Reference
Glossary
203 entries covering vulnerability management, threat intelligence, IT forensics, DFIR, law and tooling — every abbreviation spelled out, every term in context. Use the search box, click a category in the table of contents, or deep-link a single term.
Identifiers
- CPECommon Platform EnumerationStandardisierte Produkt-/Versionskennung
- CPE is a standardised naming scheme for IT products, operating systems and hardware. A CPE string uniquely identifies vendor, product and version, allowing vulnerabilities (CVE) to be matched to affected products by machine. CPE is thus the glue between an abstract vulnerability and the concrete asset in one's own estate.
- Open detail page →Original source ↗
- CVECommon Vulnerabilities and ExposuresAllgemeine Schwachstellen und Risiken
- A CVE-ID is the globally recognised, unique identifier per publicly known vulnerability in the format CVE-YYYY-NNNN(N). It is issued by the MITRE Corporation and a network of authorised partners (CNAs). Importantly, the CVE-ID names a vulnerability but on its own says nothing about its severity or likelihood of exploitation — for that, CVSS, EPSS and the KEV catalogue apply.
- Open detail page →Original source ↗
- CWECommon Weakness EnumerationKlassifikations-Schema für Software-Schwachstellen
- CWE is a catalogue of typical weakness types in software and hardware — such as flawed input validation, unsafe memory handling or poor authentication. Where a CVE names a concrete vulnerability in a concrete product, a CWE describes the underlying class of defect. This makes it possible to move from the individual flaw to the actual root cause and thus to prevention.
- Open detail page →Original source ↗
- DSADebian Security AdvisoryDebian-Sicherheitshinweis
- A DSA is the Debian project's official security advisory for one or more vulnerabilities in Debian packages. It names the affected packages, the associated CVE-IDs and the version in which the problem is fixed. For operators of Debian systems, the DSA is the authoritative, vendor-side instruction for action.
- Open detail page →Original source ↗
- GHSAGitHub Security AdvisoryGitHub-Sicherheitshinweis
- A GHSA is an entry in the GitHub Advisory Database, which primarily captures vulnerabilities in open-source dependencies across various programming-language ecosystems. It carries its own identifier in the format GHSA-xxxx-xxxx-xxxx and can exist before or without a classic CVE-ID. For the software supply chain, GHSA is therefore one of the fastest sources.
- Open detail page →Original source ↗
- GSDGlobal Security DatabaseOffene, community-getriebene Schwachstellen-Datenbank
- The GSD is an open-source project of the Cloud Security Alliance (CSA) aiming to build an open, community-maintained alternative or complement to the CVE system. The data is managed via Git under a free licence and is meant to address the gaps perceived in classic vulnerability identifiers. Conceptually the GSD identifier resembles the CVE but relies on an open contribution process.
- Open detail page →Original source ↗
- IMEIInternational Mobile Equipment IdentityInternationale Mobilfunk-Geräte-Kennung
- The IMEI is the typically 15-digit, globally unique identifier of a mobile device — it identifies the device itself, not the connection or the person. In mobile forensics it serves for unambiguous device attribution, for instance when reconciling exhibits with connection data. On most devices it can be retrieved via a short key sequence.
- Open detail page →
- IMSIInternational Mobile Subscriber IdentityInternationale Mobilfunk-Teilnehmer-Kennung
- The IMSI identifies the subscriber (the SIM) in the mobile network and is thus the counterpart to the device-side IMEI. It is stored on the SIM and consists of a country and network code plus a subscriber-specific number. Because of its sensitivity, the network replaces it with temporary identifiers wherever possible.
- Open detail page →
- RHSARed Hat Security AdvisoryRed-Hat-Sicherheitshinweis
- An RHSA is Red Hat's official security advisory for vulnerabilities in Red Hat products, primarily Red Hat Enterprise Linux. It links affected packages to the associated CVE-IDs, a severity rating and the corrected versions. For Red Hat environments it is the authoritative patch reference.
- Open detail page →Original source ↗
- USNUbuntu Security NoticeUbuntu-Sicherheitshinweis
- A USN is Canonical's official security notice for vulnerabilities in Ubuntu. It names the affected packages, the associated CVE-IDs and the version in which the flaw is closed. For Ubuntu systems the USN is the authoritative source for the actual patch status.
- Open detail page →Original source ↗
Scoring
- CVSSCommon Vulnerability Scoring SystemAllgemeines Schwachstellen-Bewertungssystem
- CVSS is the globally established, open standard for assessing the technical severity of a vulnerability on a scale from 0 to 10. It describes how easily a flaw can be exploited and what damage it can cause — but not how likely its actual exploitation is. CVSS and the complementary EPSS deliberately answer different questions.
- Open detail page →Original source ↗
- EPSSExploit Prediction Scoring SystemSystem zur Vorhersage von Exploit-Wahrscheinlichkeiten
- EPSS estimates the probability that a vulnerability will actually be exploited within the next 30 days, as a value between 0 and 1. It thus answers a different question than CVSS: not „how severe would exploitation be“ but „how likely is it“. Together the two values align the patch order with the real threat rather than with theoretical severity.
- Open detail page →Original source ↗
- Priority-ScorePriority ScorePriorisierungs-Score
- The priority score is a consolidated metric that condenses several individual signals into a single, action-guiding ranking: technical severity (CVSS), exploitation likelihood (EPSS), known-exploited status (KEV) and the context of the affected asset. The aim is to answer the only truly important question in vulnerability management: what first?
- Open detail page →
Standards & frameworks
- ATT&CKAdversarial Tactics, Techniques & Common KnowledgeWissensbasis gegnerischer Taktiken und Techniken
- MITRE ATT&CK is an open, curated knowledge base of real adversary behaviour, organised by tactics (the „why“ of a step) and techniques (the „how“). It provides a common language to describe attacks, map detections and reveal gaps in one's own defence. ATT&CK is explicitly based on observed behaviour, not on theory.
- Open detail page →Original source ↗
- ATT&CK for ICSMITRE ATT&CK for Industrial Control SystemsMITRE ATT&CK für industrielle Steuerungssysteme
- ATT&CK for ICS transfers the ATT&CK logic to the world of operational technology (OT) and industrial control systems. Instead of classic IT targets it describes tactics and techniques aimed at physical processes — such as manipulating control logic or suppressing protective functions. It is the common vocabulary for analysing attacks on manufacturing, energy and critical infrastructure.
- Open detail page →Original source ↗
- BAITBanking Supervisory Requirements for IT (Germany)Bankaufsichtliche Anforderungen an die IT
- The BAIT are a BaFin circular that, on the basis of § 25a of the German Banking Act (KWG), specifies the supervisory expectations for the IT organisation and information security of banks. For years they were the authoritative national benchmark for IT security in the banking sector. With the EU regulation DORA they are being phased out step by step.
- Open detail page →Original source ↗
- BSI-Leitfaden IT-ForensikBSI Guideline on IT ForensicsBSI-Leitfaden IT-Forensik
- The BSI Guideline on IT Forensics is the authoritative German-language reference for a methodical, court-proof approach to the forensic investigation of IT incidents. It describes a structured process from strategic preparation through data acquisition to analysis and documentation. It thereby provides a reliable framework that secures traceability and evidentiary value.
- Open detail page →Original source ↗
- CRACyber Resilience ActEU-Cyberresilienz-Verordnung (Verordnung 2024/2847)
- The CRA is EU Regulation (EU) 2024/2847 setting horizontal cybersecurity requirements for „products with digital elements“ — from industrial controllers and software to connected consumer devices. For the first time manufacturers must ensure security across the entire product lifecycle, handle vulnerabilities and provide security updates. The CE marking is thereby extended with a cybersecurity dimension.
- Open detail page →Original source ↗
- CSAFCommon Security Advisory FrameworkStandard für maschinenlesbare Sicherheitshinweise
- CSAF is an open standard for machine-readable security advisories. Instead of publishing advisories as prose, CSAF describes them in a structured format that can be processed automatically — who is affected, in which version, with which remediation. It is the answer to the simple fact that no human can manually read all relevant advisories any more.
- Open detail page →Original source ↗
- EDREndpoint Detection and ResponseEndpunkt-Erkennung und -Reaktion
- EDR continuously monitors endpoints — workstations, servers, mobile devices — records their behaviour and detects suspicious activity by patterns rather than only by known signatures. Unlike classic antivirus, EDR enables investigation and targeted response, such as isolating a compromised host. Forensic endpoint telemetry is a core ingredient of modern detection.
- Open detail page →
- IEC 61508IEC 61508 — Functional Safety of E/E/PE SystemsIEC 61508 — Funktionale Sicherheit elektrischer/elektronischer Systeme
- IEC 61508 is the overarching base standard for functional safety of electrical, electronic and programmable electronic systems. It defines how safety-related functions are designed such that a dangerous failure becomes sufficiently improbable — quantified via Safety Integrity Levels (SIL 1-4). It is the root from which numerous sector-specific safety standards are derived.
- Open detail page →Original source ↗
- IEC 61511IEC 61511 — Functional Safety for the Process IndustryIEC 61511 — Funktionale Sicherheit der Prozessindustrie
- IEC 61511 is the application of the base standard IEC 61508 to the process industry, governing safety-related systems there — so-called Safety Instrumented Systems (SIS). Such systems automatically bring a plant into a safe state when danger threatens, for instance via emergency shutdown. They are the last technical line of defence in chemical, petrochemical and comparable plants.
- Open detail page →Original source ↗
- IEC 62443IEC 62443 — Security for Industrial Automation and Control SystemsIEC 62443 — Sicherheit industrieller Automatisierungs- und Steuerungssysteme
- IEC 62443 is the authoritative series of standards for the cybersecurity of industrial automation and control systems (IACS). Unlike pure IT standards, it explicitly addresses the particularities of operational technology and distributes responsibility across all parties — operators, integrators and manufacturers. In the OT world it is what ISO 27001 is in classic IT.
- Open detail page →Original source ↗
- ISO 27001ISO/IEC 27001 — Information Security Management SystemISO/IEC 27001 — Informationssicherheits-Managementsystem
- ISO/IEC 27001 is the internationally leading standard for an information security management system (ISMS). It describes a risk-based, process-oriented framework to systematically plan, implement, review and improve information security. Certification by an accredited body is the common, auditable proof that an ISMS is effectively operated.
- Open detail page →Original source ↗
- KAITCapital Management Supervisory Requirements for IT (Germany)Kapitalverwaltungsaufsichtliche Anforderungen an die IT
- The KAIT were the BaFin circular specifying IT-supervisory expectations specifically for capital management companies — the sector-specific counterpart to the BAIT. They transferred principles on IT governance, information security and outsourcing to the fund industry. With the EU regulation DORA they were repealed.
- Open detail page →Original source ↗
- KRITISCritical InfrastructureKritische Infrastrukturen
- KRITIS denotes organisations and facilities of essential importance to society, whose failure or impairment would cause significant supply shortages or threats to public safety. In Germany the affected sectors and thresholds are defined through the BSI Act and the BSI Critical Infrastructure Ordinance (BSI-KRITISV). With NIS2 the circle of regulated entities was extended far beyond the classic KRITIS notion.
- Open detail page →Original source ↗
- MDMMobile Device ManagementVerwaltung mobiler Endgeräte
- MDM denotes the central management of mobile devices — smartphones, tablets, sometimes laptops — via a management platform. It allows devices to be enrolled, security policies enforced, applications distributed and, in case of loss or theft, remotely locked or wiped. MDM today is usually part of a broader endpoint management (UEM).
- Open detail page →
- MDRManaged Detection and ResponseVerwaltete Erkennung und Reaktion
- MDR is not a product but a service: a specialised provider operates detection and response for an organisation, combining technology with human analysts and taking over triage, investigation and initiated countermeasures. MDR closes the gap between „we bought tools“ and „someone evaluates the alerts around the clock“. It is the operated answer to the cybersecurity skills shortage.
- Open detail page →
- MISPMISP — Open Source Threat Intelligence PlatformOffene Threat-Intelligence-Sharing-Plattform
- MISP is an open platform for collecting, structuring and sharing threat information — in particular indicators such as malicious IP addresses, domains or file hashes. It enables organisations to exchange insights about attacks among one another in a trust-based, machine-readable way. In the CERT and SOC world, MISP is one of the most widely used building blocks of threat intelligence.
- Open detail page →Original source ↗
- NDRNetwork Detection and ResponseNetzwerk-Erkennung und -Reaktion
- NDR monitors network traffic, models normal behaviour and detects deviations indicating lateral movement, data exfiltration or command-and-control. Where EDR sees the endpoint, NDR sees the connections between them — including from devices on which no agent can be installed. Only the two perspectives together yield a complete picture.
- Open detail page →
- NIS2Network and Information Security Directive 2EU-Richtlinie über Netz- und Informationssicherheit 2
- NIS2 is EU Directive (EU) 2022/2555 to raise the level of cybersecurity across the Union. It substantially broadens obligations compared with the first NIS directive: more sectors, mandatory risk management, staged reporting duties and personal accountability of senior management. In Germany it is transposed by the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), which fundamentally reforms the BSI Act.
- Open detail page →Original source ↗
- SIEMSecurity Information and Event ManagementSicherheitsinformations- und Ereignis-Management
- A SIEM centrally collects, normalises and correlates security-relevant log data from across the technology stack and raises alerts from it. It is the shared data hub for detection, investigation and evidence — from servers and endpoints to network, cloud and applications. Without this central view, security monitoring stays piecemeal and blind to connected attack patterns.
- Open detail page →
- SigmaSigma — Generic Detection Rule FormatGenerisches Format für Erkennungsregeln
- Sigma is an open, vendor-neutral format for describing detection rules for log data — essentially what YARA is for files, applied to log events. A rule written in Sigma can be translated via tooling into the query language of various SIEM systems. This makes detection logic portable and shareable independently of the concrete product.
- Open detail page →Original source ↗
- SOARSecurity Orchestration, Automation and ResponseSicherheits-Orchestrierung, -Automatisierung und -Reaktion
- SOAR bundles tools and processes to automate and orchestrate recurring security workflows via so-called playbooks. Instead of routing every alert manually through a chain of tools, a playbook performs enrichment, assessment and initial countermeasures reliably and with an audit trail. The aim is to shorten response times and relieve analysts of routine work.
- Open detail page →
- VAITInsurance Supervisory Requirements for IT (Germany)Versicherungsaufsichtliche Anforderungen an die IT
- The VAIT were the BaFin circular specifying IT-supervisory expectations for insurance undertakings — the sector-specific counterpart to BAIT and KAIT. They transferred principles on IT governance, information security, outsourcing and contingency management to the insurance sector. With the EU regulation DORA they were repealed.
- Open detail page →Original source ↗
- XDRExtended Detection and ResponseErweiterte Erkennung und Reaktion
- XDR brings signals from multiple security domains — endpoint, network, cloud, identity, email — together into a shared detection and response layer. The aim is to link isolated individual alerts into a coherent attack story, enabling faster detection and more targeted response. XDR is thus the cross-domain evolution of EDR.
- Open detail page →
- XIEMExtended Security Incident and Event ManagementErweitertes Sicherheitsvorfall- und Ereignis-Management
- XIEM® is the tiered managed-security operating model from NEOSEC and a registered trademark of NEOSEC GmbH. It extends classic SIEM — the central collection, normalisation and correlation of security-relevant events — with endpoint forensics, network visibility and deception technology, and consolidates them into three building tiers: Sentry, Orchestrate and Command. The guiding idea is end-to-end visibility from detection through to defensible response, without an organisation having to build its own 24/7 capability.
- Open detail page →Original source ↗
- ZAITPayment Services Supervisory Requirements for IT (Germany)Zahlungsdiensteaufsichtliche Anforderungen an die IT
- The ZAIT were the BaFin circular specifying IT-supervisory expectations for payment service providers and e-money institutions — the youngest member of the xAIT family. They transferred the established principles on IT security and outsourcing to a particularly dynamic, technology-driven sector. With the EU regulation DORA they were repealed.
- Open detail page →Original source ↗
Bodies
- ANSSIFrench National Cybersecurity AgencyFranzösische nationale Cybersicherheitsbehörde
- ANSSI is France's national cybersecurity agency. It is responsible for protecting governmental and critical information systems, issues security requirements and certifications and operates the national CERT-FR. Within Europe it is one of the formative, technically particularly influential agencies.
- Open detail page →Original source ↗
- BaFinFederal Financial Supervisory Authority (Germany)Bundesanstalt für Finanzdienstleistungsaufsicht
- BaFin is the German supervisory authority for banks, insurers, capital management and payment service providers, founded in 2002 with offices in Bonn and Frankfurt am Main. It oversees the stability and integrity of the financial sector and over the years issued the IT-supervisory circulars of the xAIT family (BAIT, VAIT, KAIT, ZAIT) for this purpose. With the EU regulation DORA it is also the central national supervisor for digital operational resilience.
- Open detail page →Original source ↗
- BSIFederal Office for Information Security (Germany)Bundesamt für Sicherheit in der Informationstechnik
- The BSI is Germany's central authority for cybersecurity, headquartered in Bonn. It shapes information security for the state, the economy and society, issues standards such as IT-Grundschutz, operates national incident coordination via CERT-Bund and is the central supervisory, registration and reporting body for KRITIS and NIS2. For German organisations it is the authoritative governmental reference.
- Open detail page →Original source ↗
- CERT-BundComputer Emergency Response Team of the German Federal AdministrationComputer-Notfallteam des Bundes
- CERT-Bund is the German federal computer emergency response team, located within the BSI. It monitors the threat landscape, warns of acute vulnerabilities and attack campaigns via the Warning and Information Service (WID) and coordinates the response to security incidents in federal authorities and beyond. It is the operational arm of governmental incident handling in Germany.
- Open detail page →Original source ↗
- CERT-FRFrench Governmental Computer Emergency Response TeamStaatliches Computer-Notfallteam Frankreichs
- CERT-FR is the French governmental computer emergency response team operated by ANSSI. It monitors threats, publishes warnings and analyses and coordinates the response to security incidents of national relevance. Its technical notes are regarded, beyond France, as a high-quality source.
- Open detail page →Original source ↗
- CISACybersecurity and Infrastructure Security Agency (USA)US-Behörde für Cyber- und Infrastruktursicherheit
- CISA is the civilian cybersecurity agency of the USA, located within the Department of Homeland Security. It protects critical infrastructure, coordinates national incident handling and operates the globally noted Known Exploited Vulnerabilities catalogue (KEV). It is also the governmental sponsor of the CVE programme.
- Open detail page →Original source ↗
- CNACVE Numbering AuthorityCVE-Vergabestelle
- A CNA is an entity authorised by the CVE programme to independently assign CVE-IDs within its defined scope — for instance a vendor for its own products. This decentralised model spreads the burden of vulnerability cataloguing across many shoulders. It is the organisational backbone behind the seemingly simple CVE number.
- Open detail page →Original source ↗
- ENISAEuropean Union Agency for CybersecurityAgentur der Europäischen Union für Cybersicherheit
- ENISA is the European Union's cybersecurity agency. It supports member states and institutions with expertise, coordinates Europe-wide cooperation and plays a central role in implementing NIS2, the Cyber Resilience Act and the European certification schemes. It is the technical bracket of EU cybersecurity policy.
- Open detail page →Original source ↗
- EuropolEuropean Union Agency for Law Enforcement Cooperation (incl. EC3)Europäisches Polizeiamt (inkl. EC3)
- Europol is the law enforcement agency of the European Union, headquartered in The Hague, which supports and networks the member states' police forces in combating serious and organised crime. For cybercrime, Europol operates the European Cybercrime Centre (EC3). It is the EU's central hub in the fight against cybercrime.
- Open detail page →Original source ↗
- FIRSTForum of Incident Response and Security TeamsInternationaler Verbund von Notfall- und Sicherheitsteams
- FIRST is the international umbrella organisation of incident response and security teams (CERTs, CSIRTs, PSIRTs). It promotes worldwide cooperation in handling security incidents and stewards central open standards — including CVSS, EPSS and the TLP model. FIRST thereby shapes the common language of defenders.
- Open detail page →Original source ↗
- MSRCMicrosoft Security Response CenterMicrosoft-Sicherheitsreaktionszentrum
- The MSRC is the central body at Microsoft for handling and publishing security vulnerabilities in Microsoft products. It coordinates the response to reported vulnerabilities, assigns its own CVE-IDs as a CNA and publishes the monthly cumulative updates. Given the prevalence of Microsoft software, it is one of the most consequential vendor bodies of all.
- Open detail page →Original source ↗
- NCSC-NLNational Cyber Security Centre (Netherlands)Nationales Cybersicherheitszentrum der Niederlande
- The NCSC-NL is the national cybersecurity centre of the Netherlands. It supports governmental bodies and operators of critical infrastructure with situational awareness, warnings and incident coordination and is part of the European network of national cybersecurity bodies. It is regarded as active and well-connected internationally.
- Open detail page →Original source ↗
- NISTNational Institute of Standards and Technology (USA)US-Institut für Standards und Technologie
- NIST is the US standards and technology agency whose publications set benchmarks well beyond the USA. In the security domain it operates the National Vulnerability Database (NVD), issues the widely noted Cybersecurity Framework and publishes the influential SP 800 series of standards. Its standards shape global security practice.
- Open detail page →Original source ↗
- PSIRTProduct Security Incident Response TeamProdukt-Sicherheitsreaktionsteam
- A PSIRT is the vendor-side body that handles security vulnerabilities in its own products — from receiving a report through remediation to publishing an advisory. It is the counterpart to the internal CSIRT that protects one's own organisation: a PSIRT protects the vendor's customers. With product regulation, this function is gaining strongly in importance.
- Open detail page →Original source ↗
- SANSSANS Institute
- The SANS Institute is one of the best-known private institutions for training and research in information security. It offers practice-oriented courses and certifications, publishes widely used guidelines and operates active situational monitoring with the Internet Storm Center. Unlike the governmental bodies it is a commercial but professionally respected actor.
- Open detail page →Original source ↗
- ZACCentral Cybercrime Contact Points (Germany)Zentrale Ansprechstellen Cybercrime
- The Central Cybercrime Contact Points (ZAC) are the police contact points of the German federal and state authorities to which companies and institutions can turn in the event of IT security incidents. They receive incidents, advise and initiate first prosecutorial measures. For the economy they are the direct line to the police in a cyber emergency.
- Open detail page →Original source ↗
Data sources
- abuse.chabuse.ch — Community Threat IntelligenceGemeinnützige Threat-Intelligence-Quelle
- abuse.ch is a non-profit initiative run in the Swiss academic environment that provides freely usable threat-intelligence services. Across several platforms it collects and shares indicators on malware, command-and-control servers and malicious files. It is among the most widely used open sources in the defender community.
- Open detail page →Original source ↗
- ACSAlliance for Cyber Security (Germany)Allianz für Cyber-Sicherheit
- The Alliance for Cyber Security is a BSI initiative for industry and public authorities that bundles and disseminates knowledge and warnings on cybersecurity. It publishes notices, recommended actions and situational information and connects participating organisations. It is thus a low-threshold access to state-backed security knowledge.
- Open detail page →Original source ↗
- CrowdSecCrowdSec — Collaborative Intrusion PreventionKollaborative Angriffserkennung und -abwehr
- CrowdSec is an open-source solution for behaviour-based intrusion detection and prevention whose distinctive feature is the collective component: participating installations share signals about malicious addresses and thereby feed a community block list. Whoever stands out anywhere can be blocked in many places. The model transfers the swarm idea to network defence.
- Open detail page →Original source ↗
- EUVDEuropean Union Vulnerability DatabaseSchwachstellendatenbank der Europäischen Union
- The EUVD is the European Union's vulnerability database operated by ENISA. It consolidates publicly available information on vulnerabilities from many sources — including the CVE programme and the KEV catalogue — and assigns its own EUVD identifiers. It is conceived as a European, sovereign complement to the established sources, not as their replacement.
- Open detail page →Original source ↗
- MalpediaMalpedia — Malware EncyclopediaEnzyklopädie für Schadsoftware
- Malpedia is a curated, freely accessible knowledge base on malware families, operated at Fraunhofer FKIE. It bundles structured information, references and detection characteristics and thereby creates a common, consistent naming of malware. For analysis and threat intelligence it is a reliable reference work.
- Open detail page →Original source ↗
- NVDNational Vulnerability Database (USA)US-amerikanische Schwachstellendatenbank
- The NVD is the vulnerability database operated by the US NIST, which enriches CVE records with assessments, product mappings (CPE) and classifications (CWE). For years it was the global standard reference for enriched vulnerability data. Since 2024, however, it has been struggling with a substantial processing backlog.
- Open detail page →Original source ↗
- OSVOpen Source VulnerabilitiesSchwachstellendatenbank für Open-Source-Software
- OSV is an open vulnerability database and an associated data schema focused on open-source dependencies. Instead of tying to product names, OSV ties precisely to package versions in the respective language ecosystems and thereby answers whether a concrete dependency is affected. For software supply-chain security this is a decisive difference.
- Open detail page →Original source ↗
- OTXOpen Threat ExchangeOffene Plattform zum Austausch von Bedrohungsdaten
- OTX is an open, community-driven platform for exchanging threat data, originally founded by AlienVault. Users share so-called pulses — bundled indicators on a campaign or threat — and can adopt them into their own tools. OTX is among the best-known freely accessible collection points for indicators.
- Open detail page →Original source ↗
- VirusTotalVirusTotalMulti-Engine-Analysedienst für Dateien und URLs
- VirusTotal is a widely used online service that checks submitted files and URLs against numerous detection engines simultaneously and aggregates the result. Beyond that it serves as a vast, searchable knowledge base about already-seen artefacts and their relationships. For the quick initial assessment of suspicious objects it is a standard tool.
- Open detail page →Original source ↗
- WIDWarning and Information Service (CERT-Bund)Warn- und Informationsdienst des CERT-Bund
- The WID is the warning and information service of CERT-Bund within the BSI. It publishes structured warnings on vulnerabilities in widely used products, each with a rating, affected versions and recommended actions. For German-speaking organisations it is a reliable, governmental early-warning source.
- Open detail page →Original source ↗
Concepts
- AIArtificial IntelligenceKünstliche Intelligenz
- Artificial intelligence denotes methods by which machines solve tasks that previously required human judgement — such as recognising patterns in large volumes of data or processing language. In cybersecurity, AI works in both directions: it improves detection and triage but at the same time empowers attackers. It is tool and threat in one.
- Open detail page →
- Air GapAir GapAir Gap (physische Netztrennung)
- An air gap is the complete physical separation of a system or network from all other networks, especially from the internet. The idea: what is not connected cannot be attacked remotely either. In practice, however, this separation is rarer and more permeable than many assume.
- Open detail page →
- APTAdvanced Persistent ThreatFortgeschrittene, andauernde Bedrohung
- An APT is a well-resourced, targeted adversary that establishes itself persistently and as undetected as possible in a network, rather than seeking quick damage. Characteristic are patience, tailored procedures and often state or criminal resources in the background. The term describes less a single technique than a threat profile.
- Open detail page →
- APT-LifecycleAPT Lifecycle / Cyber Kill ChainLebenszyklus eines gezielten Angriffs
- The APT lifecycle describes the typical phases of a targeted attack — from reconnaissance through initial access and establishing a foothold to lateral movement and the actual objective. Such models make visible that an attack is not a single moment but a sequence. Each phase offers a chance for detection and interruption.
- Open detail page →
- BCMBusiness Continuity ManagementBetriebliches Kontinuitätsmanagement / Notfallmanagement
- BCM is the organised preparedness that ensures a company remains capable of acting during and after a serious disruption — such as a cyberattack — and can maintain or quickly restore critical processes. It answers the question „What do we do if it happens anyway?“. At the latest, ransomware has forced BCM from theory into lived practice.
- Open detail page →
- Bug BountyBug Bounty ProgrammeBelohnungsprogramm für Schwachstellenmeldungen
- A bug bounty programme invites external security researchers to look for vulnerabilities in defined systems and financially rewards responsibly reported findings. It turns potential attackers into allied testers and harnesses the swarm intelligence of the research community. The prerequisite is a clear framework defining permitted conduct and rewards.
- Open detail page →
- C2Command and ControlSteuerung kompromittierter Systeme
- C2 denotes the infrastructure and communication through which an attacker remotely controls compromised systems — issuing commands, exfiltrating data and downloading further malware. It is the umbilical cord between attacker and victim. Detecting it is one of the most effective levers for stopping an ongoing attack.
- Open detail page →
- CVDCoordinated Vulnerability DisclosureKoordinierte Offenlegung von Schwachstellen
- CVD denotes the coordinated approach in which the finder of a vulnerability and the affected vendor jointly manage publication: fix first, then disclose. The aim is to protect users without giving attackers an unnecessary head start. CVD is the broadly accepted middle path today between immediate secrecy and immediate full disclosure.
- Open detail page →
- Full DisclosureFull DisclosureSofortige Vollveröffentlichung von Schwachstellen
- Full disclosure denotes the practice of making all details of a vulnerability public immediately and completely — with no grace period for the vendor. Its proponents argue for transparency and maximum pressure for a quick fix; critics point to the risk of handing attackers a ready-made template. It is the radical opposite of coordinated disclosure.
- Open detail page →
- HashverfahrenCryptographic Hash FunctionKryptografisches Hashverfahren
- A hash function maps arbitrary data to a value of fixed length — the hash or fingerprint. Good cryptographic hash functions are practically irreversible, and even a tiny change in the input completely changes the hash. These properties make them a tool for integrity checking, recognition and forensic evidence preservation.
- Open detail page →
- HDDHard Disk DriveMagnetische Festplatte
- An HDD is a magnetic storage medium with rotating platters and moving read/write heads. In IT forensics it is particularly rewarding: deleted data often remains physically present until it is overwritten, so much can be reconstructed. Compared with the SSD, its behaviour is more predictable for evidence preservation.
- Open detail page →
- HoneypotHoneypotKöder- bzw. Täuschungssystem
- A honeypot is a deliberately vulnerable- or attractive-looking decoy system that serves no productive purpose — and precisely for that reason is a valuable early-warning signal: any interaction with it is suspicious. Honeypots serve to lure attackers, study their behaviour and detect attacks early. They are a classic means of deception technology.
- Open detail page →
- HoneytokenHoneytokenHoneytoken (Köder-Artefakt)
- A honeytoken is a deliberately placed digital bait — such as a fake credential file, a decoy data record or a prepared link — that has no legitimate purpose and serves solely to raise an alarm as soon as someone touches it. Every use is by definition suspicious. Honeytokens are the smallest, most elegant form of deception technology.
- Open detail page →
- IACSIndustrial Automation and Control SystemsIndustrielle Automatisierungs- und Steuerungssysteme
- IACS is the umbrella term for the entirety of systems that automate and control industrial processes — from sensors and controllers through supervisory systems to the associated networks. It encompasses the narrower terms ICS, SCADA and DCS. IACS is the frame of reference to which the security standard series IEC 62443 explicitly relates.
- Open detail page →
- ICSIndustrial Control SystemsIndustrielle Steuerungssysteme
- ICS denotes the control systems that monitor and regulate industrial processes — for instance in manufacturing, energy supply or water management. These include components such as programmable logic controllers (PLC), supervisory systems (SCADA, DCS) and operator interfaces (HMI). Unlike in office IT, this is about the direct control of physical processes.
- Open detail page →
- IoCIndicator of CompromiseKompromittierungsindikator
- An IoC is a concrete, observable artefact that points to a compromise — such as a malicious IP address, a domain, a file hash or a suspicious registry entry. IoCs are the tangible currency of threat intelligence: they can be shared and matched against one's own environment automatically. They describe the trace, however, not the behaviour.
- Open detail page →
- KIArtificial Intelligence (German term)Künstliche Intelligenz
- KI is the German term for artificial intelligence (AI) — methods by which machines take on tasks that previously required human judgement. In cybersecurity, AI is tool and threat at once. Beyond the technology, the regulatory classification is gaining importance in Europe.
- Open detail page →
- Lateral MovementLateral MovementLaterale Bewegung
- Lateral movement denotes the phase of an attack in which an intruder moves sideways through the network from the first compromised system in order to reach more valuable targets and higher privileges. The first hit is rarely the actual goal. Making this spread visible is one of the most important tasks of detection.
- Open detail page →
- Living off the LandLiving off the Land (LotL)Living off the Land (Leben vom Land)
- Living off the Land denotes an attack technique in which the attackers bring no malware of their own but misuse the already present, legitimate on-board tools of the system — such as administration tools and scripting languages of the operating system. They thus disguise themselves as normal operation. This is precisely what makes them so hard to grasp for classic antivirus solutions.
- Open detail page →
- MFAMulti-Factor AuthenticationMehrfaktorauthentisierung
- MFA requires more than just a password when logging in: in addition, at least one further, independent factor is needed — such as a code from an app, a hardware key or a biometric trait. Even if a password is stolen, access thus remains blocked. MFA is one of the most effective single measures against account takeovers.
- Open detail page →
- OSINTOpen Source Intelligence
- OSINT is the gaining of insights from freely and publicly accessible sources — websites, registers, social media, technical databases and more. It is legal and uses exclusively what is openly available anyway. Both defenders and attackers conduct OSINT — only with reversed signs.
- Open detail page →
- OTOperational TechnologyBetriebstechnik
- OT denotes the hardware and software that directly monitors and controls physical processes and plants — in contrast to classic, data-processing IT. This includes controllers, sensors and supervisory systems in manufacturing, energy, water or building technology. In OT, what counts first is availability and the safety of the physical process.
- Open detail page →
- PentestPenetration TestPenetrationstest
- A penetration test is a commissioned, controlled attack on a system to uncover exploitable vulnerabilities before real attackers do. Unlike an automated vulnerability scan, it combines tools with human creativity and the chaining of multiple weaknesses. The result is an evidenced statement about what an attacker could actually achieve.
- Open detail page →
- PIIPersonally Identifiable InformationPersonenbezogene bzw. personenidentifizierende Daten
- PII denotes information by which a concrete person can be identified — directly (name, ID number) or in combination of several attributes. In Europe the broader concept of personal data under the GDPR is authoritative. Protecting such data is not only a security but also a legal duty.
- Open detail page →
- Plausible DeniabilityPlausible DeniabilityGlaubhafte Abstreitbarkeit
- Plausible deniability denotes the property of a system to credibly deny the existence of certain data — for instance through hidden, encrypted areas whose presence cannot be proven. The concept stems from cryptography and concealment. In forensics it is a challenge because it deliberately undermines provability.
- Open detail page →
- Red TeamRed TeamAngreiferteam zur realistischen Sicherheitsprüfung
- A red team simulates a realistic attacker with a concrete objective — such as access to a particular piece of information — and uses every avenue: technology, people and process. Unlike a pentest that lists vulnerabilities within a scope, the red team tests the defenders' detection and response capability as a whole. The question is: would we even notice?
- Open detail page →
- Responsible DisclosureResponsible DisclosureVerantwortungsvolle Offenlegung
- Responsible disclosure denotes the practice of first reporting a discovered vulnerability confidentially to the vendor and giving it time to fix it before details are published. It is the older term for what is today usually called coordinated disclosure (CVD). The core idea: protect users rather than show off the find.
- Open detail page →
- SandboxSandboxIsolierte Ausführungsumgebung
- A sandbox is a sealed-off environment in which suspicious code can be executed and observed safely without endangering the productive system. It is a central tool of dynamic malware analysis: instead of only statically inspecting a file, one sees what it actually does. At the same time, sandboxing is a protection principle of modern software.
- Open detail page →
- SBOMSoftware Bill of MaterialsSoftware-Stückliste
- An SBOM is a machine-readable inventory of all components that make up a piece of software — in a sense the ingredient list of a program, including all incorporated libraries. It is the basis for immediately knowing, when a new vulnerability emerges, whether and where one is affected. In the EU it becomes mandatory through the Cyber Resilience Act.
- Open detail page →Original source ↗
- SHA-256Secure Hash Algorithm 256-bitSicheres Hashverfahren mit 256 Bit
- SHA-256 is a widely used cryptographic hash function from the SHA-2 family that produces a 256-bit fingerprint from arbitrary data. By current standards it is considered secure and is the de-facto standard for integrity checking, digital signatures and the identification of files. In forensics it is the usual method for evidence preservation.
- Open detail page →
- SOCSecurity Operations CenterSicherheits-Leitstand / Security Operations Center
- A SOC is the combination of people, processes and technology that continuously monitors security events, detects and assesses incidents and steers the response. It is the organisational place where SIEM alerts turn into actual decisions and countermeasures. Its key metrics are mean time to detect (MTTD) and mean time to respond (MTTR).
- Open detail page →
- SSDSolid State DriveHalbleiterlaufwerk
- An SSD stores data in flash memory cells without moving parts and is therefore faster and more robust than a magnetic hard disk. For forensics, however, it brings a catch: mechanisms such as TRIM and internal storage management can independently and quickly destroy deleted data permanently. This makes evidence preservation more demanding than with an HDD.
- Open detail page →
- SteganographieSteganographyVerbergen von Informationen in unverdächtigen Trägern
- Steganography is the art of hiding information so that even its mere existence remains undetected — for instance by embedding data invisibly in an image, an audio file or a document. Unlike encryption, which makes the content unreadable, steganography hides the message itself. Both techniques can also be combined.
- Open detail page →
- Threat HuntingThreat HuntingThreat Hunting (proaktive Bedrohungssuche)
- Threat hunting is the proactive, hypothesis-driven search for attackers who are already in the network but have not yet been caught by automatic alarms. Instead of waiting for an alarm, the hunter actively goes on the hunt for suspicious traces. It is the answer to the realisation that no detection system catches everything.
- Open detail page →
- Threat IntelligenceCyber Threat Intelligence (CTI)Cyber Threat Intelligence
- Threat intelligence is processed knowledge about threats — about attackers, their tools, procedures and indicators — distilled from raw data into actionable insights. It answers not only „What happened?“ but „Who threatens us, how, and what do we do about it?“. Good threat intelligence turns data into decisions.
- Open detail page →
- TTPTactics, Techniques, and ProceduresTaktiken, Techniken und Prozeduren
- TTP stands for Tactics, Techniques and Procedures — the description of attacker behaviour on three levels: the overarching goal (tactic), the method to get there (technique) and the concrete implementation (procedure). TTPs describe how an attacker works, not merely which tools they use. Precisely for this reason they are so meaningful and hard to fake.
- Open detail page →
- VerschlüsselungEncryptionVerschlüsselung
- Encryption transforms readable data, with the help of a key, into an unreadable form, so that only authorised parties with the matching key can decrypt it again. It is the fundamental tool for protecting confidentiality — in transmission as in storage. Without it there would be no secure internet and no effective data protection.
- Open detail page →
- VEXVulnerability Exploitability eXchange
- VEX is a machine-readable format with which a manufacturer communicates whether a product is actually affected by and exploitable through a particular vulnerability — or not. It is the most important complement to the SBOM because it reduces the flood of potential hits to the truly relevant ones. It answers the question „Does this even affect me?“.
- Open detail page →
- WazuhWazuh — Open Source Security PlatformQuelloffene Sicherheitsplattform
- Wazuh is a widely used open-source security platform that combines functions of SIEM and endpoint-based detection (XDR). Via agents it collects events from servers, endpoints and cloud services, evaluates them rule-based and supports, among other things, integrity monitoring, vulnerability detection and compliance evidence. As open source it can be deployed without licence costs.
- Open detail page →Original source ↗
- YARAYARA — Pattern Matching for MalwareMustererkennung für Schadsoftware
- YARA is an open tool and rule language with which malware can be described and recognised by characteristic patterns — text fragments, byte sequences, structural features. Analysts formulate rules that identify a malware family and can use them to search entire file or memory holdings. YARA is regarded as a standard tool of malware analysis.
- Open detail page →Original source ↗
- Zero DayZero-Day Vulnerability / ExploitZero-Day-Schwachstelle
- A zero-day vulnerability is a security flaw still unknown to the defenders (or the manufacturer) and for which there is therefore no patch yet. The name stems from the fact that the manufacturer had „zero days“ to fix it before it was exploited. It is especially dangerous because classic defence is oriented towards the known.
- Open detail page →
- Zero TrustZero Trust / Zero Trust Architecture (ZTA)Zero Trust / Zero-Trust-Architektur
- Zero Trust is a security model that breaks with the assumption that everything inside one's own network is trustworthy. The guiding principle is „never trust, always verify“: every access is checked individually, context-dependently and continuously — regardless of whether it comes from inside or outside. Protection is no longer oriented at the network boundary but at the individual resources.
- Open detail page →Original source ↗
Markers / Classification
- KEVKnown Exploited Vulnerabilities CatalogKatalog bekannter ausgenutzter Schwachstellen
- The KEV catalogue is a list maintained by the US authority CISA of vulnerabilities for which active exploitation in the wild has been confirmed. It answers not the question „how severe?“ but „is it already being attacked?“ — thereby sharply prioritising patching. A vulnerability in the KEV is no longer a theoretical risk.
- Open detail page →Original source ↗
- TLPTraffic Light ProtocolAmpel-Protokoll zur Einstufung der Weitergabe
- The Traffic Light Protocol is a simple, internationally recognised colour scheme that defines how far shared information may be passed on. With four levels — from „recipients only“ to „unrestricted“ — it creates a common language for the confidential exchange of threat data. It governs not the content but the permitted circle of recipients.
- Open detail page →Original source ↗
- TLP:AMBERTLP:AMBERTLP-Stufe Gelb — begrenzte Weitergabe
- TLP:AMBER marks information that may be passed on only in a limited way — within one's own organisation and to customers or clients who need to act for protection. It is the level for sensitive threat data meant to take effect without becoming public. The tightening TLP:AMBER+STRICT limits sharing to one's own organisation.
- Open detail page →Original source ↗
- TLP:GREENTLP:GREENTLP-Stufe Grün — Weitergabe in der Community
- TLP:GREEN marks information that may be shared freely within one's own community or sector but should not be distributed via public channels. It is the level for insights that a broader circle of peers should benefit from, without them becoming openly accessible to the general public — and thus to potential attackers.
- Open detail page →Original source ↗
- TLP:REDTLP:REDTLP-Stufe Rot — keine Weitergabe
- TLP:RED is the strictest level: the information is intended exclusively for the recipients immediately present or directly addressed and may not be passed on to anyone else — not even within one's own organisation. It is reserved for highly sensitive insights whose disclosure could cause immediate harm.
- Open detail page →Original source ↗
- TLP:WHITETLP:WHITE (now TLP:CLEAR)TLP-Stufe Weiß bzw. Clear — frei verteilbar
- TLP:WHITE — renamed TLP:CLEAR in the current version — marks information without sharing restriction: it may be distributed freely, including publicly. The normal rules on copyright and correct attribution usually apply. It is the lowest confidentiality level of the Traffic Light Protocol.
- Open detail page →Original source ↗
Forensics & DFIR
- AntiforensikAnti-ForensicsAnti-Forensik
- Anti-forensics denotes techniques by which attackers cover their tracks, destroy evidence or hinder forensic investigations — for instance by deleting logs, manipulating timestamps or obfuscating malicious code. It is the deliberate counter-movement to forensic analysis. Its presence is often itself a telltale indicator.
- Open detail page →
- Chain of CustodyChain of CustodyBeweismittelkette
- The chain of custody is the seamless documentation of who handled a digital piece of evidence, when, where and how — from acquisition to analysis. It proves that the evidence was not altered unnoticed and thereby decides its admissibility. Without it, even the best forensic find is vulnerable to challenge in court.
- Open detail page →
- Cloud-ForensikCloud ForensicsCloud-Forensik
- Cloud forensics is the forensic investigation of incidents in cloud environments — from software services to infrastructure at external providers. It is particularly demanding because the data is distributed, physical access is lacking and one depends on the provider's logs and interfaces. Here forensics shifts from the data carrier to the data trace.
- Open detail page →
- DatenakquiseData AcquisitionForensische Datenakquise
- Data acquisition is the first and most critical step of any forensic investigation: the forensically sound capture of the relevant data before it is altered. Whether on a powered-down system (static) or during operation (live) — the order follows the volatility of the data. A mistake here can invalidate the entire investigation.
- Open detail page →
- DFIRDigital Forensics and Incident ResponseDigitale Forensik und Reaktion auf Sicherheitsvorfälle
- DFIR combines two closely related disciplines: the response to an ongoing security incident (incident response) and the forensic clarification of what exactly happened (digital forensics). The goal is both at once — to stop the attack and to understand it in an evidentially sound way. DFIR is the operational answer to the worst case.
- Open detail page →
- eDiscoveryElectronic discoveryElektronische Sichtung von Beweismitteln
- eDiscovery (electronic discovery) — identifying, reviewing and producing electronic documents in civil litigation and internal investigations. Tooling filters millions of emails, office files and chats down to the relevant subset — relevance heuristics, OCR and sentiment filters.
- Open detail page →
- File CarvingFile CarvingWiederherstellung von Dateien anhand ihrer Struktur
- File carving is a forensic technique with which files can be reconstructed from raw data — even when the file system no longer contains references. Instead of relying on directory entries, the method searches for characteristic signatures and structures that mark the beginning and end of a file. This makes deleted or orphaned data visible.
- Open detail page →
- ImagingForensic ImagingForensische Datenträgersicherung
- Imaging denotes the creation of an exact, bit-precise copy of a data carrier for forensic investigation. Unlike a normal copy, it captures every sector — including deleted areas and slack space — and is secured against unnoticed alteration via a hash value. Work is then done on this copy, not on the original.
- Open detail page →
- IT-ForensikIT Forensics / Digital ForensicsIT-Forensik
- IT forensics is the methodical, evidentially sound investigation of digital systems in order to reconstruct, after an incident, what happened — who, when, how and with what effect. It combines technical analysis with strict methodology so that the results are traceable and admissible in court. It turns data traces into robust statements.
- Open detail page →
- Live-ForensikLive ForensicsLive-Forensik
- Live forensics is the investigation of a running, powered-on system in order to secure volatile data that would be lost on shutdown — such as memory, active network connections, running processes and decrypted content. It is indispensable when the decisive traces exist only during operation. Every intervention, however, alters the system slightly.
- Open detail page →
- Memory-ForensikMemory ForensicsSpeicherforensik
- Memory forensics is the analysis of a system's volatile memory (RAM). The memory contains traces that exist nowhere else: running and hidden processes, decrypted data, entered passwords, active connections and memory-resident malware. It is often the only way to capture modern, fileless attacks.
- Open detail page →
- Mobile-ForensikMobile ForensicsMobilforensik
- Mobile forensics is the forensic investigation of smartphones, tablets and similar devices. It is particularly demanding because these devices are heavily encrypted, closed and vendor-specific and contain a wealth of sensitive data — from messages through locations to app traces. Access is often the biggest hurdle.
- Open detail page →
- NetzwerkforensikNetwork ForensicsNetzwerkforensik
- Network forensics is the investigation of network traffic and records in order to reconstruct an attack — which connections existed, which data flowed, with which counterparts communication took place. It looks at the traces an attacker leaves in the network, rather than only those on an endpoint. Often it is the key to proving data exfiltration and control (C2).
- Open detail page →
- Slack SpaceSlack SpaceUngenutzter Restbereich von Speicherblöcken
- Slack space is the unused room between the end of a file and the end of the last storage block it occupies. Because storage is allocated in fixed block sizes, a remainder almost always stays — and this remainder can contain fragments of earlier data. For forensics it is an often overlooked treasure trove.
- Open detail page →
- Timeline-AnalyseTimeline AnalysisForensische Zeitleisten-Analyse
- Timeline analysis brings the countless timestamps of a system — from files, logs, registry entries and applications — into a common chronological order. From scattered individual traces, a coherent narrative of events thus emerges. It is one of the most effective methods for reconstructing the course of an incident.
- Open detail page →
- WipingSecure Wiping / Data ErasureSicheres Löschen von Daten
- Wiping denotes the secure, permanent deletion of data through actual overwriting — in contrast to normal „deleting“, which usually only removes the reference while the contents remain. The aim is that the data can no longer be reconstructed even by forensic means. It is the other side of forensics: the deliberate destruction of traces.
- Open detail page →
Attack types
- Brute-ForceBrute-Force AttackBrute-Force-Angriff
- A brute-force attack systematically tries all possible combinations to guess a password or a key — raw computing power instead of finesse. Its prospect of success depends solely on the strength of the secret and the protective measures. Against short or weak passwords it is alarmingly effective.
- Open detail page →
- Buffer OverflowBuffer OverflowPufferüberlauf
- A buffer overflow occurs when a program writes more data into a memory area than it can hold, overwriting adjacent memory in the process. Skilfully exploited, an attacker can thereby get their own code executed. It is one of the oldest and most consequential classes of software vulnerabilities.
- Open detail page →
- CHERNOVITECHERNOVITE (Activity Group)CHERNOVITE (Bedrohungsgruppe)
- CHERNOVITE is the name assigned by Dragos for the adversary group that developed the modular ICS toolkit PIPEDREAM. It is assessed as a state-attributed actor geared towards impairing industrial control systems. Notably, its tool was discovered before it could be deployed destructively.
- Open detail page →
- DatenexfiltrationData ExfiltrationDatenexfiltration
- Data exfiltration is the unauthorised outflow of data from an organisation to the outside — the actual objective of many attacks. It is often the last step in a longer chain and frequently takes place disguised, so as not to stand out. Where it succeeds, the greatest damage and the greatest legal consequences arise.
- Open detail page →
- DDoSDistributed Denial of ServiceVerteilter Überlastungsangriff
- A DDoS attack overloads a target with a flood of requests from many distributed sources simultaneously, until a service is no longer reachable for legitimate users. The distribution across countless systems — often a botnet — makes it hard to defend against and block. It attacks not confidentiality but availability.
- Open detail page →
- DefacementWebsite DefacementVerunstaltung von Webseiten
- Defacement is the unauthorised alteration of the visible content of a website — attackers replace, for instance, the homepage with a message of their own. It is a loud, demonstrative attack aimed above all at visibility and reputational damage. Unlike stealthy break-ins, defacement is meant to be seen.
- Open detail page →
- DoSDenial of ServiceÜberlastungs- bzw. Verfügbarkeitsangriff
- A DoS attack aims to make a service or system unavailable for legitimate users — through overload or the targeted exploitation of a vulnerability that crashes the system. It attacks availability, one of the three protection goals of information security. The distributed variant with many sources is called DDoS.
- Open detail page →
- Drive-by-DownloadDrive-by DownloadUnbemerkter Schadcode-Download beim Seitenbesuch
- In a drive-by download, malicious code is loaded onto the device merely by visiting a manipulated website — without the user consciously downloading or clicking anything. Vulnerabilities in the browser or its components are exploited. The attack turns browsing itself into an entry point.
- Open detail page →
- ExploitExploitAusnutzungscode für eine Schwachstelle
- An exploit is code or a technique that specifically uses a concrete vulnerability to force unintended behaviour — such as executing code or escalating privileges. It is the tool that turns a theoretical flaw into a practical attack. A „zero-day exploit“ uses a still unknown, unpatched vulnerability.
- Open detail page →
- Hash-KollisionHash CollisionHash-Kollision
- A hash collision exists when two different inputs produce the same hash value. With a secure cryptographic hash function this should be practically impossible; if it nonetheless succeeds in a targeted way, the function is broken and unsuitable for security purposes. This is exactly what happened to MD5 and SHA-1.
- Open detail page →
- IndustroyerIndustroyer / CrashOverrideIndustroyer (CrashOverride)
- Industroyer (also CrashOverride) is ICS malware that caused a power outage in Kyiv in December 2016, cutting about a fifth of the city off the grid for around an hour. It was modular in design and addressed industrial switching equipment directly via its own protocols. A variant, Industroyer2, was deployed again against Ukraine in 2022.
- Open detail page →
- InnentäterInsider ThreatInnentäter / Innentäterin
- An insider threat is a person with legitimate access — employees, service providers, partners — who uses this access to the organisation's detriment or negligently enables damage. The threat is especially tricky because it comes from within, enjoys trust and bypasses regular protective measures. It encompasses malicious as well as unintentional cases.
- Open detail page →
- Integer OverflowInteger OverflowGanzzahlüberlauf
- An integer overflow occurs when the result of an arithmetic operation exceeds the value range that the integer type used can represent and silently „wraps around“ — for instance from a very large positive to a negative value. Such silent errors can defeat security checks and lead to further vulnerabilities such as buffer overflows.
- Open detail page →
- KeyloggerKeyloggerTastatureingaben-Rekorder
- A keylogger secretly records keystrokes in order to capture passwords, messages and other confidential input. It exists as software or as a small, interposed hardware device. Its goal is to read along unnoticed at exactly the point where secrets arise — the keyboard.
- Open detail page →
- MalwareMalware (Malicious Software)Schadsoftware
- Malware is the umbrella term for any software written to cause harm — to steal or encrypt data, disrupt systems or give attackers control. It encompasses many families such as viruses, worms, trojans, ransomware and spyware. It is the connecting tool behind most technical attacks.
- Open detail page →
- MITMMan-in-the-Middle attackMittelsmann-Angriff
- Man-in-the-Middle (MITM) — attacker inserts themself between two parties, impersonating each to the other. Classic vectors: WLAN evil-twin, ARP spoofing, BGP hijack, TLS stripping. Mitigation: certificate pinning, mutual authentication.
- Open detail page →
- PhishingPhishing
- Phishing is the attempt to trick people, through forged messages, into disclosing credentials or performing harmful actions — for instance via a deceptively genuine e-mail with a link to a replicated login page. It targets not the technology but the person. It is one of the most common initial-access routes of all.
- Open detail page →
- PIPEDREAMPIPEDREAM / INCONTROLLERPIPEDREAM (INCONTROLLER)
- PIPEDREAM (referred to by Mandiant as INCONTROLLER) is a modular toolkit discovered in 2022 for attacking industrial control systems. Unlike earlier ICS malware, it is not tailored to a single facility but designed as a reusable construction kit against widely used devices. It is regarded as the seventh known ICS-specific malware.
- Open detail page →Original source ↗
- Privilege EscalationPrivilege EscalationRechteausweitung
- Privilege escalation denotes the expansion of one's own rights on a system beyond what was originally permitted — from a simple user to an administrator. It is a central intermediate step of many attacks: only with elevated rights can protective measures be disabled, data captured comprehensively and persistence established. It turns a small foot in the door into full control.
- Open detail page →
- RansomwareRansomwareErpressungssoftware
- Ransomware is malware that encrypts data or locks systems and demands a ransom for their release. It is among the most consequential threats to companies because it paralyses operations immediately. Modern variants combine the encryption with the theft and the threat of publishing the data.
- Open detail page →
- Rogue APRogue Access PointUnautorisierter WLAN-Zugangspunkt
- A rogue AP is an unauthorised Wi-Fi access point — either set up by an attacker to intercept users or carelessly plugged into the network by employees. In both cases an uncontrolled access arises that bypasses the network boundary. A particularly tricky variant is the „evil twin“, which deceptively imitates a familiar network.
- Open detail page →
- SandwormSandworm (APT)Sandworm (APT-Gruppe)
- Sandworm is a state-attributed adversary group held responsible for some of the most consequential attacks on critical infrastructure — including the power outages in Ukraine in 2015 and 2016 as well as the Industroyer2 attack in 2022. The group is attributed to Russian military intelligence (GRU). It exemplifies the threat posed by a patient, well-resourced actor (APT).
- Open detail page →
- Side-ChannelSide-Channel AttackSeitenkanalangriff
- A side-channel attack obtains secret information not by breaking a method but by observing its physical side effects — such as power consumption, timing, electromagnetic emanation or cache behaviour. Instead of cracking the lock, the attacker listens to its sounds. Such attacks are subtle and often hard to defend against.
- Open detail page →
- Smudge AttackSmudge AttackSchmierspur-Angriff
- A smudge attack reads the fingerprint smudges on a touchscreen to guess an unlock pattern or a PIN. The grease residues of the fingers reveal which areas were touched — and thus often the input. It is a simple, physical attack entirely without malware.
- Open detail page →
- StuxnetStuxnet
- Stuxnet is the malware discovered in 2010 that specifically sabotaged the uranium enrichment facility at Natanz in Iran, destroying around a thousand centrifuges in the process. It is regarded as the first known digital weapon to cause physical damage in the real world. With it began the era of targeted attacks on industrial control systems.
- Open detail page →
- TritonTriton / TRISISTriton (TRISIS)
- Triton (also TRISIS or HatMan) is the malware discovered in 2017 that, for the first time, specifically attacked a safety instrumented system (SIS) — concretely the Triconex controllers from Schneider Electric in an industrial facility in the Middle East. Because it targeted exactly the protection layer meant to safeguard human lives, it marks a particularly dangerous escalation.
- Open detail page →
- WörterbuchangriffDictionary AttackWörterbuchangriff
- A dictionary attack guesses passwords by specifically trying a list of likely terms — real words, names, common patterns and known leaked passwords — instead of blindly trying all combinations. It is the smarter, faster relative of the pure brute-force attack. Against human-chosen passwords it is especially successful.
- Open detail page →
- XenotimeXenotime (a.k.a. TEMP.Veles)Xenotime (auch TEMP.Veles)
- Threat actor that Dragos credits with developing and deploying the Triton/Trisis malware (2017, Saudi petrochemical plant). Mandiant tracked the same group as TEMP.Veles and publicly linked it to Russia's CNIIHM research institute in Moscow. Post-2018 activity widened to US and European utility providers — no disruptive incident so far, but reconnaissance reaching down to the safety layer.
- Open detail page →
Tooling
- ConpotConpot ICS/SCADA HoneypotConpot (ICS/SCADA-Honeypot)
- Conpot is an open-source honeypot that emulates industrial control systems (ICS/SCADA) — including typical OT protocols such as Modbus or S7comm. It makes attacks on industrial infrastructure visible without endangering real plants. This makes it especially relevant for OT security.
- Open detail page →Original source ↗
- CowrieCowrie SSH/Telnet HoneypotCowrie (SSH/Telnet-Honeypot)
- Cowrie is an open-source medium-interaction honeypot that emulates SSH and Telnet services and records attackers' activities in detail. It feigns a real shell and logs every command entered. It is one of the most widely used honeypots of all.
- Open detail page →Original source ↗
- DionaeaDionaea Malware HoneypotDionaea (Malware-Honeypot)
- Dionaea is an open-source honeypot specialised in capturing malware. It emulates vulnerable network services and lures attacks in order to secure the transmitted malware for later analysis. It is the successor to the earlier honeypot Nepenthes.
- Open detail page →Original source ↗
- GhidraGhidraGhidra (Reverse-Engineering-Suite)
- Ghidra is an open-source software reverse-engineering suite with which compiled programs can be decomposed back into readable code and analysed. It is used in malware analysis and vulnerability research to understand what a program actually does. As a free tool it has made reverse-engineering work broadly accessible.
- Open detail page →Original source ↗
- OpenCanaryOpenCanaryOpenCanary (Honeypot-Daemon)
- OpenCanary is an open-source, lightweight honeypot daemon that poses as various network services and raises an alarm as soon as someone interacts with them. It works like an invisible tripwire trap in one's own network. Every touch is suspicious — and thus a valuable, low-false-positive signal.
- Open detail page →Original source ↗
- PlasoPlaso (log2timeline)
- Plaso is an open-source tool that automatically creates a comprehensive timeline from a multitude of forensic artefacts — a so-called super timeline. It collects timestamps from file systems, logs, browser traces, the registry and much more and merges them. It is the backbone of many timeline analyses.
- Open detail page →Original source ↗
- Sleuth KitThe Sleuth Kit
- The Sleuth Kit (TSK) — open-source toolkit for disk and filesystem forensics. CLI tools (mmls, fls, icat) with the Autopsy GUI on top. Standard kit for disk-image analysis.
- Open detail page →Original source ↗
- SuricataSuricataSuricata (IDS/IPS/NSM)
- Suricata is an open-source engine for the detection and prevention of network attacks (IDS/IPS) and for network monitoring (NSM). It checks network traffic rule-based for known threats, logs metadata and can report or block suspicious connections. It is a central building block of network-based security.
- Open detail page →Original source ↗
- T-PotT-Pot — The All-In-One Multi Honeypot PlatformT-Pot — Multi-Honeypot-Plattform
- T-Pot is an open-source all-in-one honeypot platform that bundles numerous individual honeypots together with network monitoring and visualisation in a Docker-based system. It is maintained by Telekom Security. It is the easiest entry point to make attacks from the internet visible.
- Open detail page →Original source ↗
- TimesketchTimesketch
- Timesketch is an open-source platform for the collaborative analysis of forensic timelines. It ingests large timeline datasets, makes them searchable and allows several analysts to work collaboratively on the same investigation — with tags, annotations and shared findings. It is the analysis interface for tools such as Plaso.
- Open detail page →Original source ↗
- VolatilityVolatilityVolatility (Speicherforensik-Framework)
- Volatility is an open-source framework for memory forensics — the analysis of a system's memory (RAM). From a memory image it reconstructs running processes, loaded modules, network connections and traces of malware. It is one of the most important tools for capturing fileless and disguised attacks.
- Open detail page →Original source ↗
- WiresharkWiresharkWireshark (Netzwerk-Analysewerkzeug)
- Wireshark is the most widely used open-source tool for analysing network traffic. It captures data packets and dissects them down to the detail, so that communication can be traced step by step. In network forensics, troubleshooting and protocol analysis it is a standard instrument.
- Open detail page →Original source ↗
- ZeekZeekZeek (Netzwerk-Monitor)
- Zeek is an open-source network security monitor that does not primarily search traffic for signatures but translates it into rich, structured logs — who communicated with whom, when, over which protocol. These metadata are the basis for analysis, threat hunting and network forensics. Zeek is designed for large networks and continuous operation.
- Open detail page →Original source ↗
Artifacts
- ADSAlternate Data StreamsAlternative Datenströme (NTFS)
- Alternate data streams are a peculiarity of the NTFS file system: additional, invisible data streams can be attached to a file that do not appear in the normal directory listing. What is intended as a legitimate feature is readily misused to hide data or malicious code. For forensics, ADS are a known hiding place.
- Open detail page →
- BitlockerBitLockerBitLocker-Festplattenverschlüsselung
- BitLocker — Microsoft's full-disk encryption for Windows. Combines a TPM-bound key with a recovery key (BEK). Forensic angle: hunt the recovery key in AD/Entra; otherwise only live acquisition or a cold-boot attack.
- Open detail page →
- BookmarkBookmark (Browser Artefact)Lesezeichen (Browser-Artefakt)
- Bookmarks are the user-saved references to web pages and thus a forensically meaningful artefact: they show which pages were consciously of interest to a person. Unlike the volatile history, they are created deliberately and persist permanently. They give insight into habits and intentions.
- Open detail page →
- Disk ImageDisk ImageDatenträger-Abbild
- A disk image is a complete, bit-precise copy of a data carrier in a file — the basis of any serious disk forensics. It contains not only the visible files but also deleted areas, slack space and file-system structures. Work is done on it so that the original remains untouched.
- Open detail page →
- FATFile Allocation TableFAT (Dateizuordnungstabelle)
- FAT is a simple, very widespread file system that records via an allocation table which storage areas belong to which file. Because of its simplicity and broad compatibility it is found to this day on USB sticks, memory cards and in embedded devices. Forensically it is well understood and productive.
- Open detail page →
- Memory DumpMemory DumpSpeicherabbild
- A memory dump is a snapshot of a system's memory (RAM) at a particular moment. It contains what was active at runtime: processes, loaded modules, network connections, decrypted data and at times malicious code. It is the basis of memory forensics and often the key to fileless attacks.
- Open detail page →
- MFTMaster File TableMaster File Table (NTFS)
- The Master File Table is the central directory of the NTFS file system: it keeps an entry for every file with name, size, timestamps and the storage location. Forensically it is a first-rate source because it documents in detail which files exist or existed and when they were altered. It is a centrepiece of Windows forensics.
- Open detail page →
- PagefilePagefileAuslagerungsdatei
- The pagefile is an area on the data carrier into which Windows swaps out parts of memory when it becomes scarce. Forensically it is valuable because it can contain fragments of what was in RAM — even when the system has long been off. It is, in a sense, a permanent imprint of volatile data.
- Open detail page →
- PrefetchPrefetchPrefetch (Windows)
- Prefetch is a Windows mechanism that speeds up the launching of programs by creating a small file with startup information for each executed application. Forensically this is a stroke of luck: prefetch files prove which programs ran, when and how often. They are a central indicator of program execution.
- Open detail page →
- Windows RegistryWindows RegistryWindows-Registrierungsdatenbank
- The Windows Registry is the central configuration database of the operating system, in which system and application settings, user profiles and countless traces of usage are stored. For forensics it is a veritable treasure trove: it documents connected devices, started programs, logins and much more. It is one of the most important Windows artefacts of all.
- Open detail page →
Protocols & formats
- DCSDistributed Control SystemProzessleitsystem
- A DCS is a distributed control system for controlling complex, continuous industrial processes — such as in chemistry, refining or power generation. Unlike central controllers, it distributes the regulation across several stations connected via the plant network. It is the nervous system of large process facilities.
- Open detail page →
- HMIHuman-Machine InterfaceMensch-Maschine-Schnittstelle
- An HMI is the operating interface through which people observe and control industrial processes — from the screen in the control room to the operating panel at the machine. It translates complex process states into understandable displays and accepts control commands. It is the bridge between operator and plant.
- Open detail page →
- IEC 60870-5-104IEC 60870-5-104IEC 60870-5-104 (Fernwirkprotokoll)
- IEC 60870-5-104 (IEC-104 for short) is a telecontrol protocol widespread in European energy supply, via which control centres communicate with substations and stations. It transmits measurements and switching commands over TCP/IP networks. It became known as the attack route of the Industroyer malware.
- Open detail page →
- IEC 61850IEC 61850IEC 61850 (Norm für Schaltanlagen-Kommunikation)
- IEC 61850 is a standard series for communication in electrical switchgear and substations that standardises the networking of protection, control and measurement devices. It enables modern, digitalised station automation. With networking, the relevance of cybersecurity grows here too.
- Open detail page →
- IPInternet ProtocolInternetprotokoll
- The Internet Protocol (IP) is the fundamental protocol that addresses data packets and forwards them through networks to their destination. It is the common language on which practically all modern network communication is built. Without IP there would be no internet as we know it.
- Open detail page →
- ModbusModbusModbus (Industrieprotokoll)
- Modbus is one of the oldest and most widely used communication protocols of industrial automation. It is simple, robust and cross-vendor — and precisely for that reason ubiquitous to this day in controllers, sensors and actuators. It was, however, designed without any security function.
- Open detail page →
- OPC UAOPC Unified Architecture
- Modern vendor-neutral data and telemetry standard for industrial automation (IEC 62541). Successor to legacy OPC DA. Unlike older protocols OPC UA ships with authentication, encryption and certificates — when they are enabled. Default configurations with anonymous bind are still common in the field. The PIPEDREAM toolkit (2022) shipped a dedicated OPC UA module for manipulating generic servers.
- Open detail page →
- PCAPPacket CapturePaketmitschnitt
- PCAP denotes both the capturing of network traffic and the widespread file format in which the captured packets are stored. A packet capture records network traffic faithfully and is thereby the most important raw material of network forensics. What was not recorded cannot be analysed.
- Open detail page →
- PLCProgrammable Logic ControllerSpeicherprogrammierbare Steuerung (SPS)
- A PLC is a robust industrial computer that directly controls a physical process — it reads sensors and switches actuators according to a stored logic. PLCs are the workhorses of automation and are found in almost every facility. Whoever controls a PLC controls the process.
- Open detail page →
- ProfinetProcess Field Net
- Ethernet-based real-time protocol from Siemens / PI (PROFIBUS & PROFINET International), the de-facto standard in European manufacturing. Carries cyclic process data, acyclic configuration and engineering traffic — all on the same L2 segment. Profinet-stack vulnerabilities typically hit Siemens SIMATIC S7-1500 directly and compatible third parties such as Phoenix Contact PLCnext or Hilscher modules. Protection is almost always achieved through network zoning rather than protocol hardening.
- Open detail page →
- RTURemote Terminal UnitFernbedienungsstation
- An RTU is a robust field station that captures measurements and executes commands from a control centre at remote or inaccessible locations — such as at a pipeline, a substation or a water station. It is the interface between the central SCADA system and the distributed facility on site. It often works autonomously and over long distances.
- Open detail page →
- SCADASupervisory Control and Data AcquisitionÜberwachung und Steuerung verteilter Prozesse
- SCADA denotes systems for the central monitoring and control of widely distributed industrial processes — such as electricity, gas or water networks. A control centre collects data from field stations (RTUs, PLCs) and sends control commands back. SCADA is the overarching nervous system of critical infrastructure.
- Open detail page →
- SISSafety Instrumented SystemSicherheits-Notabschaltsystem
- An SIS is an independent safety system that automatically brings an industrial facility into a safe state when a process reaches dangerous limits — such as overpressure or overheating. It is the last technical protection barrier for preventing damage to people, the environment and the plant. An attack on it is especially consequential.
- Open detail page →
- TCPTransmission Control ProtocolÜbertragungssteuerungsprotokoll
- TCP is the protocol that ensures reliable, ordered data transmission over the otherwise unreliable IP. It guarantees that all data packets arrive completely and in the correct order — the basis for the web, e-mail and most applications. Together they form the TCP/IP stack.
- Open detail page →
- UDPUser Datagram ProtocolBenutzer-Datagramm-Protokoll
- UDP is a simple transport protocol that sends data without connection setup and without delivery guarantee — fast but „unsecured“. It is suitable for applications in which speed matters more than completeness, such as voice and video transmission, DNS or time synchronisation. It is the lean counterpart to TCP.
- Open detail page →
Law & compliance
- § 202a StGBSection 202a German Criminal Code — Data Espionage§ 202a StGB — Ausspähen von Daten
- Section 202a of the German Criminal Code criminalises the unauthorised obtaining of access to specially secured data — that is, overcoming an access protection to reach third-party data not intended for oneself. Even „cracking“ the protection is punishable, regardless of whether the data is subsequently used. The provision is a cornerstone of German computer criminal law.
- Open detail page →Original source ↗
- § 202b StGBSection 202b German Criminal Code — Interception of Data§ 202b StGB — Abfangen von Daten
- Section 202b of the German Criminal Code criminalises the unauthorised interception of non-public data transmissions — such as capturing third-party network communication or electromagnetic emanation. It covers data during transmission, not in the stored state. The provision complements data espionage with the transmission level.
- Open detail page →Original source ↗
- § 202c StGBSection 202c German Criminal Code — Acts Preparatory to Data Espionage§ 202c StGB — Vorbereiten des Ausspähens und Abfangens von Daten
- Section 202c of the German Criminal Code — the so-called „hacker paragraph“ — already criminalises preparatory acts: the production, procurement, sale or distribution of passwords, security codes or of programs whose purpose is the commission of an offence under Section 202a or 202b. Thus the mere provision of the means is punishable. The norm was and is controversial because of its broad wording.
- Open detail page →Original source ↗
- § 303a StGBSection 303a German Criminal Code — Data Tampering§ 303a StGB — Datenveränderung
- Section 303a of the German Criminal Code criminalises the unlawful deletion, suppression, rendering-unusable or alteration of third-party data. What is protected is the authorised party's interest in the unimpaired usability of their data — in a sense „criminal damage“ in the digital space. The attempt is also punishable.
- Open detail page →Original source ↗
- § 303b StGBSection 303b German Criminal Code — Computer Sabotage§ 303b StGB — Computersabotage
- Section 303b of the German Criminal Code criminalises the significant disruption of a data processing that is of essential importance to another. It covers, among other things, data tampering, the input or transmission of data with intent to cause harm (such as DoS/DDoS attacks) and the damaging of equipment. For attacks on companies and authorities the penalty range rises considerably.
- Open detail page →Original source ↗
- BSI-KritisVBSI Criticality RegulationBSI-Kritisverordnung
- The BSI Criticality Regulation (BSI-KritisV) specifies which facilities in Germany count as critical infrastructure (KRITIS). For this it defines, per sector, facility categories and thresholds — the regular benchmark being the supply of around 500,000 people. Whoever exceeds a threshold is subject to special duties towards the BSI.
- Open detail page →Original source ↗
- DORADigital Operational Resilience ActVerordnung über die digitale operationale Resilienz im Finanzsektor
- DORA is EU Regulation (EU) 2022/2554 for the digital operational resilience of the financial sector. As a regulation it applies directly in all member states — unlike NIS2, no national transposition is required. It obliges financial entities and their ICT service providers to maintain ICT risk management, incident reporting, resilience testing and strict third-party risk governance.
- Open detail page →Original source ↗