00 is monitoring, not response. See Guardian MDR.

N

Network detection and response (NDR)
Detection built on network telemetry — flow records, protocol metadata, certificate and encrypted traffic characteristics, DNS behaviour. Its unique value is coverage of everything that cannot run an agent: printers, cameras, medical devices, industrial controllers and any host the adversary has already blinded. See network security.
Network segmentation
Dividing a network into zones with enforced policy between them, so that compromise of one zone does not confer reachability to another. Microsegmentation applies the same principle at workload or process level. Segmentation is the control that converts a worm-capable ransomware event from an outage into an inconvenience.

O

OAuth consent phishing
An attack that persuades a user to grant a malicious application persistent, token-based access to their mailbox, files or directory data. No password is captured, so resetting credentials and enforcing MFA changes nothing — the malicious grant must be found and revoked explicitly, and the tokens it issued invalidated.

P

Phishing
Social engineering delivered by message that induces a recipient to disclose credentials, approve an authentication prompt or execute content. Spear phishing targets a named individual with researched context; whaling targets executives; adversary-in-the-middle phishing proxies the real login page so that the session token, not the password, is stolen.
Privilege escalation
Gaining rights beyond those originally held, either vertically — standard user to administrator, container to node, application role to subscription owner — or horizontally, into another peer's data. Vertical escalation is almost always the pivot point that converts an annoying intrusion into a serious one.
Penetration testing
An authorised, scoped assessment in which testers attempt to exploit weaknesses to demonstrate real impact. It differs from vulnerability scanning, which enumerates potential weaknesses without proving exploitability, and from red teaming, which measures whether you detect and respond rather than what can be found. See penetration testing.

Q

Quarantine
Isolating a file, message, device or identity so it can no longer act or be acted upon, while preserving it intact for investigation. Host quarantine normally maintains a management channel so responders keep access to the machine they just cut off — containment that also locks out the investigator is a self-inflicted outage.

R

Ransomware
An operation that denies an organisation access to its data or systems — by encryption, deletion, or the threat of publishing stolen data — in exchange for payment. A growing majority of operations now skip encryption entirely and extort on exfiltrated data alone, which means backup strategy no longer answers the whole question.
Red team
An adversary-simulation exercise measured by whether the defending organisation detects, investigates and responds — not by how many vulnerabilities are found. A purple team runs the same exercise collaboratively, with detection engineers in the room, and typically produces more durable improvement per day spent.
Role-based access control (RBAC)
Granting permissions to roles and roles to people, so entitlements can be assigned, reviewed and revoked as a coherent set rather than individually. Its characteristic failure is role sprawl: hundreds of near-duplicate roles accumulate until nobody can say what any of them confer, quietly reintroducing the excessive privilege RBAC was adopted to prevent.

S

Security information and event management (SIEM)
A platform that centralises log and event data for correlation, search, alerting, reporting and retention. A SIEM is only as good as the sources feeding it and the analytics written on top; the common failure mode is paying to store enormous volumes of telemetry that nothing ever queries.
Security orchestration, automation and response (SOAR)
Tooling that executes response workflows across other systems — enrich, decide, act, document — to remove repetitive analyst work. SOAR capability is increasingly absorbed into detection platforms rather than bought separately, because a playbook that has to re-query the data it is acting on is slower than one that already holds it. See automation and response.
Supply chain attack
Compromise of an organisation through a trusted third party: a signed software update, a build system, an open-source dependency, a managed service provider or a hardware component. Its economics are brutal — one successful intrusion yields access to every downstream customer, and the malicious change arrives through a channel the victim explicitly trusts.
Shadow IT
Technology adopted by a business unit without security or IT review. It is rarely malicious and usually a symptom of an internal process being too slow, but it reliably creates data flows, identities and integrations that appear in no inventory and no offboarding process.

T

Threat hunting
Proactive, hypothesis-driven investigation for adversary activity that existing detections have not fired on. A hunt that finds nothing is not a failed hunt, but a hunt that ends without producing a new detection or ruling out a hypothesis in writing is wasted effort — the output is coverage, not a feeling of diligence.
Threat intelligence
Analysed information about adversaries — who they are, what they target, how they operate and what they are likely to do next — produced to inform a specific decision. Raw indicator feeds are data, not intelligence; intelligence requires analysis, confidence assessment and an identified consumer. See threat intelligence.
Tactics, techniques and procedures (TTPs)
The behavioural signature of an adversary: their strategic goals (tactics), the general methods used to achieve them (techniques) and their specific implementation habits (procedures). TTPs are far more expensive for an adversary to change than infrastructure or tooling, which is why detections built on behaviour outlive detections built on indicators.

U

User and entity behaviour analytics (UEBA)
Analytics that model normal behaviour for each user, host and service account, then flag statistically significant deviation from that baseline. It is the most effective approach available for insider risk and credential misuse, where nothing technically prohibited occurs and only the pattern of activity gives the adversary away.

V

Vulnerability management
The continuous cycle of discovering, prioritising, remediating and verifying weaknesses across an estate. Mature programmes prioritise by exploitability in the wild and reachability from an exposed asset rather than by severity score alone, because a critical-rated flaw on an isolated internal host is genuinely less urgent than a medium-rated one on the perimeter.
Vishing
Social engineering conducted by voice call, increasingly using synthetic audio of a real colleague. The most productive target is the service desk, where the objective is a credential reset or the enrolment of an attacker-controlled MFA device. The effective control is a verification procedure the agent cannot be talked out of, not a technology purchase.

W

Watering hole attack
Compromise of a legitimate website known to be frequented by a target community — an industry association, a supplier portal, a regional news site — so that victims are attacked while doing something entirely routine on a site they have every reason to trust.
Worm
Malware that propagates automatically between systems without any user action, typically by exploiting a network-reachable vulnerability or reusing harvested credentials. Worm-capable ransomware is precisely why segmentation and containment speed are worth more than any single preventive control.

X

Extended detection and response (XDR)
Detection and response that correlates telemetry across endpoint, network, cloud, identity, email and data in one analytic layer, producing a single incident rather than six disconnected alerts. The term is genuinely contested: some products correlate natively across their own sensors, others federate alerts from third parties. Ask which one you are being sold, and ask to see two surfaces correlated in a live incident. See the Guardian platform.

Y

YARA rule
A pattern-matching rule format used to classify files, memory regions and network payloads by textual or binary content. YARA is the lingua franca for describing malware families and for retrospective hunting across previously collected samples, and rules travel between organisations far more easily than product-specific detection logic.

Z

Zero trust
An architectural model that removes implicit trust based on network location. Every request is authenticated, authorised and continuously evaluated against identity, device posture and behavioural signals, and every grant is the minimum necessary for the shortest useful time. It is a design principle, not a product, and no single vendor can sell you a finished one.
Zero-day vulnerability
A flaw exploited before a patch exists, giving defenders no remediation to apply. Genuine zero-day exploitation is rarer than headlines imply — the overwhelming majority of intrusions still use known, unpatched or simply misconfigured weaknesses — but when it happens, behavioural detection and containment speed are the only controls that still function.

Back to the top of the A–Z

Disambiguation

The five distinctions that cause the most expensive mistakes

These pairs are used interchangeably in marketing and are not interchangeable in an architecture. Getting them wrong produces overlapping spend and uncovered surfaces at the same time.

Which acronym covers which surface

EDR NDR ITDR XDR Endpoint Network Cloud workload Identity Data Filled = observes the surface directly. XDR adds correlation between them, which is the whole point.
EDR vs. XDR vs. MDR

EDR and XDR are technologies; MDR is a service. EDR observes one surface — the endpoint — in depth. XDR correlates several surfaces into a single incident. MDR is people operating either of them on your behalf, with agreed authority to contain. You can buy MDR delivered on top of XDR, and organisations frequently buy all three names from three vendors and end up with two.

SIEM vs. SOAR vs. XDR

A SIEM stores and searches; a SOAR acts; an XDR detects across surfaces. The overlap is real and growing, but the useful test is where the analytic logic and the raw telemetry live. If your detection platform has to query a separate store to make a decision, and a third system to act on it, your containment time is the sum of three round trips.

Vulnerability vs. exploit vs. zero-day

A vulnerability is a flaw. An exploit is a working method of using it. A zero-day is a vulnerability being exploited before a fix exists. Prioritisation should follow that ladder: a vulnerability with no known exploit and no reachable path from an exposed asset is a backlog item, not an incident, regardless of its severity score.

IOC vs. TTP

An indicator is a fact — this hash, that domain. A TTP is a behaviour — how this adversary escalates privilege. Indicators are precise and perishable; behaviours are fuzzy and durable. A detection programme built only on indicators looks excellent in a proof of concept and degrades within a fortnight of real use.

Dwell time vs. breakout time vs. MTTC

Breakout time is the adversary's speed — how long from first host to first lateral move. Mean time to contain is your speed — from first malicious observable to verified containment. Dwell time is the total damage window, from initial compromise to eviction. If your MTTC exceeds the median breakout time, you are structurally arriving after the incident has already spread.

Related

Where to take these terms next

Whitepapers

The research behind the numbers quoted in these definitions, including the breakout time and dwell time methodology.

Read the research

Webinars

Live demonstrations of the techniques defined here, including token theft and Kubernetes runtime attacks.

See the sessions

Case studies

What these metrics look like in production environments that measured themselves before and after.

See the outcomes

Training

Analyst certification and workforce awareness programmes that teach this vocabulary in context rather than as flashcards.

Explore training
A term missing, or a definition you would argue with? We revise this glossary quarterly and credit corrections. Tell us what we got wrong — disagreement from practitioners is the main reason these entries have improved.

See the vocabulary in a live environment

Breakout time, lateral movement, containment — all of it looks different on a console showing your own telemetry. A Guardian engineer will walk you through it.