Resource icon

Security Terminology Glossary: 120 Essential Terms, Examples and Actions

An antivirus warning says "PUA." A news story mentions a zero-day. Your phone offers a passkey. What do these words actually mean for you?

This security terminology glossary explains 120 terms in plain English, with practical examples, common misunderstandings, and next steps. Use it when a security message leaves you guessing.

Updated September 28, 2026 · Beginner-friendly · Windows, phones, accounts, and networks

Start with the question you have​




Jump to a letter​


A · B · C · D · E · F · G · H · I · J · K · L · M · N · O · P · Q · R · S · T · U · V · W · X · Y · Z

Common mix-ups · Example attack · Quick self-check · Questions and answers

A​


Access control​


Rules that decide who or what can use a device, account, file, or service. Authentication checks identity; authorization determines allowed actions.

You can read a shared document but cannot edit it.

Account takeover​


Someone gains unauthorized control of an account, using a stolen password, session, recovery method, or other access route.

Check recovery details, active sessions, and connected apps. Changing the password alone may not remove every route back in.

Advanced persistent threat (APT)​


A capable, well-resourced adversary that pursues targets over time, adapts its methods, and tries to maintain access.

APT describes a sustained threat, not simply a virus that is difficult to remove.

Adware​


Software that displays advertising. It becomes a security or privacy concern when it uses deception, intrusive behavior, or unwanted tracking.

An installer adds an advertising component you did not knowingly agree to install.

AI hallucination​


An AI-generated statement that sounds convincing but is false, unsupported, or invented. Confidence in the wording is not evidence of accuracy.

Verify security commands, download links, and claims against the original documentation before acting on them.

Allowlisting (whitelisting)​


Allowing only specified applications, connections, or other items. Everything outside the approved set is restricted under the policy.

A managed computer runs approved software only. An allowed application can still contain vulnerabilities.

Antimalware Scan Interface (AMSI)​


A Windows interface that lets participating applications submit content to an installed antimalware provider for inspection, including some scripts before execution.

AMSI is a scanning interface, not a separate antivirus or a guarantee that every script will be stopped.

Antivirus (AV)​


Software that detects, blocks, and removes malicious software. Modern antivirus products cover many malware types, not just viruses.

Keep one compatible primary real-time antivirus active. More simultaneously running antivirus engines do not automatically mean better protection.

Attack surface​


All the places where someone could try to enter, influence, or extract data from a system.

An unused browser extension or exposed remote-access service adds opportunities. Removing unnecessary software reduces this surface.

Attack surface reduction (ASR)​


Measures that remove or restrict common attack paths. Microsoft Defender ASR rules can block specific risky behaviors in applications and scripts.

Check the intended use and compatibility. An aggressive rule can also stop legitimate work.

Authentication​


Checking that a person, device, or service is who or what it claims to be, using credentials or another proof.

Signing in with a passkey authenticates you; it does not automatically make you an administrator.

Authorization​


Deciding which actions a user or system may perform.

A forum member can reply but cannot use moderator tools. That difference is authorization.

B​


Backdoor​


A hidden or unauthorized way to access a system while bypassing its normal controls.

A legitimate remote-support app is not inherently a backdoor, but attackers can abuse it for persistent access.

Backup​


A recoverable copy of data kept so it can be restored after loss, corruption, deletion, or an attack.

Restore a harmless file occasionally. Keep a recovery copy isolated from ordinary account or device access.

Behavior monitoring​


Watching what programs actually do, such as modifying startup settings or rapidly changing files, to detect suspicious activity.

A previously unknown program may be stopped because of its actions, even without an exact malware signature.

Blocklist (blacklist)​


A list of items a product or policy blocks, such as domains, addresses, files, or applications.

A new malicious site may not be listed yet. Absence from a blocklist does not prove safety.

Botnet​


A group of devices remotely coordinated by an operator, commonly after compromise, to perform attacks or other abusive activity.

Compromised routers may be used together to flood a website. The owners might notice no obvious warning.

Browser extension​


An add-on that changes or extends browser functions. Its permissions determine what information and websites it can access.

A simple calculator usually has little reason to read every website you visit. Review its purpose, publisher, and requested access.

Brute-force attack​


Repeated guessing of a password or other secret. Exhaustive brute force tries every possibility; real attacks often prioritize likely guesses.

Long, unique passwords and service-side rate limits make guessing harder. MFA adds another barrier.

Bug​


A software mistake causing unexpected behavior. Some bugs affect security; others affect reliability or usability.

A crash alone does not prove malware or an exploitable vulnerability.

C​


Certificate authority (CA)​


An organization or system that issues digitally signed certificates connecting a public key with an identity, such as a domain.

A domain-validated website certificate checks domain control, not whether the operator is honest or its products are legitimate.

ClickFix​


Social engineering that tells you to run a command to fix an error, complete a CAPTCHA, or unlock content.

A website asking you to paste a command into Run, PowerShell, or Terminal for human verification is a serious warning sign.

Cloud sync​


Keeping files or settings consistent across devices. Changes on one device may propagate to the others.

Deletion or ransomware damage can sync too. Version history helps, but check its retention and recovery limits before treating sync as backup.

Cloud-delivered protection​


Security checks that consult a vendor's online systems for threat information, reputation, analysis, or rapid blocking decisions.

Protection and data submission vary by product and settings. Read what the service sends before assuming every file stays local.

Command and control (C2)​


The communication attackers use to send instructions to compromised systems and sometimes receive stolen information.

A backdoor checks an external server for tasks. Ordinary software also contacts servers, so a connection alone is not proof.

Cookie​


Data a website asks your browser to store and send back when appropriate. Cookies can support sign-ins, preferences, shopping carts, or tracking.

A cookie is not itself an executable virus. A stolen authentication cookie can still be highly sensitive.

Credential stuffing​


Trying username-and-password pairs stolen from one service against other services, relying on people reusing passwords.

Use a different password for every account. A breach at one site should not unlock your email too.

Cryptography​


Mathematical techniques that help protect information and establish trust, including encryption, hashing, and digital signatures.

Encryption hides content. A signature checks authenticity and integrity. These are different jobs within cryptography.

CVE (Common Vulnerabilities and Exposures)​


A naming system for publicly disclosed cybersecurity vulnerabilities. A CVE identifier lets different organizations refer to the same issue.

Check the affected product, version, configuration, and vendor guidance. An identifier does not tell you whether your device is exposed.

CVSS (Common Vulnerability Scoring System)​


A standard for describing vulnerability characteristics and scoring severity. Scores run from 0 to 10.

A high base score is not the probability that you will be attacked. Exposure, exploitation, and local impact also matter.

D​


Data breach​


An incident in which information is accessed, disclosed, or obtained without authorization.

A leaked email address, stolen password hash, and copied medical record create different risks. Read which data was actually involved.

DDoS (distributed denial of service)​


An attack using many sources to exhaust a service's bandwidth or other resources, making it slow or unavailable.

A service outage does not automatically mean its customer database was stolen.

Decryption​


Turning encrypted information back into readable form using the appropriate key and process.

Removing ransomware does not necessarily decrypt files. A working decryptor must match the ransomware and circumstances.

Deepfake​


Audio, video, or imagery generated or altered with AI to imitate a person or event.

A familiar voice asking for money is not enough. Contact the person through a trusted number or established channel.

Device encryption​


Encryption of stored data on a phone, laptop, or drive, mainly protecting it against unauthorized access when the device is locked or powered off.

Keep the recovery key somewhere separate and secure. Encryption does not stop every threat on an unlocked device.

Digital footprint​


The information left about you through online activity, including posts, account records, interactions, and data others collect or publish.

Review old public profiles and sharing settings. Deleting your copy may not erase copies held elsewhere.

Digital signature​


A cryptographic mechanism for checking that data was signed using a particular key and has not changed since signing.

A valid software signature identifies a signer; it does not guarantee harmless behavior or prove the signer was never compromised.

DNS (Domain Name System)​


The system that looks up information associated with domain names, including the IP addresses used to reach websites.

DNS helps your browser find malwaretips.com. It does not decide whether every page on a resolved website is trustworthy.

DNS over HTTPS (DoH)​


Sending DNS queries through an encrypted HTTPS connection to a chosen resolver.

DoH protects that lookup connection. It does not make browsing anonymous or automatically block malicious sites.

Drive-by download​


An unwanted download initiated while visiting a website, sometimes using a browser or software vulnerability to run malicious code.

A downloaded file is not necessarily an executed infection. Keep the browser updated and do not open unexpected downloads.

E​


EDR (endpoint detection and response)​


Tools that collect device activity, identify suspicious behavior, and help investigate and contain incidents.

EDR supports ongoing detection and response, commonly for organizations. It is not simply another name for a consumer antivirus scan.

Encryption​


Converting readable data into a protected form that requires the appropriate key to read.

Device encryption protects stored files; HTTPS protects a connection. Neither guarantees that the person or application using the data is trustworthy.

End-to-end encryption (E2EE)​


Encryption designed so that message content is readable by the communicating endpoints, rather than intermediary services carrying it.

Compromised devices, recipient screenshots, metadata, and backup arrangements can still expose information. Check what the particular service actually protects.

Endpoint​


A device at the edge of a network, such as a computer, phone, or server, where people or applications access services.

An endpoint protection product runs on devices. It does not necessarily protect every account or router around them.

EPSS (Exploit Prediction Scoring System)​


An estimate of the probability that a published vulnerability will be exploited in the wild during the next 30 days.

EPSS estimates likelihood; CVSS describes severity. Neither directly measures the risk to your specific computer.

Exploit​


A technique or code that takes advantage of a vulnerability to cause behavior the system should not allow.

The vulnerability is the weakness. The exploit uses it. The payload is what the attacker then delivers or runs.

Exploit protection​


Defenses that make particular exploitation techniques harder, such as restrictions on memory use or application behavior.

These defenses reduce opportunities; they do not repair the underlying bug. Install the vendor's security fix too.

F​


False negative​


A threat that a security check fails to identify or block.

Zero detections does not prove a file is harmless. New threats, missing context, or limited scan coverage can produce a clean-looking result.

False positive​


A legitimate item or harmless activity incorrectly flagged as malicious or prohibited.

Check the exact detection and file origin, then seek a vendor review. Do not disable protection simply because someone calls it a false positive.

Fileless malware​


A broad label for threats that perform important stages in memory or through existing system tools, rather than relying only on a standalone malicious file.

Fileless does not mean traceless. Scripts, registry changes, logs, or other files can still be involved.

Fingerprinting​


Identifying or linking devices, browsers, or users using a combination of observable characteristics.

A browser's settings and capabilities can help distinguish it. Clearing cookies does not necessarily erase a fingerprint.

Firewall​


A control that allows or blocks network traffic according to rules, connection state, and sometimes application context.

A firewall is not a replacement for antivirus. Allowed traffic can still carry malicious content.

Firmware​


Software closely tied to a device's hardware, such as a router's operating code or a computer's startup firmware.

Install applicable updates from the manufacturer. An antivirus update does not automatically update your router's firmware.

G​


Gateway​


A connection point between networks or services.

Your router is usually your internet gateway. It needs protection even when your devices have antivirus.

H​


Hashing​


Calculating a digest from data. Cryptographic hashes can help check file integrity; password storage needs specially designed password-hashing methods.

A matching hash proves a file matches the reference, not that it is safe. Ordinary hashing is not reversible encryption.

Heuristic detection​


Identifying suspicious characteristics or patterns that suggest malware, rather than requiring an exact match to a known threat.

Heuristics can detect unfamiliar threats and can also flag legitimate software. A generic label needs context.

HTTP and HTTPS​


HTTP carries web requests and responses. HTTPS adds TLS protection for the connection and authenticates the server through certificates.

A phishing site can use HTTPS. An encrypted connection is not an endorsement of the page, shop, or download.

I​


Incident response​


The work of investigating, containing, removing, and recovering from a security incident while preserving useful evidence.

Record the warning and time. On a work device, contact IT before running cleanup tools or deleting evidence.

Indicator of compromise (IOC)​


An observable clue associated with potentially malicious activity, such as a file hash, domain, or unusual system change.

One clue is not always proof. Shared infrastructure and outdated indicators can create misleading matches.

Infostealer​


Malware designed to collect valuable information, such as saved credentials, browser sessions, wallet data, or files.

Cleaning the device does not retrieve stolen secrets. Protect affected accounts from a trusted device and revoke exposed sessions.

IoT (Internet of Things)​


Network-connected physical devices such as cameras, TVs, doorbells, and thermostats.

Change default credentials where applicable, install supported updates, and separate less-trusted devices from sensitive systems when your router supports it.

J​


Jailbreaking and rooting​


Removing or bypassing device restrictions to gain capabilities beyond the normal user environment, commonly on iOS or Android.

These changes can weaken security assumptions and app protections. They are different from an AI jailbreak prompt.

K​


Keylogger​


Software or hardware that records keystrokes. Attackers use it to capture information; some monitoring tools also include this capability.

A password manager reduces typing, but it does not make an infected device safe from other credential-stealing techniques.

Known exploited vulnerability (KEV)​


A vulnerability for which exploitation has been observed. CISA's KEV catalog records issues meeting its inclusion criteria.

Check whether the affected product and version are present. Absence from the catalog does not prove a flaw is unused or harmless.

L​


Least privilege​


Giving each user, application, or service only the access needed for its job, for no longer than necessary.

A note-taking app should not need administrator rights just to save a text file.

Living off the land (LOTL)​


Abusing legitimate tools and features already available in an environment to perform malicious activity.

An attacker uses a built-in scripting tool. The tool's genuine name or signature does not make that particular use safe.

Loader and dropper​


Malware components that introduce other malicious code. A loader runs or prepares another payload; a dropper places it on a system.

Removing the initial installer does not prove that every payload it delivered has also been removed.

M​


Malvertising​


Using advertising systems or ad placements to distribute malicious redirects, downloads, or deceptive content.

An ad shown on a reputable website is not automatically trustworthy. Check the destination before downloading or signing in.

Malware​


Software or code intended to harm, steal, spy, disrupt, or gain unauthorized access. Viruses, trojans, worms, and ransomware are different examples.

Malware is the umbrella term. A device can have malware without having a computer virus specifically.

Man-in-the-middle (MitM) or adversary-in-the-middle (AiTM)​


An attacker positions themselves between communicating parties to intercept, relay, or sometimes alter their interaction.

A phishing proxy can relay a sign-in and steal a session. It does not need to break the site's encryption to deceive you.

MFA fatigue (push bombing)​


Repeated authentication approval requests intended to make someone accept an unexpected prompt through confusion or annoyance.

Deny prompts you did not initiate. Open the account's security settings independently and investigate the sign-in activity.

Multi-factor authentication (MFA)​


Authentication using more than one type of proof, such as something you know and something you possess. Two-factor authentication uses two factors.

Two passwords are not two factors. SMS and typed codes can be phished; passkeys provide phishing-resistant sign-in.

N​


Network segmentation​


Separating systems into network zones and restricting traffic between them to limit access and the spread of an intrusion.

A guest network can separate visitors' devices, but check whether the router actually blocks access to your main network.

O​


OAuth consent​


Permission for an application to access specified account data or functions through an authorization system, without necessarily receiving your password.

A connected app may retain access until its authorization is revoked. Changing your password may not remove that permission.

On-demand scan​


A security scan started manually or on a schedule to inspect selected files, locations, or the system.

It complements real-time protection. Its coverage depends on scan type, settings, access, and what the product can inspect.

Open source​


Software distributed under a license that permits access to its source code and specified rights to use, modify, and redistribute it.

Public code is available for inspection; that does not prove it has been audited or that every download is safe.

P​


Passkey​


A sign-in credential based on a cryptographic key pair, usually unlocked with your device's PIN or biometrics rather than a typed account password.

Passkeys resist phishing. They can be synced or device-bound, but device compromise and account recovery still need protection.

Password manager​


A tool that creates and stores account credentials in a protected vault and helps fill them on the appropriate sites.

Use unique generated passwords, protect the vault account, and keep a recovery plan you can access if your main device is lost.

Password spraying​


Trying a small set of common passwords against many accounts, often to avoid repeatedly guessing against one account.

Credential stuffing tries stolen combinations. Spraying tries likely passwords across a broad set of usernames.

Patch​


An update that fixes a software problem, including a security vulnerability. Some updates add features without fixing the issue you are investigating.

Use the official update channel, restart when required, and confirm the corrected version was actually installed.

Payload​


The code or action delivered by an attack, such as stealing information, encrypting files, or opening remote access.

A malicious installer is the delivery route; the infostealer it runs is a payload. One attack may deliver several.

Phishing​


Deception that impersonates a trusted person or service to make you disclose information, authorize access, pay, or open malicious content.

Spear phishing targets someone specifically. Smishing uses texts, vishing uses voice calls, and QR phishing hides the route behind a scannable code.

Potentially unwanted application or program (PUA/PUP)​


Software a security vendor considers unwanted because of behavior such as bundling, misleading offers, advertising, or intrusive changes.

A PUA detection is not necessarily a trojan diagnosis. Review what the software does and whether you deliberately chose it.

Privilege escalation​


Gaining permissions beyond those originally available, such as moving from a standard account to administrator access.

Malware exploits a flaw to change protected settings. Starting with limited permissions reduces what it can do immediately.

Prompt injection​


Instructions placed in input an AI system processes, intended to redirect it away from its legitimate task or rules.

A document tells an assistant to reveal private data. Treat retrieved content as information, not authority to perform new actions.

Q​


Quarantine​


Restricted storage where a security product isolates a detected item to prevent normal access or execution.

Leave suspicious items isolated while investigating. Restoring a file can make it usable again; quarantine does not undo data already stolen.

R​


Ransomware​


Malware used to deny access to systems or data, commonly by encryption, and demand payment. Attacks may also involve stolen-data extortion.

Maintain tested, protected backups. Payment does not guarantee recovery, deletion of stolen data, or removal of attacker access.

Real-time protection​


Security monitoring that checks relevant activity as it happens, rather than only during a scheduled or manually started scan.

A file can be checked when downloaded, opened, or executed. A clean scan from yesterday cannot cover everything you do today.

Recovery code​


An emergency sign-in code used when the usual authentication method is unavailable. Many services issue single-use codes.

Keep codes private and accessible without the lost device. A recovery code is not the same as a disk-encryption recovery key.

Remote access trojan (RAT)​


Malware that gives an attacker remote capabilities such as viewing files, running commands, or monitoring activity.

Legitimate remote-access software can also be abused. Whether you intended and authorized the access matters.

Remote code execution (RCE)​


The ability to cause code to run on another system remotely, often by exploiting a vulnerability.

An RCE flaw may require authentication, a particular configuration, or user interaction. The label alone does not tell you the attack requirements.

Reputation-based protection​


Using information such as prevalence, publisher history, or observed behavior to judge files, websites, or applications.

An unfamiliar program is not automatically malware, and a previously reputable source can be compromised. Check why the warning appeared.

Rootkit​


Tools or code that conceal malicious activity or maintain privileged access by altering low-level system behavior.

A rootkit can interfere with ordinary inspection. Repeated suspicious behavior may require specialist investigation rather than repeated quick scans.

S​


Sandboxing​


Running code in a restricted environment to limit its access or observe its behavior.

A sandbox is not an absolute barrier. Shared folders, network access, configuration mistakes, or escape vulnerabilities can expose the host or other systems.

Scareware​


Deceptive warnings that frighten people into installing software, paying, or contacting fake support.

A webpage claims it found hundreds of infections. That claim is not equivalent to a detection from your installed security software.

Secure Boot​


A startup security feature that checks authorized signatures on boot components to help block unauthorized code early in the boot process.

Secure Boot protects part of startup. It does not inspect every website, document, or application you use afterward.

Security key​


A physical authenticator used to prove possession during sign-in. FIDO-compatible keys can provide phishing-resistant authentication, including device-bound passkeys.

Enroll a spare or another secure recovery method before you depend on one key for important accounts.

Security support and end of life (EOL)​


The period when a vendor provides security fixes, and the point when that support ends for a product or version.

A device may still function after support ends. Antivirus cannot replace missing operating-system or firmware fixes.

Session hijacking​


Taking over an authenticated session, often by obtaining a usable session token or cookie, instead of signing in normally.

A stolen session may bypass a fresh MFA prompt. Use the account's session-revocation controls when recovering from compromise.

SIEM (security information and event management)​


A system that collects and correlates security logs to help organizations detect and investigate suspicious activity.

Collecting logs is not the same as stopping attacks. Useful rules and someone who responds to alerts still matter.

Signature-based detection​


Identifying known threats using recognizable patterns or other matching information associated with malicious content.

This kind of signature detects threats. A software publisher's digital signature verifies a signer and file integrity.

SIM swap​


Transferring a phone number to a SIM or eSIM controlled by someone else, through a compromised carrier process or account.

Unexpected loss of mobile service can be a clue. Contact the carrier independently and protect accounts using that number for recovery.

Social engineering​


Manipulating people into taking actions that help an attacker, often by exploiting urgency, authority, trust, fear, or curiosity.

Someone posing as IT asks you to approve a login. Verify the request through an established contact route.

Spyware​


Software that collects information about a person or device without appropriate knowledge or consent.

Monitoring can include browsing activity, messages, location, or screen content. Not every spyware program relies on recording keystrokes.

SSL and TLS​


Protocols associated with protecting network communications. TLS is the modern successor; SSL is obsolete but survives in informal product names.

A service advertised as using an "SSL certificate" may actually use modern TLS. The negotiated protocol and configuration matter.

Supply-chain attack​


Compromising a supplier, dependency, update channel, or other trusted component to reach its downstream users.

An attacker tampers with a legitimate software update. Downloading from an official source reduces risk but cannot eliminate every possibility.

T​


Tamper protection​


Controls that make it harder for malware or unauthorized users to disable or alter security settings.

Implementation varies by product. Tamper protection does not mean that every setting or component is impossible to change.

Threat intelligence​


Information analyzed to explain threats, attacker behavior, targets, or useful defensive actions.

Does this information identify an affected product or action for you, or is it only a dramatic headline?

TPM (Trusted Platform Module)​


A hardware-backed security component that can protect cryptographic keys and support checks of a device's startup state.

A TPM supports features such as device encryption. Having one does not mean all your files are encrypted or your computer is malware-free.

Trojan horse​


Malicious software presented as something legitimate or desirable to persuade someone to use it.

A supposed game mod installs an infostealer. Trojans do not need to replicate themselves like viruses or worms.

U​


URL spoofing​


Using a misleading web address or link presentation to imitate a trusted destination.

Read the actual destination, not just the logo or clickable text. Familiar words in a subdomain or path do not prove ownership.

User Account Control (UAC)​


A Windows feature that asks for approval or administrator credentials when an action needs elevated permissions.

Check the application and why it needs access. UAC is not an antivirus verdict or a reason to approve every installer.

V​


Virtual private network (VPN)​


A connection that creates a protected tunnel between your device and a VPN endpoint. Sites often see the VPN server's address for tunneled traffic.

A VPN does not make you anonymous, remove malware, or stop account tracking. You also place trust in the VPN operator.

Virus​


Malicious code that replicates by attaching to or modifying a host such as a file or document.

A trojan deceives you into running it. A worm can spread independently. People often use "virus" loosely for all malware.

Vulnerability​


A weakness in software, hardware, configuration, or a system's controls that can be exploited to cause harm.

A vulnerability can exist without an attack. Risk depends on exposure, exploitability, and what would be affected.

W​


Worm​


Malware capable of replicating and spreading between systems without attaching itself to a host file.

A worm abuses a network service to spread. Infection can still depend on vulnerable software, configuration, or an initial user action.

X​


XDR (extended detection and response)​


An approach that combines detection and response information across multiple security areas, such as endpoints, identities, email, and cloud services.

Coverage and automation vary by vendor. The label does not guarantee that every product integrates with every other tool.

Y​


YARA rules​


Rules that match specified patterns and conditions in data, widely used to identify or investigate malware and related artifacts.

A match is a clue based on that rule. Broad rules can also match harmless files; context and validation matter.

Z​


Zero trust​


A security approach that avoids granting trust solely because a user or device is inside a particular network or belongs to an organization.

Access decisions consider identity, device state, and the resource requested. Zero trust is an architecture, not a single product you install.

Zero-day vulnerability​


A flaw for which defenders lack an available fix when it becomes known or is exploited. Usage varies, so read the disclosure timeline.

A zero-day vulnerability is the weakness; a zero-day exploit uses it. "Zero-day" does not mean every device is already infected.

Eight differences that prevent expensive mistakes​


TermsThe difference that matters
Malware / virusMalware is the whole category; a virus is one type. Infostealers need not be viruses.
Authentication / authorizationIdentity verification versus permission to act. A valid sign-in should not grant unlimited access.
Encryption / hashing / signatureEncryption protects readability. Hashing checks sameness against a reference. A digital signature checks signing-key authenticity and integrity.
Backup / syncSync propagates changes. A backup preserves a usable recovery copy.
Vulnerability / exploit / payloadThe weakness, the way it is used, and the resulting code or action.
MFA / phishing-resistant MFAMFA adds factors. Typed codes and approval prompts can still be tricked; FIDO authentication resists fake-site sign-ins.
Detection / protectionRecognizing a file is different from preventing compromise. Product behavior after execution and during an attack also matters.
Quarantine / recoveryIsolation limits further execution. Stolen credentials and encrypted files still need attention.

What your security alert is really telling you​


Check the detection name, affected item, time, and action together. Wording varies by product.

The alert saysA sensible response
Blocked or quarantinedCheck the affected item and completed action. A download guide telling you to restore it is not evidence of safety.
PUA or PUPReview unwanted behavior and installation source. Decide whether you actually want the application.
Generic, heuristic, or behavior detectionA detection approach, not proof of a false alarm or a precise malware-family diagnosis.
Remediation incomplete or action neededFollow the installed security app's instructions. Investigate repeated failures or returning detections.
A webpage says you have virusesDo not call, pay, or install its tool. Check your security app independently.


Ask in the malware-removal support forum with the exact alert and what happened. Remove personal information from screenshots.

How the terms fit together​


A fictional example:

  1. The lure: A fake browser update is social engineering. An ad delivering it may be malvertising.
  2. The installer: It looks useful but runs a loader. That deceptive program is a trojan.
  3. The theft: The payload is an infostealer. It collects usable browser sessions and sends data through attacker-controlled infrastructure.
  4. The access: Session hijacking reuses a stolen session, potentially avoiding a new MFA prompt.
  5. The recovery: Clean the device and protect accounts. Revoke sessions, check recovery settings, and remove unauthorized connected apps.

Read antivirus tests without being misled​


Before comparing protection percentages, check:

  • Test type: File detection, real-world protection, phishing, and performance measure different things.
  • Conditions: Version, settings, internet connectivity, operating system, and test period.
  • False positives: Consider missed threats and wrongly blocked legitimate files together.
  • Sample size: Small numerical gaps may not be meaningful. Read the lab's interpretation.
  • Your use: Consider compatibility, usability, support, and performance too.

Compare the methodologies from AV-Comparatives and AV-TEST, not just the final scores.


Check your understanding​


  1. A shop uses HTTPS. Does that prove the seller is legitimate?
  2. You delete a file and it disappears from every synced device. Was sync enough to guarantee recovery?
  3. An antivirus quarantines an infostealer. Are the sessions it already stole automatically invalidated?
  4. A vulnerability has a high CVSS base score. Is that your personal probability of being attacked?

No to all four. HTTPS protects a connection; recovery depends on available copies; stolen sessions need revocation; severity is different from likelihood and exposure.

Frequently asked questions​


Which terms should I learn first?​


Start with malware, phishing, antivirus, patches, backups, passwords, MFA, and passkeys. Then look up unfamiliar terms when they appear in a real alert or discussion.

Does paid antivirus always protect better than free antivirus?​


Price alone cannot answer that. Compare independently tested protection, false alarms, features, support, and compatibility for the specific products and versions.

Can I have malware if every scan is clean?​


Yes. Scans have limits. Investigate specific evidence, such as unauthorized account changes or recurring detections, rather than treating ordinary slowness as proof of infection.

Does MFA make account theft impossible?​


No. MFA helps, but recovery processes, phishing, malicious app consent, and stolen sessions can still matter. Protect the device and the account's recovery routes too.

Should I upload a suspicious file to an online scanner?​


Check the service's sharing policy first. Never upload confidential work files, private documents, or credentials unless you are authorized and understand how they will be handled.

Where should I go from here?​


Choose one useful action: set up a passkey, test a backup, or review browser extensions.

Bookmark this security terminology glossary for the next unfamiliar warning, setting, or forum reply.

Back to the alphabet
  • Like
Reactions: Jack
Posted by
Bot AI
Views
488
First release
Last update

Ratings

0.00 star(s) 0 ratings