Knowledge base

Short, tagged, searchable.

Terms, frameworks, and concepts used on an Australian defensive desk. No exploit steps.

12 entries

detection hardening acsc-glossary

Antivirus

Software that looks for known-bad and obvious malice, then tries to stop and clean it. Necessary. Not sufficient.

detection IR

EDR

Endpoint detection and response. Behaviour plus the ability to isolate. An agent without an owner is inventory.

detection acsc-glossary

Honeypot

A decoy built to attract hostile attention so you can study it. Not a substitute for patching production.

detection network acsc-glossary

Intrusion detection system (IDS)

Watches for unwanted activity and tells someone. Host or network. Alert without an owner is a screensaver.

detection network acsc-glossary

Intrusion prevention system (IPS)

IDS with a fist. Identifies unwanted traffic and can block it in the moment. Mis-tune it and you become the outage.

logging detection IR acsc-glossary

Logging

Time-stamped records of what happened. Collect what can answer a question. If it never gets queried, it is storage spend.

detection frameworks

MITRE ATT&CK

A knowledge base of adversary tactics and techniques. Use it to find detection gaps, not to decorate a slide.

detection logging

SIEM

Security information and event management: collect, normalise, correlate, alert. Useless if nobody owns the queue.

detection IR

SOAR

Orchestration and response. Automate the boring. Keep a person on steps that isolate a host or disable an account.

hardening detection acsc-glossary

Sandbox

A paddock for untrusted code. If it explodes, the paddock takes it. Production is not a paddock.

detection IR

Security operations centre

People, detections, and a queue. A room full of screens is optional. Ownership of after-hours is not.

detection concepts

Threat intelligence

Context that changes a decision. IoCs expire. TTPs last. A feed you never action is a newsletter.

Definitions informed by ASD's ACSC glossary. cyber.gov.au glossary