Antivirus
Software that looks for known-bad and obvious malice, then tries to stop and clean it. Necessary. Not sufficient.
Terms, frameworks, and concepts used on an Australian defensive desk. No exploit steps.
12 entries
Software that looks for known-bad and obvious malice, then tries to stop and clean it. Necessary. Not sufficient.
Endpoint detection and response. Behaviour plus the ability to isolate. An agent without an owner is inventory.
A decoy built to attract hostile attention so you can study it. Not a substitute for patching production.
Watches for unwanted activity and tells someone. Host or network. Alert without an owner is a screensaver.
IDS with a fist. Identifies unwanted traffic and can block it in the moment. Mis-tune it and you become the outage.
Time-stamped records of what happened. Collect what can answer a question. If it never gets queried, it is storage spend.
A knowledge base of adversary tactics and techniques. Use it to find detection gaps, not to decorate a slide.
Security information and event management: collect, normalise, correlate, alert. Useless if nobody owns the queue.
Orchestration and response. Automate the boring. Keep a person on steps that isolate a host or disable an account.
A paddock for untrusted code. If it explodes, the paddock takes it. Production is not a paddock.
People, detections, and a queue. A room full of screens is optional. Ownership of after-hours is not.
Context that changes a decision. IoCs expire. TTPs last. A feed you never action is a newsletter.
Definitions informed by ASD's ACSC glossary. cyber.gov.au glossary