Skip to main content

Reference

Cybersecurity Glossary

Clear definitions of 78+ threat intelligence, cybersecurity and AI agent security terms — from IOCs and TTPs to CVSS, EPSS, the CISA KEV catalog and prompt injection.

Threat Intelligence

Observable

An observable is a domain, IP address, URL, file hash, email address, phone number, or wallet address that can be examined during a security investigation. A submitted observable is not automatically malicious and is not automatically an indicator of compromise.

Indicator

An indicator is an observable whose evidence makes it relevant to a security investigation or detection. It becomes an indicator of compromise only when the evidence supports compromise or malicious activity.

IOC (Indicator of Compromise)

An indicator of compromise is an indicator supported by evidence of compromise or malicious activity. Security teams use IOCs to detect, contain, and investigate threats; an arbitrary IP address, domain, URL, file hash, or email address is only an observable until evidence supports that promotion.

Threat Intelligence

Threat intelligence is evidence-based knowledge about cyber threats, including observed infrastructure, behaviors, campaigns, and likely intent. It combines source observations with context so security teams can make a specific detection, triage, containment, or response decision.

TTP (Tactics, Techniques, and Procedures)

TTPs describe the behavior of threat actors: the high-level goals they pursue (tactics), the specific methods they use to achieve those goals (techniques), and the detailed, repeatable actions that implement those methods (procedures). The MITRE ATT&CK framework catalogues TTPs used by real adversaries.

Threat Feed

A threat feed is a structured, continuously updated stream of IOCs and threat data from a single source or aggregator. Security tools ingest threat feeds to keep blocklists and detection rules current. Examples include Spamhaus DROP, abuse.ch URLhaus, and CISA KEV.

Dark Web

The dark web is a portion of the internet accessible only through anonymizing networks like Tor. It hosts illicit marketplaces, ransomware leak sites, stolen credential databases, and threat actor forums. Monitoring dark web sources provides early warning of breaches and planned attacks.

Threat Actor

A threat actor is any individual, group, or organization that conducts malicious cyber activity. Threat actors are classified by motivation (financial, espionage, hacktivism), capability (nation-state, organized crime, script kiddie), and targeting patterns. Attribution helps predict future attack patterns.

Threat Hunting

Threat hunting is the proactive, human-led search for threats that automated security tools have not detected. Hunters form hypotheses about attacker behavior, then query security telemetry (logs, EDR data, network flows) to confirm or refute them using TTPs from frameworks like MITRE ATT&CK.

Confidence Score

A confidence score quantifies how certain a threat intelligence system is that an indicator is malicious, given the evidence. isMalicious weights source signals by reliability, compares agreement and conflicts, and applies time decay to older observations.

SIEM (Security Information and Event Management)

A SIEM aggregates, normalizes, and correlates log data from across an organization's infrastructure to detect threats and support incident response. Popular SIEMs include Splunk, Microsoft Sentinel, and Elastic Security. Threat intelligence enrichment significantly improves SIEM detection accuracy.

SOC (Security Operations Center)

A Security Operations Center is a team (and facility) responsible for continuously monitoring, detecting, investigating, and responding to cybersecurity incidents. SOC analysts rely on threat intelligence, SIEM platforms, and playbooks to triage alerts efficiently.

Incident Response

Incident response (IR) is the structured process of detecting, containing, eradicating, and recovering from a security incident, then conducting a post-incident review to prevent recurrence. The SANS PICERL model defines six phases: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.

False Positive

A false positive in threat intelligence is a benign indicator incorrectly classified as malicious. High false positive rates waste analyst time and cause legitimate traffic to be blocked. isMalicious uses multi-source correlation and reliability weighting to minimize false positives below 0.1% for high-confidence verdicts.

False Negative

A false negative is a genuinely malicious indicator that a security system fails to detect or classify as a threat. False negatives are more dangerous than false positives because they allow real attacks to pass undetected. Coverage across multiple threat feeds reduces false negative rates.

Initial Access Broker (IAB)

An initial access broker is a threat actor or service that sells footholds — compromised VPN credentials, RDP access, or web shells — to other criminals who deploy ransomware or data theft. Tracking IAB infrastructure helps prioritize blocking and hunting before payloads land.

Indicator Aging

Indicator aging is the process of reducing confidence or removing stale IOCs from blocklists as infrastructure is retaken, sinkholed, or reassigned. Without aging, blocklists accumulate false positives and block legitimate services on recycled IPs.

Lateral Movement

Lateral movement is the phase of an intrusion in which an attacker, having compromised one machine, moves to others inside the same network to reach the data or systems that were the actual target. It relies on stolen credentials, remote administration protocols and trust between hosts rather than on new exploits.

Domain Intelligence

Domain intelligence is the body of evidence about a domain name: when and where it was registered, who operates its nameservers, what it has resolved to over time, what certificates it has carried, which sources list it and for what activity. It is the domain-side counterpart of IP intelligence and the more durable of the two, because names persist while addresses rotate.

IP Intelligence

IP intelligence is the evidence available about an IP address: the network that announces it, its geography, its classification (datacenter, residential, mobile, VPN, proxy, Tor), the names that have pointed at it, and its record across abuse and threat sources with dates. It describes where something is hosted right now, which is exactly what a firewall or a rate limiter needs to know.

Malware & Attacks

Ransomware

Ransomware is malware that encrypts a victim's files or systems and demands payment (usually cryptocurrency) for the decryption key. Modern ransomware groups also exfiltrate data before encrypting and threaten to publish it — a tactic called double extortion.

C2 (Command and Control)

A Command and Control server is infrastructure used by attackers to remotely control compromised hosts (a botnet) and deliver instructions, exfiltrate data, or push malware updates. Blocking C2 communications is one of the most effective ways to disrupt an active attack.

Botnet

A botnet is a network of compromised devices ("bots") controlled by an attacker via a C2 server. Botnets are used for DDoS attacks, spam campaigns, credential stuffing, and ransomware delivery. Individual bots are often unaware they are compromised.

Malware

Malware is any software designed to harm, exploit, or gain unauthorized access to a system. It includes viruses, worms, trojans, ransomware, spyware, adware, rootkits, and more. Detection relies on file hashes, behavioral signatures, and threat intelligence feeds.

Phishing

Phishing is a social engineering attack that tricks users into revealing credentials, clicking malicious links, or downloading malware — typically via email. Spear phishing targets specific individuals; smishing uses SMS; vishing uses voice calls.

Double Extortion

Double extortion is a ransomware tactic where attackers both encrypt and exfiltrate victim data, then threaten to publish the stolen data on a leak site if the ransom is not paid. This creates pressure on victims even if they have functional backups.

Trojan

A Trojan is malware that disguises itself as legitimate software to trick users into installing it. Unlike viruses, Trojans do not self-replicate; they rely on social engineering. Once installed, they may install backdoors, steal credentials, or drop additional malware.

Credential Stuffing

Credential stuffing is an automated attack where stolen username/password pairs from one data breach are tested against other services, exploiting the widespread habit of password reuse. It is distinct from brute force because it uses real credentials rather than guessing.

Supply Chain Attack

A supply chain attack targets the software or hardware supply chain rather than the end victim directly. Attackers compromise a trusted supplier — a software library, build system, or hardware manufacturer — to inject malicious code that is then distributed to thousands of downstream users.

Infostealer

An infostealer is malware designed to exfiltrate credentials, cookies, browser sessions, and cryptocurrency wallets from infected endpoints. Infostealer logs are a major source of initial-access credentials sold on criminal markets and linked to follow-on ransomware.

C2 Infrastructure

Command-and-control (C2) infrastructure is the server, domain, or cloud resource malware uses to receive instructions and exfiltrate data. Blocking C2 IPs and domains at the firewall and DNS layer disrupts active infections before lateral movement.

Phishing Kit

A phishing kit is a pre-built package of HTML templates, credential capture scripts, and anti-detection code sold to low-skill attackers. Kits often reuse the same hosting paths and file hashes, making them detectable via URL and hash reputation feeds.

Polymorphic Malware

Polymorphic malware changes its own code or packaging on each infection or each build so that no two samples share a file hash or a static signature, while the behaviour stays the same. It defeats hash-based blocklists and forces detection onto behaviour, network indicators and the infrastructure the samples share.

Network & Infrastructure

IP Reputation

IP reputation is a score or classification indicating whether an IP address has been associated with malicious activity. Factors include appearance on blocklists, volume of spam sent, history of port scanning, C2 hosting, and abuse reports.

Blocklist (Denylist)

A blocklist is a list of IPs, domains, URLs, or file hashes known to be malicious. Firewalls, DNS resolvers, and email gateways use blocklists to automatically block traffic from known bad actors. Blocklists must be kept current to remain effective.

ASN (Autonomous System Number)

An Autonomous System Number identifies a collection of IP address ranges under the control of a single organization (an Internet Service Provider, cloud provider, or enterprise). ASNs are used in threat intelligence to identify hosting providers commonly used by attackers.

NRD (Newly Registered Domain)

A Newly Registered Domain is a domain registered within the past 30–90 days. NRDs are a key risk signal because the vast majority of phishing campaigns, malware distribution, and spam infrastructure uses freshly registered domains to evade blocklists.

DNS History

DNS history is a record of historical DNS resolution data for a domain — including all IP addresses it has ever resolved to, when changes occurred, and what nameservers have been used. It is used in threat investigations to trace infrastructure reuse and identify related malicious domains.

Reverse IP Lookup

Reverse IP lookup returns all domain names hosted on a given IP address. It is used by threat hunters to identify other malicious domains sharing the same hosting infrastructure as a known bad actor — a technique known as infrastructure pivoting.

Domain Reputation

Domain reputation is a classification of a domain based on its history of malicious activity, registration patterns, and content. Factors include age, registrar, phishing/malware associations, WHOIS data, and appearance on threat feeds.

WHOIS

WHOIS is a protocol that returns registration information for a domain or IP address — including registrant, registrar, registration and expiration dates, and nameservers. Threat analysts use WHOIS to investigate ownership, identify registration patterns of malicious actors, and find related infrastructure.

DNS (Domain Name System)

The Domain Name System translates human-readable domain names (like ismalicious.com) into IP addresses. DNS data is a rich source of threat intelligence — malicious domains, fast-flux networks, DNS tunneling, and typosquatting are all detectable via DNS analysis.

Fast Flux

Fast flux is a DNS technique used by attackers to rapidly change the IP addresses associated with a domain — sometimes cycling through hundreds of IPs within minutes. It is used to make C2 servers and phishing sites resistant to IP-based blocking and takedowns.

Typosquatting

Typosquatting (also called URL hijacking) registers domains that are slight misspellings of legitimate websites to capture traffic from users who make typing errors. These domains are often used for phishing, malware distribution, or ad fraud.

Sinkhole

A sinkhole is a controlled destination that security researchers or law enforcement redirect malicious traffic to — often for botnet takedowns. Sinkholed domains and IPs may still appear on threat feeds during transition periods; enrichment context helps avoid blocking legitimate sinkhole operators.

Passive DNS

Passive DNS records historical resolutions between domain names and IP addresses collected from recursive resolvers and sensors. Analysts use passive DNS to pivot from a malicious IP to related domains, identify fast-flux patterns, and timeline infrastructure changes.

ASN Reputation

ASN reputation assesses whether an Autonomous System Number — the network block announcing an IP range — has a history of hosting abuse, bulletproof providers, or residential versus datacenter traffic. It contextualizes IP verdicts when the same IP moves between benign and hostile ASNs.

Bulletproof Hosting

Bulletproof hosting providers ignore abuse complaints and allow criminals to host phishing kits, C2 servers, and malware distribution with minimal takedown response. IPs and domains on bulletproof ASNs receive elevated risk scores in threat intelligence platforms.

ISP (Internet Service Provider)

An ISP provides internet connectivity to consumers and businesses. In threat intelligence, ISP context for an IP address indicates whether it is a residential, commercial, or hosting IP — a key factor in risk scoring, since hosting IPs are far more likely to be malicious.

URL Hijacking

URL hijacking is the family of techniques that capture traffic meant for a legitimate web address by registering or taking over a look-alike one. It covers typosquatting (misspellings), homoglyph domains (look-alike Unicode characters), combosquatting (a brand plus a plausible word) and the takeover of expired domains that still receive links and visitors.

DGA (Domain Generation Algorithm)

A domain generation algorithm is code inside malware that produces a large list of domain names from a seed such as the date, so that the infected host can find its command server by trying names until one resolves. The operator, who knows the algorithm, registers only a few of the day’s names, and defenders cannot block a list they cannot predict.

Vulnerabilities

EPSS (Exploit Prediction Scoring System)

EPSS is a data-driven model from FIRST.org that estimates the probability a CVE will be exploited in the wild within the next 30 days. Scores range from 0 to 1 (0%–100%). EPSS helps prioritize patching by combining NVD data with real-world exploitation observations.

CVSS (Common Vulnerability Scoring System)

CVSS is an open framework for communicating the severity of software vulnerabilities. A CVSS v3 base score from 0 to 10 reflects factors like attack vector, complexity, privileges required, and impact on confidentiality, integrity, and availability. Scores ≥ 9.0 are Critical; ≥ 7.0 are High.

CVE (Common Vulnerabilities and Exposures)

CVE is a public catalogue of known cybersecurity vulnerabilities, maintained by MITRE and sponsored by CISA. Each entry has a unique CVE ID (e.g., CVE-2024-12345), a description, and references. CVE IDs are the universal language for tracking and patching specific vulnerabilities.

KEV (CISA Known Exploited Vulnerabilities)

The CISA KEV catalog lists CVEs that have been confirmed as actively exploited in the wild. US federal agencies are required to patch KEV vulnerabilities by mandated due dates. KEV status is the highest-urgency signal for vulnerability prioritization.

SBOM (Software Bill of Materials)

An SBOM is a formal inventory of all software components and dependencies in an application — similar to an ingredient list. SBOMs are used to rapidly identify which systems are affected when a vulnerability (like Log4Shell) is discovered in a common dependency.

SSVC (Stakeholder-Specific Vulnerability Categorization)

SSVC is a decision-tree framework developed by CISA and Carnegie Mellon for prioritizing vulnerability response based on exploitation status, automatable exploitation, and mission impact. It complements CVSS by focusing on actionability rather than technical severity alone.

Zero-Day

A zero-day is a vulnerability that is unknown to the software vendor and therefore has no patch available. Attackers who discover zero-days can exploit them with no defenders able to protect patched systems. CISA KEV and EPSS track exploitation risk for both zero-days and known vulnerabilities.

Patch Management

Patch management is the systematic process of identifying, acquiring, testing, and deploying software updates (patches) to fix security vulnerabilities and bugs. EPSS scores and CISA KEV membership help security teams prioritize which patches to apply first when resources are limited.

Standards & Frameworks

MITRE ATT&CK

MITRE ATT&CK is a globally-accessible knowledge base of adversary tactics and techniques based on real-world observations. It is used as a foundation for threat detection, red team exercises, and gap analysis in security programs. The framework covers Enterprise, Mobile, and ICS environments.

STIX (Structured Threat Information Expression)

STIX is a standardized language for describing cyber threat intelligence in a machine-readable format. It enables organizations to share IOCs, TTPs, and threat actor profiles in a consistent way. STIX is often paired with TAXII for transport.

TAXII (Trusted Automated eXchange of Intelligence Information)

TAXII is a transport protocol for sharing STIX-formatted threat intelligence between organizations. It defines how threat data is packaged, requested, and delivered. isMalicious provides a TAXII 2.1-compatible endpoint for enterprise consumers.

NIST CSF (Cybersecurity Framework)

The NIST Cybersecurity Framework provides a policy framework of computer security guidance for how private-sector organizations can assess and improve their ability to prevent, detect, and respond to cyber attacks. It organizes security activities into five functions: Identify, Protect, Detect, Respond, and Recover.

OpenCTI

OpenCTI is an open-source threat intelligence platform for storing, analyzing, and sharing structured threat intelligence data in STIX 2.1 format. It supports connectors to external feeds and platforms, including isMalicious, enabling automated enrichment of indicators.

API & Integration

API Key

An API key is a unique identifier used to authenticate requests to an API. It grants access to specific resources and rate limits. API keys should be kept secret and rotated regularly; they should never be exposed in client-side code or version control.

Rate Limiting

Rate limiting controls how many API requests a client can make in a given time window, preventing abuse and ensuring fair resource distribution. isMalicious enforces per-key rate limits and returns HTTP 429 with a Retry-After header when limits are exceeded.

Webhook

A webhook is an HTTP callback that sends a notification to a configured URL when a specific event occurs. isMalicious webhooks deliver alerts when a monitored observable changes status, so security tools can react without polling.

Bulk API

A bulk API endpoint accepts multiple indicators in a single request, enabling high-throughput threat intelligence lookups without the latency overhead of individual calls. isMalicious supports batches of up to 10,000 mixed IP, domain, and URL indicators per request.

Streaming Threat Feed

A streaming threat feed delivers real-time updates of newly identified malicious indicators via a persistent HTTP connection or webhook, eliminating the need to poll for updates. This is critical for SIEMs and firewalls that need sub-minute freshness.

IOC Enrichment

IOC enrichment augments a bare indicator — an IP, domain, or hash — with context such as risk score, confidence, categories, WHOIS, DNS, geolocation, and related infrastructure. Enrichment turns block/allow decisions into informed analyst and automation workflows.

IP Enrichment

IP enrichment is the process of attaching context to a bare IP address: who announces it (ASN and operator), where it is (geolocation), what it is (datacenter, residential, VPN, proxy, Tor), what name it carries (reverse DNS), and what it has done (reputation across abuse sources, with dates). It turns a number in a log into something an analyst can act on.

AI Agent Security

Prompt Injection

Prompt injection is an attack on a system built around a language model in which text supplied as data (a web page, an e-mail, a document, a tool result) is written so that the model reads it as instructions. The model then does what the text says instead of what its operator intended: leaking data, calling tools, or changing its answer.

Indirect Injection (Indirect Prompt Injection)

Indirect prompt injection is prompt injection delivered through content the model fetches or is handed rather than typed by its user: a web page, a search result, an e-mail, a PDF, a repository file, a tool’s output. The attacker never talks to the system; they plant instructions where an agent will read them, and the agent’s owner is the victim.

Instruction Override

Instruction override is the prompt injection technique that tells the model to discard what it was told before: “ignore all previous instructions”, “your new task is”, “disregard the system prompt”, “you are now in developer mode”. It is the most recognisable injection family and the one heuristic scanners catch first, which is why real attacks paraphrase it.

Tool Call Forgery

Tool call forgery is a prompt injection technique in which untrusted content imitates the format an agent uses to call its tools or to receive their results, so that the model believes a tool has been invoked, has returned a value, or should be invoked next. It targets agents that can act, not just answer, and is how an injection turns into a file deletion or a payment.

Homoglyph Attack

A homoglyph attack substitutes characters that look identical or nearly so but are different code points: a Cyrillic а for a Latin a, a Greek ο for a Latin o, a digit 1 for a lowercase l. In a domain name it produces a look-alike address for phishing; in text fed to a language model it disguises a keyword so that a filter misses it while the model still reads it.

Invisible Text Injection

Invisible text injection hides instructions for a language model in content a human cannot see: zero-width characters, Unicode tag characters, text coloured to match its background, font size zero, HTML comments, off-screen elements, or alt text and metadata. The reviewer sees a normal document; the model, which reads the raw text, sees the instructions.

Payload Smuggling

Payload smuggling is the delivery of a prompt injection in an encoded form (base64, percent-encoding, hexadecimal, Unicode escapes, a cipher the text itself explains) so that the malicious instruction is not present as readable words in the content a filter sees, while a language model, which decodes such encodings readily, still receives and follows it.