ALL PASS, NO FAIL!

CEH Glossary: 263 Cybersecurity Terms with Exam Notes

Every term the CEH v13 (312-50) exam can throw at you, in reading order A–Z. Definition first; the grey note under each one says what the exam actually asks about it.

A

Active Directory Attack Techniques

Kerberoasting, AS-REP Roasting, Pass-the-Hash, DCSync, Golden/Silver Ticket, BloodHound enumeration, Shadow Credentials, ACL abuse, GPP (Group Policy Preferences) exploitation.

Active Directory Persistence Attacks

Skeleton Key (Mimikatz), Overpass the Hash, Malicious Replication, WMI Event Subscription persistence (PowerLurk), AdminSDHolder abuse. Methods to maintain access in AD environments.

Active Reconnaissance

Directly interacting with the target system to gather information. Examples: network scanning, ping sweeps, DNS zone transfers, enumeration. More likely to be detected by security systems and IDS.

Active Session Hijacking

Takes over active session by breaking connection or actively participating as MITM. Must guess sequence number before target responds.

Acunetix Scanner

Automated web application vulnerability scanner with deep Vulnerability Detection technology. Detects SQL injection, XSS, CSRF, and other OWASP Top 10 vulnerabilities.

Advanced Persistent Threat (APT)

An Advanced Persistent Threat (APT) is a prolonged, targeted cyberattack in which an adversary gains unauthorized access to a network and remains undetected for an extended period. The primary goal is data theft, espionage, or sabotage rather than immediate disruption. APTs are typically state-sponsored or well-funded criminal organizations with advanced capabilities, dedicated resources, and long-term operational planning.

On the CEH v13 exam: APTs are referenced throughout CEH v13, particularly in Modules 07 (Malware), 05 (Vulnerability Analysis), and the overall exam context. The exam tests knowledge of APT characteristics (targeted, persistent, advanced, organized), real-world examples (Stuxnet as first major discovered APT, targeting Iranian nuclear facilities via industrial control systems), the Lockheed Martin Cyber Kill Chain phases, MITRE ATT&CK framework awareness, and detection strategies (UEBA, threat intelligence, network traffic analysis for low-and-slow exfiltration).

AMSI Bypass

Antimalware Scan Interface bypass to prevent PowerShell scripts from being scanned by antivirus. Common technique: patching amsi.dll AmsiScanBuffer function in memory.

Android Security Vulnerabilities

APK reverse engineering, insecure data storage (SQLite, shared preferences), insufficient transport layer encryption, weak server-side API controls, code obfuscation bypass (ProGuard), malicious third-party app stores.

API Security

Securing application programming interfaces: authentication/authorization, rate limiting, input validation, encryption in transit, monitoring for abuse, OWASP API Security Top 10.

ARP Spoofing

ARP Spoofing (also called ARP Cache Poisoning) is a Layer 2 attack where an attacker sends forged Address Resolution Protocol (ARP) messages onto a local network to associate their MAC address with the IP address of another device (typically the default gateway). This causes all traffic destined for that IP to be routed through the attacker, enabling man-in-the-middle interception.

On the CEH v13 exam: ARP spoofing is covered in CEH v13 Module 08 (Sniffing and Traffic Analysis) as a primary sniffing technique. The exam tests understanding of ARP protocol mechanics (ARP request/reply format, cache table structure, gratuitous ARP), how to detect ARP poisoning (monitoring for duplicate IP-to-MAC mappings, comparing ARP tables across hosts), defensive countermeasures (Dynamic ARP Inspection on managed switches, static ARP entries on critical systems, port security), and the limitations of ARP spoofing (only works on same Layer 2 broadcast domain/VLAN). Questions may present ARP cache outputs for anomaly identification.

AS-REP Roasting

Cracking Kerberos TGT ticket targeting users who do NOT have Kerberos pre-authentication required. Extract AS-REP ticket → crack offline for user password.

Asymmetric Encryption

Mathematically related public/private key pair. Public key encrypts, private key decrypts (and vice versa for signatures). Algorithms: RSA, ECC, Diffie-Hellman. Slower than symmetric but solves key distribution.

Attack Trees

Hierarchical model of possible attacks against a system. Root = attacker goal. Branches = methods. Leaves = specific techniques. Used for threat modeling and risk assessment.

Authenticated vs Unauthenticated Scanning

Authenticated scanning uses valid credentials to log into targets for deeper assessment including configuration review and patch level. Unauthenticated scanning only observes from outside the network, missing many configuration issues.

B

Baiting

Offering something enticing to the victim to lure them into a trap. Examples: leaving infected USB drives in parking lots, offering free downloads, promising exclusive content in exchange for credentials.

Bettercap

Advanced network attack and monitoring framework for Linux. Capabilities: ARP spoofing, DNS spoofing, HTTP proxying, Bluetooth attacks, WiFi deauth detection. Modern replacement for Ettercap in many scenarios.

Black Hat Hacker

A malicious hacker who exploits system vulnerabilities for personal gain, financial profit, or unauthorized access. Operates without permission and violates computer fraud laws.

Blockchain Security Concepts

Distributed ledger technology security: 51% attack, double-spending, smart contract vulnerabilities, private key management, consensus mechanism attacks (PoW, PoS).

BloodHound Tool

Powerful Active Directory enumeration tool using Neo4j graph database. Maps relationships between users, computers, groups, and GPOs to find attack paths for privilege escalation.

Blue Team (Defensive Security)

Defensive security professionals responsible for detecting, responding to, and recovering from cyberattacks. Activities: monitoring SIEM, incident response, threat hunting, patch management.

Brute Force Attack

Password cracking method systematically trying every possible character combination until the correct one is found. Effective against short/simple passwords but slow on strong ones.

Buffer Overflow

A Buffer Overflow is a memory corruption vulnerability that occurs when a program writes more data to a buffer than it can hold, overwriting adjacent memory. This allows an attacker to modify program execution flow, inject and run arbitrary code, or cause a denial of service by corrupting critical data structures.

On the CEH v13 exam: Buffer overflows are central to CEH v13 Module 06 (System Hacking). The exam tests understanding of memory layout (stack frames, heap structure), exploitation methodology (finding EIP offset, NOP sleds, ROP chains), and modern mitigations including Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP/NX bits), stack canaries, and Control Flow Integrity (CFI). Questions often present assembly or C code snippets for vulnerability identification.

Bug Bounty Program

Incentive program where organizations reward ethical hackers for discovering and reporting vulnerabilities. Platforms: HackerOne, Bugcrowd, Intigriti. Ranges from $50 to $1M+ for critical findings.

Burp Suite

Integrated platform for web application security testing. Features: proxy, scanner, intruder, repeater, repeater, sequencer, decoder, comparer. Community (free) and Professional editions.

Business Continuity Plan (BCP)

A documented process to ensure that essential business functions can continue during and after a disaster. Includes incident response procedures, backup systems, recovery sites, communication plans, and regular testing schedules.

C

CEO Fraud / Business Email Compromise

Impersonating executive to request wire transfers or sensitive information from employees, particularly finance departments. Also called Business Email Compromise (BEC).

Certificate Pinning

Mobile security technique locking an app to specific certificate or public key, preventing MITM attacks even if device's trusted CA store is compromised. Bypass techniques exist but provide strong defense.

Chain of Custody

Documented chronological record of evidence handling from collection through court presentation. Ensures evidence integrity and admissibility in legal proceedings.

CIA Triad

The foundational information security model consisting of three pillars: Confidentiality (data not disclosed), Integrity (data not tampered with), Availability (data accessible when needed). All other security controls map back to one or more of these principles.

Clickjacking Attack

Tricks user into clicking hidden/misleading elements using invisible iframe overlaying legitimate content. Prevention: X-Frame-Options DENY/SAMEORIGIN, CSP frame-ancestors directive.

Clone Phishing

Resending a legitimate email with a malicious link or attachment replacing the original. Uses the credibility of the previous communication to trick the recipient.

Cloud Cryptojacking

Unauthorized use of cloud resources for cryptocurrency mining. Detected via unusual CPU/billing patterns. Prevention: Resource monitoring alerts, IAM least privilege, container security scanning.

Cloud Deployment Models

Public Cloud (shared infrastructure), Private Cloud (dedicated), Hybrid Cloud (combination), Multi-Cloud (multiple providers), Community Cloud (shared by organizations with common requirements).

Cloud Forensics Challenges

Challenges: multi-tenancy, data location jurisdiction, volatile evidence, reliance on provider APIs, lack of physical access. Techniques: snapshot analysis, log collection, API audit trails.

Cloud Misconfiguration Risks

Public S3 buckets, insecure APIs, weak IAM policies, cross-account permission issues, data exposure from encryption misconfiguration, insufficient audit logging. Most common cloud security issue.

Cloud Service Models

IaaS (Infrastructure as a Service — EC2, VMs), PaaS (Platform as a Service — Heroku, App Engine), SaaS (Software as a Service — Office 365, Salesforce), FaaS (Function as a Service — Lambda).

Cloud Shared Responsibility Model

Provider secures: Infrastructure, physical security, hypervisor. Customer secures: Data, access management, OS configuration, applications. Different for each service model — IaaS customer manages more, SaaS provider manages more.

Cobalt Strike

Commercial adversary simulation platform used by red teams. Features: Beacon (payload), Malleable C2 (traffic obfuscation), resource editor, payload generation, lateral movement tools.

Command Injection

Command Injection (also called OS Command Injection or Shell Injection) is a vulnerability that allows an attacker to execute arbitrary operating system commands on the underlying server by injecting malicious input into application parameters that are passed to system call functions (system(), exec(), popen() in C; Runtime.exec() in Java; os.system() in Python).

On the CEH v13 exam: Command injection is covered in CEH v13 Module 14 (Hacking Web Applications) alongside SQL injection and XSS as a key injection vulnerability. The exam tests knowledge of shell metacharacters and their functions (;, |, &&, ||, $(), backticks), how to identify vulnerable endpoints (parameters passed to system calls), blind/OOB injection techniques, prevention strategies (input validation with allowlists, avoiding shell interpretation via parameter arrays, output encoding, containerization/sandboxing), and differences from SQL injection (OS-level vs database-level). Questions may present code snippets for vulnerability identification.

Container Security

Security for Docker/Kubernetes environments: image scanning, runtime protection, network policies, secrets management, least privilege, vulnerability assessment of base images.

CRIME Attack

Compression Ratio Leak Made Easy. Client-side attack exploiting TLS/HTTP compression ratio to infer cookies by analyzing compressed packet sizes. Applies to SSL/TLS, SPDY, HTTPS. Prevention: Disable TLS compression.

Cross-Site Scripting

Cross-Site Scripting (XSS) is a web security vulnerability that allows an attacker to inject malicious JavaScript or HTML into web pages viewed by other users. The injected script executes in the victim's browser with the victim's permissions, enabling session theft, data exfiltration, and account compromise.

On the CEH v13 exam: XSS is covered in CEH v13 Module 14 (Hacking Web Applications) and the OWASP Top 10. Exam questions test your ability to identify XSS vectors in code samples, distinguish between reflected/stored/DOM-based variants, understand browser security context (same-origin policy bypass via session cookies), and apply prevention measures like Content Security Policy (CSP) headers and output encoding.

Cryptographic Hash Functions

One-way functions producing fixed-size digest: MD5 (128-bit, broken), SHA-1 (160-bit, deprecated), SHA-256 (256-bit, secure), SHA-512 (512-bit, secure), BLAKE3 (modern), bcrypt/scrypt/Argon2 (password hashing).

Cryptomining Malware

Hijacks victim system resources to mine cryptocurrency without consent. Uses Proof-of-Work algorithms. Also called 'Cryptojacking.' Can be inline (web-based) or installed (malware). Signs: high CPU/GPU usage, increased power consumption.

CSRF (Cross-Site Request Forgery)

Cross-Site Request Forgery (CSRF) is an attack that forces an authenticated user's browser to send unintended requests to a trusted application. The attacker crafts a malicious request (form submission, link click, image load) that is automatically sent with the victim's valid session cookies, causing actions to be performed as if the victim initiated them.

On the CEH v13 exam: CSRF is covered in CEH v13 Module 14 (Hacking Web Applications). The exam tests understanding of the CSRF mechanism (browser automatically includes cookies with same-origin requests), distinction between CSRF and XSS (XSS executes attacker code; CSRF uses victim's own browser to send requests), prevention strategies (anti-CSRF tokens with unique per-session values, SameSite cookie attribute Lax/Strict, verifying Origin/Referer headers, requiring re-authentication for sensitive actions), and how to identify vulnerable endpoints. Questions may present HTML/code samples for vulnerability identification.

CVE (Common Vulnerabilities and Exposures)

A dictionary of publicly disclosed information security vulnerabilities. Each entry has a unique identifier (e.g., CVE-2024-1234) and description. Maintained by MITRE Corporation.

CVSS Scoring

Common Vulnerability Scoring System rates vulnerabilities from 0.0 to 10.0: 0.0 None, 0.1-3.9 Low, 4.0-6.9 Medium, 7.0-8.9 High, 9.0-10.0 Critical. Base metrics: Attack Vector, Complexity, Privileges Required, User Interaction, Scope, Confidentiality, Integrity, Availability.

Cyber Kill Chain

A Lockheed Martin framework identifying seven phases of a cyber attack: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control (C2), Actions and Objectives. Used to classify and prevent attacks at each stage.

Cyber Threat Intelligence (CTI)

Evidence-based knowledge about threats that helps organizations make better security decisions. Types: Strategic (for executives), Tactical (for security teams), Operational (for incident response), Technical (for systems/SIEM). Lifecycle: Direction → Collection → Processing → Analysis → Dissemination → Feedback.

D

Dark Web Investigation

Investigating hidden services on Tor/I2P networks where stolen data, exploits, and malware are traded. Tools: Tor Browser, Ahmia (search engine), dark web monitoring services.

DCSync Attack

Attacker obtains privileged account with domain replication rights, creates virtual DC similar to original AD, extracts NTLM hashes enabling Golden Ticket attacks. Tool: Mimikatz — lsadump::dcsync.

DDoS Mitigation Strategies

Rate limiting, traffic filtering with ACLs, blackhole routing (RFC 3896), CDN (Cloudflare, Akamai), Anycast distribution, IPS, redundant infrastructure across datacenters, ISP-level scrubbing centers, DDoS protection services (AWS Shield).

Decoy Scanning

Nmap -D flag sends packets from multiple fake source IPs simultaneously. Example: nmap -D decoy1,decoy2,yourIP target. IDS sees traffic from all decoys, making it hard to identify real scanner.

Denial of Service (DoS)

A Denial of Service (DoS) Attack is a malicious attempt to make a system, network, or service unavailable to legitimate users by overwhelming it with traffic, exploiting resource exhaustion vulnerabilities, or corrupting configuration. A Distributed DoS (DDoS) uses multiple compromised systems (botnet) to amplify the attack volume beyond what a single source can generate.

On the CEH v13 exam: DoS/DDoS is CEH v13 Module 10. The exam tests understanding of all three attack categories (volume, protocol, application), specific named attacks (SYN flood mechanics with half-open connections, amplification factors for DNS/NTP/memcached), and mitigation strategies including rate limiting, connection pooling, DDoS scrubbing services (Cloudflare, Akamai), SYN cookies, and BGP flow specifications. Questions may present packet captures or attack logs for classification.

DevSecOps

Integrating security into DevOps pipeline. Shift-left security: SAST/DAST scanning in CI/CD, infrastructure as code security, automated compliance checks, container image signing.

DHCP Starvation Attack

Creating a massive number of DHCP requests to exhaust the available IP pool. Combined with a rogue DHCP server, allows Man-in-the-Middle attacks on switched networks.

Diamond Model of Intrusion Analysis

A model for describing cyber intrusions with four core components: Adversary (WHO), Capability (WHAT), Infrastructure (WHERE), Victim (WHO TARGETED). Used to analyze and compare intrusion events.

Dictionary Attack

Password cracking method using a pre-compiled word list to guess passwords. Significantly faster than brute-force for dictionary-based passwords. Tools: Hydra, Hashcat, John the Ripper.

Diffie-Hellman Key Exchange

Method of securely exchanging cryptographic keys over public channel. Allows two parties to jointly agree upon shared secret key without prior shared secrets. Based on discrete logarithm problem.

Digital Signature

Mathematical scheme verifying authenticity and integrity of digital messages. Uses asymmetric cryptography — sender encrypts hash with private key, receiver decrypts with public key.

Digital Stenography

Hiding data within images, audio, or video files. Tools: OpenStego, StegoOnline, DeepSound. Used by attackers to hide C2 communications and exfiltrated data.

Directory Traversal

Directory Traversal (Path Traversal) is a vulnerability that allows an attacker to access files and directories outside the intended web root directory by manipulating file path parameters with sequences like ../ (Unix) or ..\ (Windows). When exploited for reading sensitive files, it is also called Local File Inclusion (LFI). Remote variants where the server fetches external resources are called Remote File Inclusion (RFI).

On the CEH v13 exam: Directory traversal is covered in CEH v13 Module 14 (Hacking Web Applications). The exam tests understanding of path resolution mechanisms on Linux vs Windows, how web servers handle relative vs absolute paths, null byte handling differences across OS versions, WAF bypass techniques (encoding, case manipulation, null bytes), prevention strategies (canonicalizing paths, using allowlists for accessible files, running as unprivileged user, disabling RFI in PHP configuration), and identifying vulnerable parameters in application code. Questions may present file path strings for traversal attempt identification.

Disk/File System Forensics

Analysis of disk images to recover deleted files, examine file system metadata, identify timestamps (MACBT), and detect tampering. Tools: Autopsy, FTK, EnCase.

DLL Injection

Inserting malicious DLL into another process's address space to execute code within its context. Used for privilege escalation, persistence, and evasion.

DLL/Dylib Hijacking

Placing malicious DLL in application library path on Windows, or dynamic library on macOS. Tool: Spartacus (Windows), Dylib Hijack Scanner (macOS). Exploits application loading order.

DLP (Data Loss Prevention)

Technologies and policies to detect and prevent unauthorized data exfiltration. Monitors email, web uploads, USB transfers, network traffic for sensitive data patterns.

DNS Amplification Attack

Type of volumetric amplification attack. Attacker sends DNS queries with spoofed source IP (victim) to open DNS resolvers. DNS response is much larger than query (28x+ amplification). Mitigation: BCP38/BCP84, disable open resolvers.

DNS Record Types

Types of DNS records: A (IPv4 address), AAAA (IPv6 address), MX (mail exchange), NS (name server), CNAME (alias), SOA (start of authority), SRV (service record), PTR (reverse lookup), RP (responsible person), HINFO (host info), TXT (text data for DKIM/SPF).

DNS Tunneling

Encode data in DNS queries to bypass firewalls. Domain: encoded-data.evil.com. DNS server acts as relay for exfiltrated/stolen data. Tools: iodine, dnscat2, dns2tcp.

DNS Zone Transfer (AXFR)

A DNS protocol mechanism (type 256) that copies an entire zone file from primary to secondary servers. If misconfigured, attackers can harvest all subdomains and internal hostnames using dig axfr or nslookup.

Domain Spoofing

Registering domain similar to legitimate one: missing letter (microsof.com), double letter (companny.com), extra TLD (company.com.co). Used in phishing emails and fake login pages.

Dumpster Diving

Searching through discarded materials (paper documents, storage media) to find sensitive information such as credentials, network diagrams, or business plans. A common OSINT technique.

E

Eavesdropping (Social Engineering)

Listening to unauthorized conversations to gather sensitive information. Can be performed in person near office spaces or via network sniffing of unencrypted communications.

EDR (Endpoint Detection and Response)

Security solution monitoring and responding to threats on endpoints (computers, servers, mobile). Provides continuous visibility, behavioral analysis, threat hunting, and automated response capabilities.

Error-Based SQL Injection

Uses database error messages to extract schema information. When injection causes SQL syntax errors, the error message reveals table names, column names, or data types.

Ethical Hacking

The authorized practice of circumventing computer systems to identify potential security breaches. Ethical hackers use the same tools and techniques as malicious hackers but with permission and for defensive purposes.

Evidence Removal Techniques

Disabling auditing, clearing logs (Metasploit meterpreter), manipulating logs, covering tracks on network/OS, deleting files, hiding artifacts, disabling Windows functionality. Using cipher.exe to securely delete files.

F

Firewall Types

Stateless (filters packets based on rules), Stateful (tracks connection state), Application-layer/Next-Gen (inspects content), WAF (web-specific), NGFW (integrates IPS, application control, threat intelligence).

FOCA Tool

Tool to find metadata and hidden information in scanned documents. Extracts author names, company info, timestamps, hidden comments, tracked changes, network paths, usernames from Office documents and PDFs.

Forward Secrecy

Property where compromise of long-term keys does not compromise past session keys. Implemented via ECDHE (Elliptic Curve Diffie-Hellman Key Exchange). Ensures past communications remain secure.

FREAK / Forbidden Attack

FREAK (Factoring RSA Export Keys): Forces downgrade to weak export-grade crypto. Forbidden Attack: MITM exploiting reuse of cryptographic nonce during TLS handshake. AES-GCM cipher exploitation.

G

Golden Ticket Attack

Forge Ticket Granting Ticket (TGT) by compromising KRBTGT account password hash. Grants access to ANY service in the domain indefinitely. Tool: Mimikatz.

Google Hacking / Advanced Search Operators

Special operators used to find sensitive information exposed on the web. Key operators: cache:, link:, related:, info, site:, allintitle:, intitle:, allinurl:, inurl:, location:. Database at Google Hacking Database (GHDB).

H

Hacktivist

A threat actor who conducts cyberattacks for political, social, or ideological causes, targeting organizations to draw attention to their agenda through defacement, data leaks, or denial of service.

Heap Spraying

Floods free space of process memory by writing multiple copies of malicious code. Used with buffer overflow exploits to increase chance of code execution.

HMAC (Hash-based Message Authentication Code)

Combines cryptographic hash function with secret key to provide both integrity and authentication. Used in IPsec, TLS, and API authentication.

Honeypot Types

Production Honeypot (used by organizations for defense), Research Honeypot (used for security research), Threat Intelligence Honeypot (collects attacker TTPs). Low interaction vs High interaction.

HTTP GET Flood

Application-layer DDoS attack sending大量 HTTP GET requests to overwhelm web server resources. Targets specific URLs that require database queries or expensive processing.

HTTP Request Smuggling

Exploiting differences in how front-end and back-end servers interpret HTTP request boundaries to send malicious requests that bypass security controls or gain unauthorized access.

I

IAM (Identity and Access Management)

Framework for managing digital identities and their access to resources. Includes authentication, authorization, provisioning, deprovisioning, and access review processes.

ICMP (Internet Control Message Protocol)

Network layer protocol used for diagnostics and error reporting. Types: Type 0 (Echo Reply), Type 3 (Destination Unreachable), Type 8 (Echo Request/ping), Type 11 (Time Exceeded/traceroute). Used in ping sweeps and host discovery.

IDS Evasion Techniques

Fragmentation, Junk Data Injection, Timing Manipulation, Decoy Scanning (Nmap -D), OS Fingerprint Evasion, Packet Reordering, TCP Wrapping.

IDS Types

NIDS (Network-based): Monitors network traffic. HIDS (Host-based): Monitors system activity. Signature-based: Matches known patterns. Anomaly-based: Detects deviations from baseline behavior.

Impacket Toolkit

Collection of Python classes for working with network protocols. Tools: secretsdump.py (LSASS/SAM/NTDS), psexec.py, wmiexec.py, atexec.py, smbexec.py — essential for AD penetration testing.

Impersonation (Social Engineering)

Pretending to be a legitimate or authorized person, often wearing uniforms, using fake IDs, or spoofing phone numbers and email addresses to gain access to restricted areas or information.

Incident Response (IR)

A structured approach to handling and managing security breaches. Phases: Preparation, Recording and Assignment, Triage, Notification, Containment, Evidence Gathering, Eradication, Recovery, Post-Incident Activity.

Information Assurance (IA)

A framework for ensuring information security. Process: Plan → Design → Find Problems → Get Resources → Plan Fixes → Apply Controls → Verify → Train People. Covers all aspects of information handling and protection.

Information Security Principles

The five core pillars: Confidentiality, Integrity, Availability, Authenticity (ensuring files, communications, and identities are genuine), and Non-repudiation (guaranteeing a sender cannot deny sending a message).

Insecure Deserialization

Exploiting unsafe deserialization of user-supplied data to execute arbitrary code, cause DoS, or bypass authentication. Common in Java, PHP, Python, Ruby applications.

Insider Threat

A security risk originating from within the organization by trusted users with legitimate access who carry out attacks from inside the network perimeter. Can be malicious or accidental.

iOS Security Vulnerabilities

Jailbreaking removes Apple restrictions exposing system files. Insecure data storage (Keychain misuse), backup encryption disabled, SSL pinning bypass, ClassKit/Handoff vulnerabilities, iMessage exploit vectors.

IoT Firmware Analysis

Extract firmware from flash chip for offline analysis. Tools: binwalk, firmware-mod-kit, QEMU. Look for hardcoded credentials, backdoors, update mechanisms, serial console access.

IoT Protocols

MQTT (pub/sub telemetry), CoAP (constrained HTTP-like), Zigbee (low-power mesh), Z-Wave (home automation), BLE (short-range), LoRaWAN (long-range low-power).

IoT Security Testing Methodology

Physical access (UART/USB serial console), firmware extraction (binwalk), hardware analysis (logic analyzer), network protocol testing, API security assessment, mobile app reverse engineering.

IP Geolocation

The process of mapping IP addresses to physical locations including country, region, city, latitude/longitude. Tools like IP2Location provide geographic data associated with an IP address.

IPS Bypass Techniques

Exploit blind spots, use encryption to hide payload, slow down attacks to stay below thresholds, fragment traffic across multiple sessions, target application-layer vulnerabilities not covered by IPS signatures.

K

Kerberoasting Attack

Request service ticket for any service account (SPN), extract encrypted TGS offline and crack for password. Works against any domain-joined user. Tool: Rubeus, Impacket.

Kerberos Authentication

Secret key cryptography authentication protocol. Components: KDC, AS (Authentication Server), TGS (Ticket Granting Server). Process: Login → Request ticket → Receive TGT → Request service access → Receive Service Ticket → Access service.

Keylogger

A Keylogger (keystroke logger) is a surveillance technology that records every keystroke made on a computer or device, along with additional data such as clicked URLs, captured screens, and sent email content. Keyloggers can be hardware-based (physical device between keyboard and motherboard) or software-based (malware or monitoring application), and are used for both legitimate enterprise monitoring and malicious credential theft.

On the CEH v13 exam: Keyloggers are referenced throughout CEH v13, particularly in Module 07 (Malware) and Module 09 (Social Engineering context). The exam tests understanding of keylogger implementation mechanisms (API hooking vs driver-level vs hardware), how they differ from screen capture and clipboard monitoring, detection methods (endpoint monitoring for anomalous process injection, hardware inspection for physical devices, network traffic analysis for C2 beaconing of logged data), prevention (USB port control, endpoint detection and response, user education on hardware inspection), and legal/ethical considerations for deployment in enterprise environments.

L

LDAP Enumeration

Lightweight Directory Access Protocol — extract user lists, group memberships, organizational structure. Ports: 389 (unencrypted), 636 (LDAPS). Tools: ldapsearch, Quest ActiveRoles Server.

Rules of engagement, written authorization requirements, scope boundaries, reporting obligations, data privacy laws (GDPR, CCPA), Computer Fraud and Abuse Act (CFAA), professional codes of conduct.

Live Forensics

Collecting volatile evidence from running systems: memory dumps, network connections, running processes, open files, logged-in users. Performed before powering down to preserve time-sensitive data.

Living off the Land (LotL)

Using built-in OS tools (PowerShell, WMI, PsExec, rundll32) for attack operations instead of custom malware. Evades signature-based detection by using legitimate binaries.

LLMNR/NBT-NS Poisoning

Windows name resolution methods for hosts on same link. Attacker spoofs responses to intercept authentication. Tool: Responder detects and performs poisoning. Detection tools: Vindicate, got-responded.

Logic Bomb

Malicious code triggered by specific conditions (date, event, password). Lies dormant until trigger condition is met. Often used by disgruntled employees with insider access.

LOIC / HOIC Tools

LOIC (Low Orbit Ion Cannon): Basic traffic flood tool for DoS testing. HOIC (High Orbit Ion Cannon): Enhanced LOIC with presets and multiple attack profiles. Both used for educational/lab purposes.

M

MAC Flooding Attack

Flood switch CAM table with thousands of fake MAC addresses. When table overflows, switch enters 'fail-open' mode and behaves like a hub, broadcasting all traffic. Enables sniffing on previously switched networks.

Maltego Tool

Visual link analysis tool for open-source intelligence and forensics. Visualizes relationships between people, domains, IPs, URLs, social media accounts, companies, DNS records, and infrastructure.

Malware

Malware (malicious software) is any software intentionally designed to cause harm to a computer, server, or network. It encompasses a broad range of threat types including viruses, worms, trojans, ransomware, rootkits, spyware, adware, and logic bombs. Modern malware frequently combines multiple capabilities (polymorphic engines, anti-analysis, fileless techniques) to evade detection and maintain persistence.

On the CEH v13 exam: Malware is CEH v13 Module 07 and one of the highest-weighted modules. The exam tests knowledge of all malware types with emphasis on distinguishing characteristics, the malware lifecycle (delivery → execution → persistence → C2 → exfiltration), detection methods (signature-based, behavioral/heuristic, sandboxing, memory analysis), removal procedures, modern evasion techniques (fileless malware using PowerShell/Live, process hollowing, DLL sideloading, AMSI bypass), APT-specific malware families, and ransomware incident response. Questions may present malware descriptions or screenshots for classification.

Malware Analysis Methods

Static Analysis (examining code without running it — disassembly, strings extraction, header analysis) and Dynamic Analysis (running malware in controlled environment/sandbox — network traffic observation, file modification tracking, registry changes monitoring).

Malware Analysis Tools

Static: IDA Pro, Ghidra, PEiD, strings, exiftool. Dynamic: Cuckoo Sandbox, ANY.RUN, Joe Sandbox. Debuggers: OllyDbg, x64dbg, GDB. Network: Wireshark, TCPView. System: Process Monitor, Process Explorer, API Monitor. Memory: Volatility.

Man-in-the-Browser

Trojan infects computer, installs malicious code that loads after browser restart. Handler registered for every webpage visit. Extension matches URL with known targeted sites, extracts DOM field values, and modifies them before sending to server.

Man-in-the-Middle Attack

A Man-in-the-Middle (MitM) Attack is a technique where an attacker secretly intercepts and potentially alters communication between two parties who believe they are directly communicating with each other. The attacker positions themselves between the communicating endpoints to eavesdrop, modify, or inject data without detection.

On the CEH v13 exam: MitM attacks are covered in CEH v13 Modules 08 (Sniffing and Traffic Analysis) and 11 (Session Hijacking). The exam tests knowledge of Layer 2-7 interception techniques, how to detect MitM (certificate pinning, HSTS, network monitoring), the mechanics of ARP cache poisoning, DNS hijacking variants, and TLS-specific attacks (BEAST, POODLE as enablers). Questions often present network topology diagrams for attack feasibility assessment.

Masscan

Internet-scale port scanner capable of scanning all 65535 ports in under a minute. Sends SYN packets at extremely high rates. Can scan the entire internet in under 6 hours.

Meltdown and Spectre

Spectre: Found in AMD, Apple, ARM, Intel. Tricks speculative execution to read restricted data. Meltdown: All ARM and Intel CPUs. Tricks processors into accessing out-of-bounds memory.

Memcached Amplification

Most powerful DNS-like amplification attack. Open Memcached servers can achieve up to 51,000x amplification factor when queried with ANY command and spoofed source IP.

Memory Forensics

Analysis of volatile RAM content to find malware artifacts, encryption keys, network connections, and running processes not visible through normal means. Tool: Volatility framework.

Metamorphic Malware

Rewrites its entire code structure each time it infects a system, performing the same function with completely different code. More advanced than polymorphic — changes both signature AND behavior patterns.

Metasploit Framework Modules

Module types: Exploit (configure active exploit), Payload (establishes communication — singles, stagers, stages), Auxiliary (one-time actions like scanning), NOPs (generate no-op instructions), Encoder (hide payloads), Evasion (modify behavior to avoid detection), Post-exploitation (interact after compromise).

Mirai Botnet

IoT botnet that infected millions of devices (cameras, routers) scanning for default credentials on Telnet/SSH. Used for massive DDoS attacks (Dyn DNS attack: 1Tbps+). Source code leaked in 2016.

MITRE ATT&CK Framework

A knowledge base of adversary tactics and techniques based on real-world observations. Structure: Tactics (WHY hacker acts), Techniques (HOW they achieve goals), Subtechniques, Procedures. Contains 14+ tactics across Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact.

Mobile Device Management (MDM)

System for managing mobile devices in enterprise: Remote wipe, enforce encryption and password policies, app whitelisting/blacklisting, VPN configuration, certificate management, jailbreak/root detection.

Mobile Forensics

Recovery of digital evidence from mobile devices. Covers physical extraction (bit-for-bit), logical extraction (file system), and file-based methods. Tools: Cellebrite, Oxygen Forensics.

Mobile Malware Types

Trojans (appear legitimate), Spyware (track location, contacts), Ransomware (lock device), Adware (inject ads), Rootkits (gain root access), Banking Trojans (intercept transactions).

Multi-Factor Authentication (MFA)

Requiring two or more independent credentials for authentication: something you know (password), something you have (token/phone), something you are (biometric). Significantly reduces credential theft impact.

N

Named Pipe Impersonation

Privilege escalation technique using Windows named pipes for process impersonation. Metasploit module available for exploitation.

Nessus Scanner

Industry-standard vulnerability scanner with extensive plugin library. Identifies vulnerabilities, misconfigurations, compliance violations. Commercial product with free personal edition.

NetBIOS Enumeration

Enumerate computer names, user names, domains via NetBIOS Session Service (port 139) and Name Service (ports 137/138). Tools: nbtscan, enum4linux, rpcclient.

Netstat Commands

Network statistics tool. Commands: netstat -an (all connections and listening ports), netstat -b (executable tied to each port), netstat -n (numeric only, no DNS resolution). Shows TCP connection states: ESTABLISHED, SYN_SENT, FIN_WAIT, CLOSE_WAIT, TIME_WAIT, LISTEN.

Network Enumeration

Network Enumeration is the process of extracting detailed information about a network's resources, including usernames, machine names, network shares, group memberships, service versions, and configuration details. It follows initial scanning and provides the attacker with specific targets for exploitation — essentially converting "open ports" into "known vulnerabilities with specific exploit targets."

On the CEH v13 exam: Enumeration is CEH v13 Module 04. The exam tests knowledge of each protocol's enumeration methods, specific commands and tools, how to interpret enumeration output for attack planning, and defensive countermeasures (restricting SMB anonymous access, hardening LDAP with TLS and bind requirements, changing SNMP community strings or migrating to SNMPv3, disabling NetBIOS where not needed). Questions often present enumeration output for analysis — identifying exploitable findings from the data.

Network Forensics

Capture and analysis of network traffic for investigation. Uses packet captures (PCAP), NetFlow data, and firewall logs to reconstruct attack timeline and identify indicators of compromise.

Network Segmentation

Dividing network into smaller subnets to limit lateral movement during a breach. Reduces attack surface and contains compromise within specific zones.

NIS Enumeration

Network Information Service enumeration for Unix systems. Retrieves passwd/group database entries via UDP 751.

NIST SP 800-115

A guide to information technology security testing published by NIST that provides guidelines for conducting security testing including planning, testing, and documentation phases.

Nmap OS Detection

-O flag enables OS detection by analyzing TCP/IP stack fingerprints. Analyzes TCP Initial TTL values, window size, IP ID sequence generation, TCP options ordering. Compares responses against nmap-os-db database.

Nmap Scan Types

Multiple scanning techniques in Nmap: SYN Scan (-sS), Connect Scan (-sT), UDP Scan (-sU), XMAS Scan (-sX), NULL Scan (-sN), FIN Scan (-sF), ACK Scan (-sA), Idle Scan (-sI). Each type has different stealth and detection characteristics.

Nmap Zombie/Idle Scan

-sI option uses an idle 'zombie' host to scan the target, making the scan appear to come from the zombie. Requires an idle zombie with predictable IP ID sequence and no communication during scan.

NTFS Alternate Data Streams (ADS)

Hidden data streams within files on NTFS filesystem. Attackers hide malicious content in alternate streams. Tools: StreamArmor, GMER, ADS Scanner.

NTLM Authentication

NT LAN Manager — default Windows authentication scheme using challenge-response. Process: Client requests access → Server sends challenge → Client computes response → Server verifies (AD or SAM). NTLMv2 is reasonably secure but weaker than Kerberos.

O

Open Redirect

Web vulnerability where application redirects users to a URL derived from user input without proper validation, enabling phishing attacks that appear to originate from trusted domain.

OpenVAS Scanner

Open-source alternative to Nessus. Full-featured vulnerability scanner with regular feed updates. Part of Greenbone network.

OSINT Framework

Collection of open-source intelligence tools organized by category. Covers reconnaissance, domain research, IP address research, social media investigation, and more.

OSSTMM

Open Source Security Testing Methodology Manual. A free and open framework for security testing that provides standardized metrics and measurements for penetration testing.

OT Security Principles

Safety-first approach to industrial control systems. Network segmentation (Purdue Model), passive monitoring, disable unnecessary services, physical security, incident response plans for OT environments.

Out-of-Band SQL Injection

Uses different channel to exfiltrate data — DNS lookups or HTTP requests from the database server. Requires specific DB configuration but works when in-band methods fail.

P

Packet Fragmentation for IDS Evasion

Split malicious payload into smaller fragments. Each fragment individually appears harmless. IDS may not reassemble before inspection. Target system reassembles and executes the payload. Nmap: -f flag.

Pass the Hash (PtH)

Injecting compromised hash into local session to authenticate to network resources without cracking password to plaintext. Uses logged-in user hash to log into domain controller.

Passive Reconnaissance

Gathering information about a target without directly interacting with their systems. Examples: searching search engines, checking social media, WHOIS lookups, public records, company websites. Leaves no trace on target infrastructure.

Passive Session Hijacking

Only observe and record traffic, capture IDs/passwords without disturbing the session. Uses packet sniffers to intercept unencrypted session tokens.

Password Dumping Methods

Methods to extract credentials: dumping from memory, stealing SAM database, stealing AD file ntds.dit, extracting SYSKEY boot key, intercepting credentials on network. Tools: pwdump7, Mimikatz, DSinternals.

Password Spraying

Targets multiple accounts simultaneously with the same common password to avoid account lockout that single-password brute force would trigger. Example: Try 'Password123' against all user accounts.

Penetration Testing Phases

Structured methodology for authorized simulated cyberattacks. Phases: Preparation (define scope, rules of engagement), Assessment (actual penetration testing including reconnaissance, scanning, exploitation), Conclusion (report preparation, findings documentation, recommendations).

Penetration Testing Reporting

Documenting findings with executive summary, technical details, risk ratings, evidence (screenshots), and remediation recommendations. Key to demonstrating value to stakeholders.

Pharming

Redirecting traffic to fake websites via DNS poisoning or manipulating hosts file. Users visit legitimate sites but are directed to fraudulent lookalike sites.

Phishing Attack

A Phishing Attack is a social engineering technique where an attacker disguises themselves as a trusted entity (via email, SMS, phone, or other communication channels) to trick victims into revealing sensitive information such as credentials, financial data, or personally identifiable information (PII). It is the most common initial vector for cyberattacks.

On the CEH v13 exam: Phishing is covered extensively in CEH v13 Module 09 (Social Engineering). The exam tests knowledge of all phishing variants, the difference between phishing and pretexting, email header analysis for spoofing detection, user education strategies, technical countermeasures (SPF, DKIM, DMARC), and how to design and evaluate a corporate phishing simulation program. Expect multiple questions covering both offensive and defensive perspectives.

Ping of Death

Sends malformed or oversized ICMP packets (>65,535 bytes). Target system crashes trying to reassemble fragmented packets. Mostly patched in modern systems but still relevant for legacy/IoT.

Ping Sweep

Method to find active machines on a network by sending ICMP Echo Requests. Tools: Angry IP Scanner, Superscan, Nmap (-sn), Advanced IP Scanner, PingPlotter.

PMKID Attack

Targets WPA2-Personal networks. Captures PMKID from first handshake message. Faster than full handshake capture. Tool: aircrack-ng with hashcat. Requires station connected to AP or known SSID.

Polymorphic Malware

Changes its code signature each time it replicates while keeping the original algorithm intact. Uses mutation engines to evade signature-based AV detection. Different from Metamorphic which rewrites entire code structure.

Port Number Ranges

Well Known Ports: 0-1023 (reserved), Registered Ports: 1024-49151 (assigned), Dynamic/Private Ports: 49152-65535 (temporary). Common ports: 21/FTP, 22/SSH, 23/Telnet, 25/SMTP, 53/DNS, 80/HTTP, 443/HTTPS, 445/SMB, 3389/RDP.

Port Scanning

Port Scanning is a network reconnaissance technique used to identify open ports, running services, and their versions on a target system by sending crafted packets to specific port numbers and analyzing responses. It is one of the first steps in any penetration test or cyberattack, providing the attacker with an attack surface map.

On the CEH v13 exam: Port scanning is the foundation of CEH v13 Module 03 (Scanning Networks). The exam tests understanding of TCP/IP packet flag behavior for each scan type, when to use stealth scans vs connect scans, Nmap command syntax and options (-sS, -sT, -sU, -sF, -sN, -sX, -A, -p, --top-ports), detection via IDS signatures (Suricata/Snort rules for SYN floods on non-standard ports), and evasion techniques (fragmentation, decoys, timing adjustments, OS fingerprinting). Questions may present packet captures for scan type identification.

PowerShell in Attacks

Living-off-the-land technique using PowerShell for fileless malware, credential theft, lateral movement. Techniques: -encodedcommand, IEX (Invoke-Expression), IWR (Invoke-WebRequest), AMSI bypass.

Predicting Session Tokens

Sequential tokens (easily predictable), timestamp-based tokens, small token space (brute force possible), weak RNG algorithms, lack of rate limiting allows rapid guessing.

PREP Framework

Social engineering methodology: Positioning (establish credibility and role), Rapport (build trust and connection), Extraction (gather information gradually), Prestige (make target feel honored to help).

Pretexting

Creating a fabricated scenario (pretext) to engage the victim and extract information. The attacker researches the target beforehand to create a believable story, often impersonating IT support, bank representative, or law enforcement.

Privilege Escalation

Privilege Escalation is the process of exploiting software vulnerabilities, misconfigurations, or logic flaws to gain higher-level permissions on a system. Vertical escalation (vertical) moves from low-privilege user to root/administrator. Horizontal escalation moves between users at the same privilege level.

On the CEH v13 exam: Privilege escalation is a core topic in CEH v13 Module 06. The exam tests knowledge of both Linux and Windows escalation paths, specific misconfigurations to check (world-writable files, SUID binaries, scheduled tasks), kernel exploit mechanics, Active Directory-based escalation (Kerberoasting, Pass-the-Hash escalation), and post-exploitation enumeration techniques. Questions frequently present system configurations for vulnerability identification.

Process Hollowing

Technique where a running process is suspended, its memory is unmapped, and replaced with malicious code. The original process resumes execution but runs attacker-controlled payload.

Psychological Principles of SE

Principles exploited in social engineering: Authority (people obey figures of authority), Scarcity (limited availability creates urgency), Urgency (time pressure prevents rational thinking), Familiarity/Liking, Consistency, Reciprocity.

PTES

Penetration Testing Execution Standard. Provides a comprehensive taxonomy including pre-engagement, intelligence gathering, threat modeling, vulnerability analysis, exploitation, post-exploitation, and reporting.

Public Key Infrastructure (PKI)

System for managing digital certificates and public-key encryption. Components: Certificate Authority (CA), Registration Authority (RA), Digital Certificates, CRL, Certificate Revocation.

Purple Team

Collaborative approach combining red team (attack) and blue team (defense) in real-time to improve detection capabilities and security posture through continuous feedback.

Q

QR Code Phishing (Quishing)

QR codes used as attack vector in phishing. Directs victim to malicious URLs without showing URL until after scan. Bypasses email security filters that cannot scan QR codes.

Qualys Scanner

Cloud-based vulnerability management solution. Provides continuous monitoring, compliance scanning, and asset discovery without requiring on-premise hardware.

Quantum Computing Threat to Crypto

Quantum computers could break RSA and ECC encryption. Shor's algorithm factors large numbers efficiently. NIST standardizing post-quantum cryptography (lattice-based, hash-based, code-based). Timeline: 10-30 years.

Quid Pro Quo (Social Engineering)

A social engineering technique where the attacker promises a benefit in exchange for information ("I'll fix your computer if you share your admin password"). Derived from Latin meaning "something for something."

R

Rainbow Table Attack

A Rainbow Table Attack is a password cracking technique that uses precomputed tables of hash values to reverse common passwords significantly faster than brute-force or dictionary attacks. Each table maps a chain of plaintext → hash → transformation → plaintext → hash sequences, allowing rapid lookup of a target hash by finding its matching position in the chain and working backwards.

On the CEH v13 exam: Rainbow tables are covered in CEH v13 Module 06 (System Hacking) in the context of password attacks and credential recovery. The exam tests understanding of how hash chains work, why salting defeats rainbow tables (each salt requires separate table), the difference between LM and NTLM hashing (LM splits password into two 7-char halves, making it weaker), modern password storage best practices (bcrypt/scrypt/Argon2 with high cost factors), and how to identify which hashing algorithm was used from stored hash format. Questions may present hash values for algorithm identification.

Ransomware Types

Crypto-ransomware (encrypts files), Locker-ransomware (locks device/screen), Double Extortion (steals data THEN encrypts, threatens to leak). Examples: WannaCry, Ryuk, LockBit, BlackCat/ALPHV.

Rapid7 Nexpose/InsightVM

Enterprise vulnerability management platform providing comprehensive scanning, risk-based prioritization, and remediation guidance.

Recon-ng Framework

Web-based reconnaissance framework (open-source, modular) for gathering information from public sources. Features modules for WHOIS, DNS, Google hacking, Shodan integration, and more.

ReconDog Tool

All-in-one reconnaissance tool providing DNS lookup, whois information, port scanning, and more. Usage: recondog footprint, recondog scanner.

Red Team vs Penetration Testing

Pen test: Find and report vulnerabilities within scope. Red team: Simulate real adversary TTPs to test detection and response. Broader, more stealthy, objectives-based rather than vulnerability-focused.

Regional Internet Registries (RIRs)

Organizations managing IP address allocation by region: ARIN (Americas), AFRINIC (Africa), APNIC (Asia-Pacific), RIPE NCC (Europe/Middle East/Central Asia), LACNIC (Latin America/Caribbean).

Remote Code Execution Techniques

Methods for executing code remotely: Web-browser exploitation (spear phishing), Office-application exploitation, WMI (Windows Management Instrumentation), WinRM (Windows Remote Management). Tools: Dameware, Ninja, Pupy, PsExec.

Responder Tool

LLMNR/NBT-NS/mDNS poisoner and credential harvester. Captures Windows name resolution requests and returns malicious responses, harvesting NTLM hashes from the network.

Responsible Vulnerability Disclosure

Process of privately notifying vendor of vulnerability before public disclosure, allowing time for patch development. Timeline: 90 days initial, 180 days max before public release.

Return Oriented Programming (ROP)

Reusing code snippets already existing in the binary, usually in libc or kernel32.dll. Chains small code 'gadgets' ending in RET instruction to build arbitrary execution. Defeats DEP/NX protections.

Risk Analysis

The process of identifying, estimating, and prioritizing threats to information assets. Formula: Risk = Threats × Vulnerabilities × Impact. Key metrics include ARO (Annual Rate of Occurrence), SLE (Single Loss Expectancy), and ALE (Annualized Loss Expectancy = SLE × ARO).

Risk Treatment Options

Four approaches: Mitigation (reduce risk), Transfer (insurance/outsourcing), Accept (tolerate residual risk), Avoid (eliminate activity causing risk).

Rogue Access Point

Unauthorized AP connected to secure network. Can be installed by employees without IT knowledge providing backdoor for attackers. Detection: Wireless intrusion detection systems (WIDS). Prevention: Network access control policies.

Rootkit Detection

Detection methods: Integrity-based detection (Tripwire, AIDE baseline), analyzing memory dumps, comparing process lists (rootkit vs OS view). Anti-Rootkit tools: GMER (SirMed), Stinger, TDSSKiller, Avast One.

RST Flood Attack

Sending TCP RST packets to established connections to forcibly terminate them. Can disrupt legitimate communications and cause application-level denial of service.

Rules of Engagement (RoE)

Written agreement defining scope, timing, techniques allowed, target systems, communication procedures, and emergency contacts for a penetration test. Protects both tester and client.

S

SCADA/ICS Attack Surface

Legacy systems not designed for connectivity, proprietary protocols with weak authentication, long lifecycle without updates, physical safety implications. Common targets: power grids, water treatment, manufacturing.

SCADA/ICS Protocols

Modbus (no authentication), DNP3 (utilities), BACnet (building automation), PROFINET (industrial Ethernet), OPC UA (more secure), S7comm (Siemens PLC).

Script Kiddie

An inexperienced attacker who uses pre-made exploit tools, scripts, or automated attack tools without understanding the underlying concepts, often causing more disruption than damage.

Security Compliance Frameworks

Standards and frameworks for organizational security: ISO 27001, NIST CSF, PCI DSS, HIPAA, SOC 2, GDPR, COBIT. Provide structured approach to managing security risks.

Session Donation Attack

Attacker logs into shared session, victim clicks link, victim authenticates attacker's session, attacker gains victim's data. Prevention: Bind session to user/IP/device.

Session Fixation

Attacker sets session ID in advance (via link, cookie). Victim logs in using attacker-known session ID. Prevention: Regenerate session ID after login.

Shodan Search Engine

Search engine for internet-connected devices. Indexes banners from all connected devices including webcams, routers, servers, IoT devices. Used for discovering exposed services and vulnerabilities.

Shoulder Surfing

A physical social engineering technique observing a target's screen, keyboard, or password entry by standing nearby. Can be performed in person or via surveillance cameras.

SIEM (Security Information and Event Management)

Centralized platform for collecting, analyzing, and correlating security logs and events from multiple sources. Enables real-time threat detection, compliance reporting, and incident response.

Silver Ticket Attack

Steal user credentials and create fake Service Ticket (TGS, not TGT). Grants access to a specific service, not entire domain. Tool: Mimikatz.

Slowloris Attack

Application Layer (Layer 7) attack opening multiple connections to web server and keeping them open. Sends partial HTTP requests with slow intervals. Uses very little bandwidth, hard to detect.

SMS Phishing (Smishing)

Fake text messages with malicious links. Mobile-optimized phishing using SMS as the delivery vector. Often includes urgency to prompt immediate action.

SMTP Enumeration

Using SMTP VRFY, EXPN, or RCPT TO commands to verify email addresses and enumerate users. Tools: smtp-user-enum, Nmap scripts (smtp-enum), Swaks.

Smurf Attack

Sends ICMP echo requests (pings) to broadcast addresses with spoofed source IP of victim. All hosts on network reply to victim simultaneously, overwhelming it with traffic.

SNMP Enumeration

Using community strings to extract system info, interface stats, routing tables, connected devices. Common defaults: 'public' (read-only), 'private' (read-write). Tools: snmpwalk, snmpget, Net-SNMP.

Social Engineering

Social Engineering is the art of manipulating people into performing actions or disclosing confidential information through psychological manipulation rather than technical exploitation. It exploits human traits such as trust, curiosity, fear, urgency, and willingness to help. Social engineering is considered the weakest link in organizational security because it bypasses all technical controls by targeting the human element directly.

On the CEH v13 exam: Social Engineering is CEH v13 Module 09 and one of the highest-weighted modules. The exam tests all major SE techniques with emphasis on distinguishing between them, understanding the psychology behind each (Cialdini's principles: reciprocity, commitment, social proof, authority, liking, scarcity, unity), designing penetration test social engineering assessments, legal/ethical boundaries, and organizational countermeasures (training programs, verification procedures, security awareness). Expect 10+ questions across the exam touching SE concepts.

Social Media Reconnaissance

Gathering information from social media platforms for OSINT. LinkedIn reveals organizational structure and employee roles. Facebook/Twitter reveal personal details used in spear phishing.

Spear Phishing

Targeted phishing attack directed at specific individual or organization. Uses personalized information gathered through reconnaissance to make the attack more convincing and effective.

SQL Injection

SQL Injection (SQLi) is a code injection technique that exploits vulnerabilities in an application's database interface by inserting or "injecting" malicious SQL statements into input fields. When successfully exploited, it can manipulate the database to disclose, alter, or delete data, and in some cases execute administrative commands on the database server.

On the CEH v13 exam: SQL Injection is explicitly covered as CEH v13 Module 15 and appears throughout the exam. Questions test knowledge of attack vectors, detection via input validation analysis, prevention strategies (parameterized queries, stored procedures, WAF rules), and the specific behaviors of different SQLi types. Expect at least 5-7 questions directly addressing SQLi concepts.

SQLmap Usage

Automated SQL injection tool. Commands: sqlmap -u "url?id=1" --dbs (list databases), -D dbname --tables (list tables), -T tbl --dump (dump data), --os-shell (OS shell), --passwords (extract passwords).

SSL Strip

Downgrades HTTPS connections to HTTP before TLS negotiation begins, enabling plaintext interception. Tool by Moxie Marlinspike. Exploits the transition period before application redirects to secure version.

SSRF (Server-Side Request Forgery)

Attacker induces the server to make HTTP requests to an arbitrary domain of their choosing. Can be used to access internal resources, cloud metadata services, or scan internal networks.

State-Sponsored Threat Actor

A government-backed adversary conducting sophisticated cyber operations for intelligence gathering, strategic disruption, or economic espionage. Resources and sophistication far exceed criminal groups.

Steganography

Hiding secret data within non-secret files (images, audio, video). Unlike cryptography which hides content, steganography hides the existence of the message itself.

STRIDE Threat Model

A threat categorization model: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege. Used during threat modeling to systematically identify potential threats.

Stuxnet Worm

Discovered in 2010, targeted Iranian nuclear facilities. Specifically attacked Siemens SCADA systems to disrupt centrifuge operations. Used multiple zero-day exploits. First cyberweapon targeting physical infrastructure.

Subfinder Tool

Fast subdomain discovery tool using passive online sources. Finds subdomains belonging to target domains for attack surface mapping and reconnaissance.

Symmetric Encryption

Same key for encryption and decryption. Algorithms: AES (128/192/256-bit), DES (broken), 3DES, RC4 (broken), Blowfish, Twofish, ChaCha20. Faster than asymmetric but key distribution is challenging.

SYN Flood Attack

Exploits TCP three-way handshake by sending many SYN requests but never completing with SYN-ACK. Target's connection table fills up with half-open connections, preventing legitimate connections. Mitigation: SYN cookies.

T

Tailgating (Physical SE)

A physical social engineering attack where an unauthorized person follows an authorized person into a restricted area without independent authentication. Also called piggybacking.

TCP (Transmission Control Protocol)

A connection-oriented transport layer protocol providing guaranteed delivery, ordered packets, error checking, and flow control. Uses three-way handshake (SYN, SYN/ACK, ACK) to establish connections.

TCP Connection States

Connection lifecycle states: ESTABLISHED (active), SYN_SENT (request sent), SYN_RECEIVED (waiting for response), FIN_WAIT_1/2 (waiting for close), CLOSE_WAIT (remote closed), TIME_WAIT (local closed, waiting ACK), LISTEN (accepting connections).

TCP Flags

Control bits in TCP header: SYN (connection initiation), ACK (acknowledgment), RST (reset), FIN (finish/close), URG (urgent), PSH (push), NULL (none set), XMAS (FIN+URG+PSH all set). Used for connection management and scan detection.

TCP Three-Way Handshake

Process to establish a TCP connection: 1) SYN — Client sends synchronization packet with random sequence number, 2) SYN/ACK — Server acknowledges and sends its own SYN, 3) ACK — Client acknowledges server's SYN, connection established.

theHarvester Tool

Email and subdomain reconnaissance tool. Usage: theHarvester -d domain.com -l 200 -b linkedin. Collects emails, subdomains, hostnames from public sources including search engines, LinkedIn, PGP key servers.

Threat Modeling

Process of identifying what can go wrong, how systems can be attacked, and how to mitigate risks. Steps: Identify assets, Create attack trees, Identify threats (STRIDE framework), Mitigate threats, Validate assumptions.

Token Impersonation

Using Windows access tokens to impersonate other users or system accounts. Enables lateral movement without credentials. Tool: Meterpreter (steal/tokn impersonate).

Traffic Analysis

Analyzing network traffic patterns WITHOUT reading content. Can reveal communication patterns, frequency, volume, parties involved. Useful even when traffic is encrypted. Tools: Wireshark statistics, Maltego, NetworkMiner.

Trojan Types

Downloader Trojan (downloads additional malware), Dropper Trojan (deploys other malware), Backdoor Trojan (creates unauthorized access channel), DDoS Trojan (joins botnet), Banking Trojan (steals financial credentials), RAT (Remote Access Trojan — full remote control).

U

UAC Bypass Techniques

Methods to bypass User Account Control: FodHelper Registry, eventvwr Registry, COM handler hijacking, binary planting, registry permission abuse.

UDP (User Datagram Protocol)

A connectionless transport layer protocol with no guaranteed delivery or ordering but faster with lower overhead. Used by TFTP, DNS, DHCP, and real-time applications.

V

VPN Protocols

Secure tunneling protocols: IPsec (network layer), SSL/TLS (application layer), OpenVPN (open-source), WireGuard (modern, lightweight), PPTP (deprecated), L2TP/IPsec (combined).

Vulnerability Scanner

A tool that automatically identifies known vulnerabilities in systems, networks, or applications by comparing configurations and software versions against databases of known vulnerabilities (CVE). Examples: Nessus, OpenVAS, Qualys.

W

WAF (Web Application Firewall)

Filters, monitors, and blocks HTTP traffic between web application and internet. Protects against SQL injection, XSS, path traversal, and other OWASP Top 10 attacks.

WarDriving

Searching for wireless networks while moving through an area using laptop/phone with WiFi adapter and GPS. Tools: NetSpot, InSSIDer, Android WiFi Analyzer. Reveals open networks, WEP/WPA networks, hidden SSIDs.

Waterholing

Attack where attackers identify websites regularly visited by their target group and compromise those sites. When targets visit the compromised site, malware is delivered to them.

Web Application Security Tools

OWASP ZAP (open-source scanner), Burp Suite (manual testing toolkit), Acunetix (automated scanner), Nikto (server scanner), SQLmap (SQLi tool), Wfuzz (web fuzzer), Skipfish, Arachni.

Web Security Headers

X-Frame-Options (DENY/SAMEORIGIN), X-Content-Type-Options (nosniff), Strict-Transport-Security (HSTS), Content-Security-Policy (CSP), X-XSS-Protection, Referrer-Policy. All essential for web security.

Web Server Hardening

Remove default pages, disable directory listing, use strong SSL/TLS, keep software updated, restrict HTTP methods, implement WAF, use security headers (X-Frame-Options, CSP, HSTS), regular vulnerability scanning.

Whaling

Spear phishing specifically targeting C-level executives and senior management. High-value targets with access to sensitive data and authority to authorize transactions.

White Hat Hacker

An ethical security professional who tests systems and networks with explicit authorization to identify vulnerabilities and help organizations strengthen their defenses.

WHOIS Lookup

A protocol used to query databases for information about domain registration. Provides registrant contact details, registration dates, nameservers, and IP address allocations. Thick vs Thin WHOIS models.

Windows Security Accounts Manager (SAM)

Database storing hashed passwords for local user accounts. Location: %SystemRoot%\system32\config\SAM or registry HKEY_LOCAL_MACHINE\SAM. Cannot copy while Windows running. Stores LM or NTLM hashed passwords.

Wireless Security Tools

Aircrack-ng suite (monitor mode, capture, crack), Kismet (detector/sniffer), Reaver (WPS attack), Fern WiFi Cracker (GUI tool), Bully (WPS offline/online), Cowpatty (PMKID attacks).

Worm vs Virus

Virus requires host file and human action to spread (opens attachment, runs program). Worm is standalone malware that self-replicates across networks WITHOUT user interaction. Worms spread faster but viruses can be more destructive.

WPA2 Cracking

WPA2 Cracking refers to the process of recovering the pre-shared key (PSK) or passphrase of a Wi-Fi network protected by WPA2-PSK encryption. The primary method involves capturing the 4-way handshake during client association, then performing offline dictionary or brute-force attacks against the captured handshake data using tools like Aircrack-ng.

On the CEH v13 exam: WPA2/WPA3 security is CEH v13 Module 16 (Attacking Wireless Networks). The exam tests understanding of the WPA2 4-way handshake process (ANonce, SNonce, PMK, PTK derivation), how deauthentication triggers reconnection and handshake, PMKID capture mechanics, WPS vulnerability specifics, WPA3 SAE improvements and remaining weaknesses, and enterprise wireless security (802.1X, RADIUS). Questions may present handshake captures for analysis or ask about specific attack feasibility given network conditions.

WPS PIN Attack

Exploits WPS 8-digit PIN with split authentication vulnerability (4+4 digits). ~11,000 attempts max. Tool: Reaver. Can recover PSK in hours.

X

XXE (XML External Entity) Attack

Exploits XML parsers that process external entity declarations, enabling file read, SSRF, and data exfiltration through crafted XML input. OWASP Top 10 vulnerability.

Z

Zenmap (Nmap GUI)

Official graphical user interface for Nmap. Provides preset scan configurations, visualization of network topology, and comparison of scan results over time.

Zero Trust Architecture

Security model assuming no user or system should be trusted by default, even if inside the network perimeter. Requires continuous verification of identity, device health, and access rights for every request.

Zero-Day Vulnerability

A Zero-Day Vulnerability (0-day) is a software security flaw that is unknown to the vendor and for which no patch or mitigation exists. The term "zero-day" refers to the fact that the vendor has had zero days to fix the vulnerability since it was discovered by the attacker. Once publicly disclosed or patched, it becomes an N-day vulnerability (where N is the number of days between disclosure and exploitation in the wild).

On the CEH v13 exam: Zero-days are referenced throughout the CEH v13 exam, particularly in the context of APT operations (Module 07), vulnerability management (Module 05), and ethical considerations. The exam tests understanding of the difference between 0-day and N-day, the responsible disclosure process (identifying researcher, notifying vendor, providing reproduction steps, allowing remediation period), why zero-days are critical for APT groups, and defensive strategies when a 0-day is active (virtual patching via WAF/IPS, network segmentation, enhanced monitoring).