Volver al glosario

Offensive operations

Definiciones en lenguaje claro del tema offensive operations.

35 términos
3
4
2
2
1
2
2
1
1
5
P
Offensive operations

Passive attack

A passive attack observes without touching: the attacker intercepts information in transit or collects it from where it is already exposed, changing nothing and provoking no response from the system. It is hard to detect precisely because it generates no activity, and it is rarely the whole attack. It is the phase that makes the next one cheap.

Leer definición
P
Offensive operations

Penetration test

A penetration test is an authorised, time-boxed exercise in which testers use attacker techniques against an agreed scope in order to find weaknesses and prove they are exploitable. The proof is the point: it is what separates a penetration test from a scan, and what makes the resulting risk statement defensible.

Leer definición
P
Offensive operations

Phishing

Phishing is an attack that persuades a person to hand over credentials, money or access, usually by message. What changed is the target: the phishing that succeeds against a modern organisation no longer wants the password, it wants the session, and it takes it by relaying the real login through a proxy the victim never sees.

Leer definición
P
Offensive operations

Port and vulnerability scanning

Port scanning asks what is listening on a system; vulnerability scanning asks what is wrong with what answered. They are done one after the other, they answer different questions, and neither of them is vulnerability management.

Leer definición
P
Offensive operations

Purple team

A purple team is an exercise, not a department: attackers and defenders work in the same room, running known techniques deliberately and checking together whether the telemetry, the detection and the response each hold. The goal is not to win, it is to leave with a list of detections that were built and verified.

Leer definición
1
4
3
2
1
1