Glossary
Every term is explained twice: first in plain language, then formally.
CSV opens in Excel/Sheets. The Anki file is a tab-separated deck: front = term, back = explanation.
Active Directory (AD)
In simple wordsThink of a giant organization phone book: who the users are, what computers exist, and what each one is allowed to do.
Formal definition:Microsoft's Directory Service for centrally managing users, computers, and policies across the organization's network.
Domain
In simple wordsOne neighborhood in the network with shared rules. Everyone inside is managed the same way.
Formal definition:A logical group of AD objects with a shared security policy and a shared database.
Forest
In simple wordsThe whole city — a collection of several neighborhoods (Domains) that share basic infrastructure.
Formal definition:The top level of the AD structure. A collection of one or more Domain trees, with a shared Schema and a shared Global Catalog.
OU (Organizational Unit)
In simple wordsA folder inside the domain. Users/computers are organized in it so rules can be applied to them.
Formal definition:A Container within the Domain for organizing users, computers, and groups. Group Policies can be applied to it.
DC (Domain Controller)
In simple wordsThe gatekeeper server. It checks passwords and tells who you are.
Formal definition:A server that runs Active Directory and handles Authentication requests and directory queries.
LDAP
In simple wordsThe phone book's query language: how you ask AD who someone is and what they have.
Formal definition:Lightweight Directory Access Protocol — a protocol for accessing and searching directory services.
Kerberos
In simple wordsA ticket system: you log in once, get a ticket, and use it to enter services without a password each time.
Formal definition:A network authentication protocol that uses tickets (Tickets: TGT, TGS) instead of passing passwords over the network.
NTLM
In simple wordsAn old authentication method. It works, but it's relatively easy to steal an identity with it — Kerberos is preferable.
Formal definition:An old Microsoft authentication protocol, vulnerable to Pass-the-Hash attacks.
TGT
In simple wordsThe main ticket you get at logon. It's used to request tickets for services.
Formal definition:Ticket Granting Ticket — the initial Kerberos ticket issued after the user logs in.
TGS
In simple wordsA ticket for a specific service, for example a file server.
Formal definition:Ticket Granting Service — a Kerberos ticket used to access a specific service.
SPN
In simple wordsA service's tag on the network. Without it, Kerberos doesn't know which service to issue a ticket for.
Formal definition:Service Principal Name — a unique name for a service in the Domain, for which a Kerberos ticket can be requested.
GPO
In simple wordsA list of rules automatically distributed to computers and users (for example: minimum password length).
Formal definition:Group Policy Object — an object for centralized management of Windows settings.
Kerberoasting
In simple wordsAn attacker requests a ticket for a service and then tries to guess its password on their own computer, quietly.
Formal definition:An attack in which TGS tickets are requested for Service Accounts and then the Hash is cracked Offline.
Pass-the-Hash
In simple wordsInstead of stealing a password, the password's fingerprint is stolen and used to log in.
Formal definition:An attack that uses a stolen password Hash to log in, without the actual password.
Pass-the-Ticket
In simple wordsA valid Kerberos ticket is stolen and used to log in as if it were you.
Formal definition:An attack that uses a stolen Kerberos ticket to authenticate against services.
DCSync
In simple wordsAn attacker impersonates a Domain Controller and asks the real one for all the passwords.
Formal definition:An attack in which an attacker mimics a Domain Controller's Replication process to extract password Hashes.
Golden Ticket
In simple wordsA forged ticket that gives access to almost everything in the domain. A very severe nightmare.
Formal definition:A forged TGT created using the krbtgt account's Hash — grants super-access to the Domain.
LAPS
In simple wordsA tool that automatically changes the local admin password on every computer, so there isn't one password for everyone.
Formal definition:Local Administrator Password Solution — a Microsoft tool for managing and automatically rotating Local Administrator passwords on computers.
Delegation
In simple wordsGranting a service permission to act on your behalf, so it can fetch information for you from another server.
Formal definition:Delegation of permissions: a mechanism that lets a service act on behalf of the user who connected to it, in order to access an additional resource on their behalf.
Unconstrained Delegation
In simple wordsA too-broad permission: the server can impersonate you to everything. Dangerous — better to avoid.
Formal definition:Unlimited delegation — the server receives and keeps a full TGT of everyone who connects to it, and can therefore impersonate them to any service in the domain. Especially dangerous.
Constrained Delegation (KCD)
In simple wordsThe same capability, but limited to an approved list of services only.
Formal definition:Delegation limited to a predefined list of SPNs in the msDS-AllowedToDelegateTo attribute. With Protocol Transition (S4U2Self) the risk increases.
RBCD
In simple wordsThe target itself decides who is allowed to impersonate it. Flexible, but an attacker who gains control can exploit it.
Formal definition:Resource-Based Constrained Delegation — the target resource itself determines, in the msDS-AllowedToActOnBehalfOfOtherIdentity attribute, who is allowed to impersonate it.
S4U2Self / S4U2Proxy
In simple wordsTwo Kerberos tricks that let a service obtain a ticket on your behalf.
Formal definition:Kerberos extensions used in Delegation: S4U2Self issues a ticket on behalf of the user, and S4U2Proxy allows it to be used against another service.
MachineAccountQuota
In simple wordsHow many computers a regular user can join to the domain. Default is 10 — 0 is recommended.
Formal definition:The number of computer accounts a regular user can create in the domain (default 10). A high value enables RBCD attacks — 0 is recommended.
Credential Guard
In simple wordsA vault inside Windows that stores passwords and tickets so they're hard to steal from memory.
Formal definition:A Windows technology that protects Credentials from being extracted from memory.
BloodHound
In simple wordsA graphical map showing how you can get from a regular user to Domain Admin.
Formal definition:A tool for visually mapping relationships between AD objects and finding Privilege Escalation paths.
Mimikatz
In simple wordsA tool that extracts passwords from memory. For legal and educational use only.
Formal definition:A tool for extracting Credentials from Windows memory. For educational and legal testing purposes only.
SIEM
In simple wordsA control center that collects logs from the whole organization and alerts on suspicious things.
Formal definition:Security Information and Event Management — a system for collecting and analyzing security events across the entire organization.
Least Privilege
In simple wordsGive everyone only the keys they truly need — no more.
Formal definition:The principle of minimal permissions: grant a user only the permissions necessary to perform their role.
msDS-KeyCredentialLink
In simple wordsA field that tells AD 'you can also log in with this key' — not just with a password.
Formal definition:An attribute in an AD object that contains a public key credential; used by Windows Hello for Business and FIDO2, allowing TGT requests via PKINIT.
PKINIT
In simple wordsA Kerberos ticket issued based on a certificate, not a password.
Formal definition:A Kerberos extension that allows authentication and TGT requests using a certificate/cryptographic key instead of a password.
Diamond Ticket
In simple wordsTake a real ticket, 'add' permissions to it, and return it — it looks completely legitimate.
Formal definition:A legitimate TGT whose PAC has been compromised: the attacker decrypts it with the KRBTGT key, modifies groups/SIDHistory, and re-encrypts it.
Bronze Bit
In simple wordsA vulnerability that allows delegation even for those marked 'do not allow delegation'.
Formal definition:CVE-2020-17049 — A signature check bypass in S4U2Proxy that allows delegation even for Protected Users or sensitive accounts.
CVE-2020-17049
In simple wordsThe official number for the bug that enabled Bronze Bit.
Formal definition:A Kerberos KDC vulnerability published in November 2020 — the basis for the Bronze Bit attack; addressed by Microsoft security updates.
SACL
In simple wordsA setting that says 'log who touched this object'.
Formal definition:System Access Control List — an audit list on an object; determines which actions will be written to the security log.
Canary Token
In simple wordsA phrase that chirps as soon as someone touches it.
Formal definition:A trap token (file, API key, link) where any use of it triggers an external alert.
GOAD
In simple wordsA ready-made training ground with a 'broken' AD to practice safely.
Formal definition:Game of Active Directory — An Orange Cyberdefense lab environment with ~5 intentionally vulnerable domains for practicing AD attacks and defenses.
Edge (BloodHound)
In simple wordsAn arrow in the graph that says 'X can do something to Y'.
Formal definition:An arc in the BloodHound graph representing a relationship between two nodes — MemberOf, AdminTo, HasSession, DCSync, etc.
Cypher
In simple wordsThe language used to ask the graph 'find me a path from A to B'.
Formal definition:The query language for Neo4j (and also BloodHound) — for finding patterns and paths in a graph.
FSSO
In simple wordsThe firewall learns who is behind each IP and can filter access by group.
Formal definition:Fortinet Single Sign-On maps users to IP addresses from AD logon events so the firewall can apply policy by domain group.
Collector Agent
In simple wordsIt reads logon events and tells the firewall who logged in and from where.
Formal definition:A service that reads the domain controller security log, including Event 4624, and sends user-to-IP mappings to FortiGate.
AAA
In simple wordsWho you are, what you may do and which actions were recorded.
Formal definition:Authentication, Authorization and Accounting — the three functions of a network identity service: who you are, what you may do and what you did.
RADIUS
In simple wordsA common user authentication protocol for VPN and Wi-Fi access.
Formal definition:An AAA protocol over UDP that encrypts only the password. It is used for VPN, Wi-Fi and 802.1X.
TACACS+
In simple wordsNetwork administrator authentication with encryption and a record of each command.
Formal definition:An AAA protocol over TCP that encrypts the entire payload and supports detailed per-command authorization. It suits administrator access to network devices.
802.1X
In simple wordsThe network port stays closed until the computer proves its identity.
Formal definition:A standard for authentication at a switch port or access point; until authentication succeeds, only EAP traffic to the RADIUS server is allowed.
NAC
In simple wordsThe network gatekeeper checks the device and decides where it may go.
Formal definition:Network Access Control determines who may connect, which VLAN they enter and which compliance conditions they must meet.
EAP-TLS
In simple wordsThe computer proves its identity with a digital certificate instead of a password.
Formal definition:An 802.1X method in which the client presents a device certificate issued by a CA such as AD CS; no password crosses the network.
PEAP
In simple wordsPassword authentication inside an encrypted tunnel is safe only when the server is validated.
Formal definition:An 802.1X method that carries the username and password inside a TLS tunnel. It is vulnerable to Evil Twin attacks if the client does not validate the server certificate.
Evil Twin
In simple wordsA fake wireless network designed to steal credentials.
Formal definition:A rogue access point that imitates a legitimate network to make clients connect and disclose credentials.
MAB
In simple wordsA printer exception based on a MAC address that can be forged.
Formal definition:MAC Authentication Bypass permits devices that do not support 802.1X based on their MAC address. A MAC address is easy to spoof.
FortiToken
In simple wordsA phone approval or code used in addition to the password.
Formal definition:A Fortinet second factor: a push/TOTP application or hardware token integrated with FortiAuthenticator.
FortiClient
In simple wordsThe user's computer application for VPN access and protection.
Formal definition:Fortinet's endpoint agent for VPN, antivirus and compliance checking, centrally managed through EMS.
EMS
In simple wordsThe central console for managing endpoints by AD group.
Formal definition:Endpoint Management Server centrally manages FortiClient, synchronizes with AD and applies policy by domain group.
FortiEDR
In simple wordsIt protects the computer by suspicious behavior, not signatures alone.
Formal definition:Fortinet's Endpoint Detection and Response product for behavioral detection of LSASS access, injection and other suspicious activity.
FortiAnalyzer
In simple wordsOne place for Fortinet logs and reports.
Formal definition:A platform that collects, correlates and reports on Fortinet product logs alongside a SIEM.
Defense-in-Depth
In simple wordsSeveral circles of defense instead of one, so that one failure doesn't bring everything down.
Formal definition:A security principle where protection is provided in independent layers, so that a failure in one control does not lead to overall failure.
Port Security
In simple wordsThe switch limits which devices are allowed to connect to a specific port.
Formal definition:A switch control that restricts which MAC addresses are allowed on a port and responds to deviations by blocking or alerting.
DHCP Snooping
In simple wordsPrevents a foreign device from distributing network addresses and routing traffic through it.
Formal definition:A switch mechanism that marks trusted ports and filters DHCP responses from unauthorized servers.
DAI
In simple wordsChecks that ARP messages are real and not a spoof by an attacker.
Formal definition:Dynamic ARP Inspection — Checks ARP messages against the DHCP Snooping table to prevent ARP spoofing.
Load Balancer
In simple wordsDistributes workload among servers so the service keeps working.
Formal definition:A component that distributes requests among servers for availability and performance; primarily serves the Availability leg of the CIA triad.
Proxy
In simple wordsAn intermediary that makes internet requests instead of your computer.
Formal definition:An intermediary that makes requests on behalf of internal network stations, hides internal addresses, and enables centralized Web policy.
WAF
In simple wordsA firewall that understands websites, not just addresses.
Formal definition:Web Application Firewall — Layer 7 protection for Web applications, including checking HTTP Methods, parameters, and OWASP Top 10 patterns.
UTM
In simple wordsOne box that combines several protections together.
Formal definition:Unified Threat Management — A device that centralizes Firewall, IPS, content filtering, and anti-malware; a compromise between simple management and depth/performance.
Mail Gateway
In simple wordsA guard at the entrance to the organizational email.
Formal definition:A mail gateway that filters Spam, enforces SMTP standards, checks Reverse DNS, and analyzes content before transferring to the internal mail server.
Reverse DNS
In simple wordsA check that the address and name truly belong to each other.
Formal definition:Translating an IP address to a domain name, which is checked, among other things, as an indication of the reliability of an email sender.
Stateless
In simple wordsChecks each packet individually, without remembering what happened before.
Formal definition:Filtering that decides on each packet separately based only on headers, without remembering the connection it belongs to.
Stateful Inspection
In simple wordsThe firewall remembers who initiated the connection and allows the response.
Formal definition:Filtering that maintains a table of active connections and allows traffic based on matching an existing connection.
State Table
In simple wordsA list of open conversations managed by the firewall.
Formal definition:The table of active connections for a Stateful firewall, containing addresses, ports, protocol, and connection status.
Application Gateway
In simple wordsAn intermediary that deeply inspects the content of communication.
Formal definition:A Proxy Firewall that terminates the connection on both sides and inspects the application protocol; secure but performance-intensive.
NGFW
In simple wordsA firewall that identifies which application is running, not just the port.
Formal definition:Next-Generation Firewall — a firewall with application identification, application control, and SSL Inspection capabilities.
IDS
In simple wordsDetects and alerts, but does not stop.
Formal definition:Intrusion Detection System — a system that detects suspicious activity and alerts, usually out of the traffic path.
IPS
In simple wordsIs in the path and can stop the attack.
Formal definition:Intrusion Prevention System — an inline system capable of blocking or disconnecting malicious traffic in real-time.
FortiOS
In simple wordsThe software that runs Fortinet devices.
Formal definition:The operating system for Fortinet products, identical across physical devices, VMs, and the cloud.
FortiGuard
In simple wordsAn update service that keeps security protection current.
Formal definition:Fortinet's intelligence and update services, including IPS signatures, application detection, and website categories.
NSE
In simple wordsThe names of Fortinet's older certifications.
Formal definition:Network Security Expert — Fortinet's historical certification path for levels 1–8; the current certification program uses new names and paths.
ICAO spelling alphabet
In simple wordsFixed words for each letter, so they are not confused over the phone.
Formal definition:An international spelling alphabet (Alfa, Bravo, Charlie ...) for accurate voice communication of letters and numbers.
AD CS
In simple wordsThe domain's «ID printer» — and a certificate can work like a password.
Formal definition:Active Directory Certificate Services — the built-in Windows certificate authority (CA); issues certificates for authentication, encryption, and signing inside the domain.
Certificate Template
In simple wordsThe certificate's manufacturing instructions — who gets one, what is allowed, and what is forbidden.
Formal definition:A template in AD CS defining who may request a certificate, for what purpose, and which fields the requester sets themselves; its misconfiguration is the basis of ESC1–ESC4.
ESC1–ESC8
In simple wordsEight open doors in the «ID printer» — any single one is enough for a takeover.
Formal definition:Eight common AD CS misconfigurations (per SpecterOps research) that allow obtaining certificates in other names and taking over the domain.
Replicating Directory Changes
In simple wordsA «replicate everything to me» license — normally reserved for DCs only.
Formal definition:A right on the domain object that allows requesting replication of AD data — including hashes; the right behind the DCSync attack.
NTLM Relay
In simple wordsInstead of breaking the lock — the key is passed along on the move.
Formal definition:An attack where the attacker forwards a victim's NTLM authentication in real time to another service, without cracking the hash; stopped by signing (SMB/LDAP Signing).
LLMNR
In simple wordsThe computer shouts «who knows this name?» — and the attacker answers first.
Formal definition:A local name-resolution protocol in Windows; when DNS fails, the computer asks the whole network — and an attacker can answer and receive authentication (poisoning).
Responder
In simple wordsThe tool that answers «me!» to every name query on the network.
Formal definition:An open-source tool for LLMNR/NBT-NS/mDNS poisoning and capturing NTLM authentications on the network; the standard for practicing NTLM Relay in a lab.
SMB Signing
In simple wordsA seal on every message — forwarding through a middleman breaks it.
Formal definition:A digital signature on SMB traffic verifying that authentication arrived directly from the source; enforcing it blocks NTLM Relay to file servers.
EPA (Extended Protection for Authentication)
In simple wordsA check that the authentication and the secure connection are one and the same — relay fails.
Formal definition:A Channel Binding mechanism in Windows that ties the authentication to the TLS channel; enforcing it on AD CS interfaces blocks ESC8.