Sycope dictionary

We understand how important it is to build the knowledge around the solution we offer - we provide you with extra insights that can help in using the Sycope solution more effectively.

Learn more

Newest additions

Check our vocabulary

Active directory

Microsoft's proprietary directory service. It runs on Windows Server and enables administrators to manage permissions.
Learn more >

Anomaly Detection

A method that monitors data to identify unusual patterns or behavior. It helps detect possible threats, faults, or fraud early so they can be investigated.
Learn more >

Application Layer Attack (L7)

Attacks targeting web applications and APIs by exploiting software vulnerabilities to disrupt services, steal data, or prevent legitimate user access.
Learn more >

APT (Advanced Persistent Threat)

APT is a targeted cyberattack in which attackers keep covert access to a system for a long time to steal data, disrupt operations, or conduct espionage.
Learn more >

ARP Spoofing / Poisoning

ARP spoofing is a network attack where a hacker sends forged ARP messages to redirect traffic through themselves, enabling data interception and manipulation.
Learn more >

Beaconing

Malware's periodic communication with a remote attacker-controlled server to receive commands or exfiltrate data while evading detection.
Learn more >

BGP (Border Gateway Protocol)

A routing protocol that directs data between different networks on the internet. It helps choose paths for traffic so networks can exchange information efficiently.
Learn more >

Botnet

A botnet is a network of infected devices controlled remotely by an attacker. It is used to carry out automated attacks such as spam, DDoS, and data theft.
Learn more >

Brute Force

Automated attack method that systematically tests numerous password combinations until gaining unauthorized access to an account or system.
Learn more >

C2 / C&C (Command and Control)

Infrastructure allowing attackers to remotely command infected devices, steal data, and launch coordinated cyberattacks across networks.
Learn more >

Credential Stuffing

Automated attack using stolen login credentials across multiple websites to gain unauthorized account access.
Learn more >

Cryptojacking / Cryptomining

Unauthorized use of a device’s computing power to mine cryptocurrency, usually without the owner’s knowledge. It consumes resources, slowing performance and increasing energy use.
Learn more >

Cyber Threat Intelligence

Security feed algorithm implemented in Sycope CTI actively monitors a number of sources and generates unified list of current IoCs.
Learn more >

Data deduplication

It helps to save enormous amount of data storage. Sycope as first on the market used deduplication mechanism for NetFlow.
Learn more >

Data mining

A technique used to analyze existing information, usually with the intention of pursuing new avenues to pursue business.
Learn more >

DDoS (Distributed Denial of Service)

Cyberattack where multiple compromised devices flood a target with traffic to overwhelm and disable services.
Learn more >

Dead Drop Resolver

A technique where attackers hide malicious data in legitimate online resources, allowing covert control without direct contact.
Learn more >

Deep Packet Inspection

A method used in computer networking to scrutinise the content of data packets transmitted over a network.
Learn more >

DGA (Domain Generation Algorithms)

Malware technique that automatically generates numerous domain names to evade detection and maintain contact with command-and-control servers.
Learn more >

Digital Experience Monitoring

A strategy for optimizing digital interactions, enhancing performance, ensuring security, and boosting user satisfaction.
Learn more >

Direct Network Flood

A type of DoS attack that overwhelms a network with excessive traffic, causing disruption and downtime.
Learn more >

DNS Amplification

DNS Amplification is a DDoS attack where attackers exploit open DNS servers to flood targets with massive response traffic, causing service outages.
Learn more >

DNS Spoofing / Cache Poisoning

Attack injecting fake DNS responses to redirect users to malicious sites for data theft, credential harvesting, or malware distribution.
Learn more >

DNS Tunneling

DNS Tunneling is a technique that encodes data within DNS queries to covertly transmit information through networks and bypass security controls.
Learn more >

Domain Hijacking

Cyberattack where hackers gain unauthorized control of a domain by exploiting weak security or stolen credentials to redirect traffic.
Learn more >

DORA

An EU regulation requiring financial firms to manage ICT risk, report incidents, test resilience, and oversee technology suppliers. It aims to strengthen digital operational resilience in finance.
Learn more >

DoS (Denial of Service)

Attack overwhelming a server with traffic requests to make services inaccessible to legitimate users.
Learn more >

EDR

Endpoint detection and response (EDR) is a security technology that monitors endpoints for suspicious activity. It detects threats, alerts defenders, and can isolate compromised devices.
Learn more >

End User Experience Monitoring

A strategy for optimizing end-users' interactions, focusing on real-time analysis.
Learn more >

False Positive

A false positive is an incorrect alert that flags a safe email, file, or process as a threat. It matters because it can waste time and interrupt normal work.
Learn more >

Fast Flux

A technique where attackers rapidly change IP addresses of malicious servers, using a botnet to evade detection and takedown efforts.
Learn more >

Firewall / NGFW

A network security system that monitors and filters incoming and outgoing traffic based on rules. An NGFW adds deeper inspection of applications and threats to block advanced attacks.
Learn more >

Honeypot

A honeypot is a decoy system set up to attract cyberattacks. It helps defenders detect threats and study attacker behavior in a controlled environment.
Learn more >

HTTP Flood

HTTP Flood is a DDoS attack overwhelming servers with massive volumes of legitimate-looking HTTP requests from thousands of bots.
Learn more >

ICMP Flood (Ping Flood)

ICMP Flood is a denial-of-service attack using excessive ping packets to overwhelm network resources and disrupt service availability.
Learn more >

Insider Threat

A risk posed by employees, contractors, or partners who misuse or accidentally expose access to data or systems. It helps identify internal sources of security breaches and loss.
Learn more >

Internet Peering

A direct network interconnection between ISPs, enabling mutual traffic exchange, enhancing efficiency, and reducing costs.
Learn more >

Intrusion Detecting System

A security solution that monitors network traffic for signs of suspicious activity, cyberattacks, or policy violations.
Learn more >

IoA (Indicator of Attack)

An indicator of attack is a sign of suspicious activity that may show an attack is in progress or about to happen. It helps security teams detect and stop threats early.
Learn more >

IoC (Indicator of Compromise)

An indicator of compromise is a digital artifact or behavior that may signal a security breach. It helps security teams detect, investigate, and respond to threats quickly.
Learn more >

IPFIX

A standardized method for exporting network flow data, enabling detailed analysis of traffic patterns.
Learn more >

IPS (Intrusion Prevention System)

An intrusion prevention system monitors network traffic for suspicious activity and blocks detected attacks automatically. It helps protect systems and data from unauthorized access and other threats.
Learn more >

Lateral Movement

Lateral movement is a post-breach technique where attackers move across a network to escalate privileges and access sensitive systems and data.
Learn more >

Malware

Malicious software designed to infiltrate systems, steal data, disrupt operations, or sabotage computers without user knowledge or consent.
Learn more >

Man-in-the-Middle (MitM)

Attack where a hacker intercepts and eavesdrops on communications between two parties, potentially stealing data or altering information.
Learn more >

MITTRE ATT&CK

A knowledge base that classifies and documents cyber threat tactics and techniques enabling effective defence against cyber attacks.
Learn more >

MTTD (Mean Time to Detect)

The average time it takes to detect a security threat or incident. It measures how quickly an organization identifies problems so it can respond sooner and reduce damage.
Learn more >

MTTR (Mean Time to Repair)

The average time needed to repair a system or recover from an incident after a failure is detected. It measures how quickly operations can be restored and downtime reduced.
Learn more >

NAC

A cybersecurity system designed to regulate and manage access to computer networks.
Learn more >

NDR (Network Detection and Response)

A security technology that monitors network traffic to detect suspicious activity and respond to threats. It helps identify attacks early and support incident response.
Learn more >

NetFlow

Information about streams of data flowing through network devices is called NetFlow - the most widely-used standard for flow data statistics
Learn more >

Network Observability

A real-time data analysis, enabling proactive issue resolution and optimization for seamless operations and enhanced security.
Learn more >

Network Topology

A blueprint of device connections, defining data flow patterns and influencing performance and fault tolerance.
Learn more >

NIS2

An EU directive that sets cybersecurity requirements for essential and digital service providers. Its purpose is to improve risk management, incident reporting, and resilience against cyber threats.
Learn more >

Password Spraying

Password spraying is a cyberattack that tries one common password across many user accounts to bypass detection systems.
Learn more >

Phishing

Phishing attacks can be difficult to detect. However, there are steps you can take to protect yourself from phishing attacks.
Learn more >

Port Scanning

A method of detecting vulnerable nodes in a network by accessing different ports on a host or same port on different hosts.
Learn more >

Principle of Least Privilege

A cybersecurity principle limiting user access to essential functions, minimizing risks, and safeguarding sensitive data.
Learn more >

Privilege Escalation

Privilege escalation is an attack where an attacker gains higher-level system access than authorized, exploiting vulnerabilities or misconfigurations.
Learn more >

Process Doppelgänging

A sophisticated malware injection technique that creates and executes malicious processes without being detected.
Learn more >