1/75
Comprehensive vocabulary flashcards covering threat identification, STRIDE, DREAD, CVSS, threat actors, APT lifecycles, and risk management strategies from Lessons 7 and 8.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress

Asset, Threat, and Vulnerability Trio
The fundamental cybersecurity relationship where an Asset is something valuable, a Threat is what we defend against, and a Vulnerability is a gap or weakness undermining defenses, intersecting to form Risk.
Passive Attacks
Attacks such as eavesdropping, packet sniffing, and traffic analysis aimed at gathering information without altering data, which violates confidentiality.
Active Attacks
Attacks involving unauthorized system alterations—such as data modification, Denial of Service (DoS), and spoofing—that target integrity and availability.
Cybercriminals
Profit-driven threat actors relying heavily on ransomware, phishing, identity theft, and Cybercrime-as-a-Service (CaaS).
Hacktivists
Ideologically or socially motivated threat actors seeking public embarrassment through DDoS attacks, website defacements, and doxxing.
Nation-States / APTs
Highly funded, politically or strategically motivated actors focusing on long-term espionage, critical infrastructure targeting, and IP theft that adapt, pivot, or bypass rather than abandon targets when blocked.
Insider Threats
Malicious or negligent internal personnel, partners, or stakeholders who misuse legitimate credentials or access to compromise systems or leak data.
Script Kiddies
Amateur threat actors who utilize pre-made tools without understanding the underlying code.
Zero-Day Exploits
Cyberattacks targeting unknown, unpatched software vulnerabilities before security patches are available.
Supply Chain Attacks
Cyberattacks that target third-party vendors or software suppliers (nth Party) to compromise a primary target organization.
STRIDE Model
A threat modeling framework developed by Microsoft that categorizes threats into Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
Spoofing
Pretending to be someone else to violate system authenticity.
Tampering
Unauthorized alteration of data or information, violating system integrity.
Repudiation
Performing an action while denying responsibility without proof, violating non-repudiation.
Elevation of Privilege
Gaining unauthorized administrative or elevated access rights, violating system authorization.
PASTA (Process for Attack Simulation and Threat Analysis)
An attacker-centric threat modeling methodology that aligns business objectives with technical threats.
VAST (Visual, Agile, and Strategic Threat Modeling)
A threat modeling framework scalable across large software development pipelines.
Data Flow Diagram (DFD)
A visual diagram used in threat modeling to map system boundaries, processes, data stores, and external entities, identifying threats as data flows cross trust boundaries.
Network Indicators of Compromise (IoCs)
Network-level artifacts such as unusual outbound traffic patterns, spikes in data transfer, or connections to known bad IP addresses.
Host Indicators of Compromise (IoCs)
System-level artifacts including unauthorized registry alterations, unexpected file modifications, or rogue administrator accounts.
DREAD Scoring System
A threat assessment system evaluating Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability.
CVSS (Common Vulnerability Scoring System)
An industry standard framework providing numerical vulnerability severity scores from 0.0 to 10.0 based on Base, Temporal, and Environmental metrics.
Threat Register
A risk management log that organizes threat data by Threat ID, Description, Threat Actor, Associated Vulnerability, and Risk Score.
Cybercrime-as-a-Service (CaaS)
A business model in which cybercriminals purchase malware kits, zero-day exploits, and access credentials from external providers.
Living off the Land (LotL)
A post-exploitation technique where attackers use legitimate, native administrative tools like PowerShell or WMI to evade detection.
Pass-the-Hash (PtH) Attacks
Attacks using stolen password hashes to authenticate across systems without requiring cleartext passwords.
SolarWinds Supply Chain Attack
A 2020 supply chain attack attributed to Russian Foreign Intelligence Service (SVR/Cozy Bear-APT29) that injected malicious code into software updates for SolarWinds Orion.
MTTD and MTTC
MTTD (Mean Time to Detect) measures how quickly an organization discovers a threat, while MTTC (Mean Time to Contain) measures how quickly an organization isolates the threat to stop harm.
MITRE ATT&CK Framework
A globally accessible knowledge base documenting real-world adversary tactics, techniques, and procedures (TTPs).
Strategic Cyber Threat Intelligence
High-level threat intelligence analyzing broad trends, geopolitical alignments, and threat motivations for executive boardrooms.
Operational Cyber Threat Intelligence
Threat intelligence detailing upcoming threat actor campaigns, specific capabilities, and active attack vectors.
Tactical Cyber Threat Intelligence
Technical threat intelligence providing immediate Indicators of Compromise (IoCs) such as IP addresses, file hashes, and domain registries.
Zero Trust Architecture
A security framework operating on the principle 'never trust, always verify,' eliminating implicit internal network trust.
War Exclusion Clause
A traditional insurance policy clause excluding damages caused by military action or sovereign conflict, which creates legal debate when applied to nation-state cyberattacks.
Merck & Co. v. Ace American Insurance Co.
A key legal benchmark ruling that a traditional war exclusion clause did not apply to the state-sponsored NotPetya malware attack.

Asset, Threat, and Vulnerability Trio
A foundational risk model where an Asset is something valuable, a Threat is something being defended against, a Vulnerability is a gap or weakness undermining defense, and Risk is their intersection.
Threat Agent
Any individual, group, or entity that initiates an action to compromise an information system, evaluated by intent, capability, and opportunity.
Passive Attack
An attack aimed at gathering information without altering data (such as eavesdropping, packet sniffing, and traffic analysis), violating confidentiality.
Active Attack
An attack involving unauthorized alterations to systems (such as data modification, Denial of Service, and spoofing), violating integrity and availability.
Cybercriminals
Profit-driven threat actors relying heavily on ransomware, phishing, identity theft, and Cybercrime-as-a-Service (CaaS).
Nation-States / APTs
Politically or strategically motivated threat actors funded by sovereign government budgets that focus on long-term espionage, IP theft, and critical infrastructure disruption.
Hacktivists
Ideologically or socially motivated threat actors who use tactics like website defacements, doxxing, and DDoS attacks to cause public embarrassment for a cause.
Insider Threats
Disgruntled employees seeking revenge/espionage or negligent staff who ignore policies and misuse legitimate internal privileges.
Script Kiddies
Amateur threat actors who use pre-made attack tools without understanding the underlying code.
Supply Chain Attacks
An emerging threat targeting third-party vendors (nth Party) to compromise a larger primary target organization.
Zero-Day Exploits
Attacks targeting unknown, unpatched software vulnerabilities where vendor patches are not yet available.
STRIDE Model
A Microsoft threat modeling framework assessing Spoofing identity, Tampering with data, Repudiation, Information disclosure, Denial of Service, and Elevation of privilege.
Spoofing
Pretending to be someone else (such as an administrator), which violates Authenticity.
Tampering
Altering information without permission (such as unauthorized database modification), which violates Integrity.
Repudiation
Denying an action without proof (such as deleting system logs to deny a malicious action), which violates Non-repudiation.
Information Disclosure
Data leakage or unauthorized data exfiltration, which violates Confidentiality.
Denial of Service (DoS)
Overwhelming resources or crashing systems to render them unavailable, which violates Availability.
Elevation of Privilege
Gaining unauthorized access rights (such as escalating from a guest account to admin rights), which violates Authorization.
PASTA
Process for Attack Simulation and Threat Analysis; an attacker-centric methodology that aligns business objectives with technical threats.
VAST
Visual, Agile, and Strategic Threat Modeling; a threat modeling framework designed to scale across large software development pipelines.
Threat Modeling
A structured approach to identifying, quantifying, modeling, prioritizing security, and mitigating threats relative to software, networks, or business processes.
Data Flow Diagram (DFD)
A diagramming tool used to visualize boundaries, data stores, external entities, and processes to identify threats as data crosses trust boundaries.
DREAD Scoring System
A threat assessment system evaluating Damage potential, Reproducibility, Exploitability, Affected users, and Discoverability.
CVSS
Common Vulnerability Scoring System; an industry standard framework rating vulnerability severity from 0.0 to 10.0 (Critical) by combining Base, Temporal, and Environmental metrics.
Threat Register
A risk management database organizing threat data by Threat ID, Description, Threat Actor, Associated Vulnerability, and Score.

Threat Agent Taxonomy
A classification structure categorizing threat agents (Cybercriminals, Hacktivists, Insiders, Nation-States, Corporate Espionage) by motivation, capability level, and primary targets.
Advanced Persistent Threat (APT)
A well-funded, human-driven threat actor using customized stealthy malware and engineered zero-day exploits to carry out a specific, long-term "low and slow" mission.
Living off the Land (LotL)
A persistence tactic where attackers use legitimate, native administrative tools (such as PowerShell or WMI) to perform operations without triggering security detections.
Pass-the-Hash (PtH) Attack
An attack technique where threat actors use extracted password hashes to authenticate across network systems without needing cleartext passwords.
Lateral Movement
Systematically hopping horizontally from workstation level to server level access across internal corporate network zones (East-West traffic).
Command & Control (C2) Channels
Covert communication lines established between compromised internal hosts and external malicious infrastructure to direct attacks and exfiltrate data.
SolarWinds Supply Chain Attack (2020)
A major cyber attack attributed to Russian Foreign Intelligence Service (SVR/Cozy Bear-APT29) that injected malicious code into software updates for SolarWinds Orion, compromising over 18,000 organizations.
Mean Time to Detect (MTTD)
A high-value business metric measuring how quickly an organization discovers a threat or vulnerability in its environment to minimize attacker dwell time.
Mean Time to Contain (MTTC)
A critical metric measuring how quickly an organization isolates an active threat to halt further operational or data harm.
MITRE ATT&CK Framework
A globally accessible open knowledge base of adversary tactics, techniques, and procedures (TTPs) used to build behavior profiles and run security simulations.
Strategic Cyber Threat Intelligence
High-level intelligence covering overall threat trends, geopolitical alignments, and adversary motivations tailored for executive boardrooms.
Operational Cyber Threat Intelligence
Intelligence offering specific details into upcoming threat actor campaigns, technical capabilities, and active attack vectors.
Tactical Cyber Threat Intelligence
Direct technical Indicators of Compromise (IoCs) including IP addresses, file hashes, and domain registries.
Zero Trust Architecture
A security methodology based on the principle of "Never trust, always verify," eliminating implicit trust inside internal networks.
War Exclusion Clause
A traditional insurance policy provision excluding damages caused by military action or sovereign conflict, creating legal coverage disputes when attributing nation-state APT attacks.
Merck & Co. v. Ace American Insurance Co.
A benchmark legal ruling establishing that a traditional war exclusion clause did not apply to the state-sponsored NotPetya malware attack.