- OSINT
- Open source intelligence: everything about you that can be pieced together from public sources. Website, job ads, LinkedIn profiles, a photo of a company badge on Instagram.
- Initial access
- The first access to a system or account inside the organisation, usually through phishing, an exposed portal or physical entry.
- Foothold
- A persistent access that survives a reboot or password change. Work continues from here.
- C2 (command & control)
- The link between a compromised machine and the attacker's infrastructure that carries commands. Disguised as normal web traffic.
- Lateral movement
- Moving from one system to the next, one step closer to the objective each time.
- Kerberoasting
- An Active Directory attack that requests service tickets and cracks them offline. Works when service accounts have weak passwords.
- Rogue device
- A small computer we plug into the network inside the building that opens an access path for us from outside.
- Tailgating
- Walking through a door behind an authorised person without a card of your own. Works alarmingly often with a coffee cup and a phone in hand.
- White cell
- The few people on the client side who know about the engagement and act as contacts and emergency brake.
- TTPs
- Tactics, techniques and procedures: an attacker's ways of working, described in a standard form in the MITRE ATT&CK framework.
- Crown jewels
- The systems or data whose loss would hurt the organisation most. They are the engagement's objective.
- Purple team
- Red and blue together: attackers and defenders work openly side by side to improve detection and response.