• Access Rights & Permissions Matrix
    • Data Breach Notification Log
    • Data Classification Register
    • Data Loss Prevention (DLP) Incident Log
    • Document Retention & Disposal Tracker
    • Security KPI Dashboard
    • Asymmetric-Key Cryptography
    • Combined Security Model: Digital Signature + Digital Envelope
    • Database Encryption Techniques (API, Plug-in, TDE)
    • Diffie-Hellman Key Exchange
    • Digital Envelope
    • Digital Signature
    • Hash Function
    • Homomorphic Encryption
    • Hybrid Cryptography
    • PKI (Public Key Infrastructure)
    • Post-Quantum Cryptography (PQC)
    • Quantum Security
    • RSA Encryption
    • Sign-then-Encrypt
    • Symmetric-Key Cryptography
    • CIA Triad
    • Endpoint Security
    • Systematic Server Defense Strategy
    • DDoS Attack Mitigation Plan Tracker
    • IP Whitelist–Blacklist Tracker
    • Network Access Control Log
    • Network Device Inventory
    • Network Security Risk Mitigation
    • Network Traffic Monitoring Dashboard
    • DDoS (Distributed Denial of Service)
    • DRDoS (Distributed Reflective Denial of Service)
    • Network Separation & Integration
    • SASE (Secure Access Service Edge)
    • SDP (Software Defined Perimeter)
    • Spoofing
    • Zero Trust
    • IPSec
    • OSI 7-Layer Security
    • OSI 7-Layer Security Threats
    • TLS (Transport Layer Security)
    • Cloud Access Control Matrix
    • Cloud Asset Inventory Tracker
    • Cloud Backup & Recovery Testing Tracker
    • Cloud Incident Response Log
    • Cloud Security Configuration Baseline
    • CASB (Cloud Access Security Broker)
    • CNAPP (Cloud Native Application Protection Platform)
    • The Two Pillars of Cloud Security (CSPM and CWPP)
    • DSPM (Data Security Posture Management)
    • Integrated Cloud-Native Security Architecture
    • Shadow IT
    • Kubernetes Security
    • Amdahl's Law
    • Patch & Update Tracker
    • Secure Coding Checklist
    • Secure Mobile App Testing Tracker
    • Security Misconfiguration Log
    • Static Code Analysis Log
    • Web Application Vulnerability Tracker
    • Application Threat Modeling
    • CSRF (Cross-Site Request Forgery)
    • SQL Injection
    • XSS (Cross-Site Scripting)
    • API Security (OWASP API Top 10 and BOLA)
    • Code Security (SAST, DAST, and Secure Coding)
    • DevSecOps Pipeline
    • DevSecOps
    • Software Supply Chain Security (SBOM and SLSA)
    • Acceptable Use of Assets Policy
    • Password Policy
    • Backup and Recovery Policy
    • Compliance Management
    • Disposal and Destruction Policy
    • Information Classification Policy
    • Information Transfer Policy
    • ISMS Policy
    • COBIT-Based Security Governance
    • ISMS-P
    • ISO 27001
    • Privacy Impact Assessment (PIA)
    • Korea's Data 3 Acts
    • Differential Privacy
    • EU AI Act
    • 5 Pseudonymization Techniques
    • CSAP Tiered Certification
    • Incident Management Policy
    • Incident Management Process
    • Intern Incident Report
    • Major Incident Report Template
    • Structural Damage Incident Report
    • Workplace Violence Report
    • The Core of Endpoint Visibility, EDR
    • The Integrated Control Tower for Threat Detection and Analysis, SIEM
    • Digital Forensics
    • Known Error (KE) Record Template
    • Major Problem Report Template
    • Problem Management Process
    • Problem Record Template
    • DR Approach Document
    • DR Asset Register
    • DR Closure Report
    • DR Communications Plan
    • DR Plan Template
    • MAC vs. DAC vs. RBAC: Access Control Models Compared
    • Access Control
    • Authentication vs. Authorization
    • FIDO (Fast IDentity Online)
    • Identity Provider (IdP)
    • JWT (JSON Web Token)
    • Kerberos
    • OAuth 2.0
    • OAuth 2.0 and OIDC
    • OpenID Connect (OIDC)
    • Passkey
    • SAML (Security Assertion Markup Language)
    • Single Sign-On (SSO)
    • Active Directory (AD)
    • LDAP (Lightweight Directory Access Protocol)
    • Systematic Classification of Attack Techniques
    • Penetration Testing Methodology
    • OSINT (Open Source Intelligence)
    • OSSTMM (Open Source Security Testing Methodology Manual)
    • PTES (Penetration Testing Execution Standard)
    • RAV (Risk Assessment Value)
    • Fuzzing
    • CTF Categories
    • Red Teaming
    • AI System Security
    • Deepfake
    • LLM Security (OWASP Top 10 for LLM)
    • OT/ICS Security and the Purdue Model
    • Blockchain
    • GitHub
  • to navigate
  • to select
  • to close
    • Home
    • Offensive Security
    On this page
    radar

    Offensive Security

    Penetration testing methodology, vulnerability research, and red team / CTF practice used to proactively find weaknesses before attackers do.

    swords

    Systematic Classification of Attack Techniques

    A security analysis framework that classifies cyberattacks by stage, layer, and objective to optimize defense strategy and threat …

    checklist

    Penetration Testing Methodology

    The standardized procedures and technical framework for attempting to breach an organization's information systems from an attacker's …

    travel_explore

    OSINT (Open Source Intelligence)

    The practice of collecting and analyzing data from legally accessible public sources to derive intelligence that serves a specific purpose.

    analytics

    OSSTMM (Open Source Security Testing Methodology Manual)

    A security testing standard from ISECOM that scientifically and quantitatively measures the effectiveness of security controls to assess …

    gps_fixed

    PTES (Penetration Testing Execution Standard)

    A seven-stage technical execution standard defining the full penetration testing process, from pre-engagement to reporting, to guarantee …

    monitoring

    RAV (Risk Assessment Value)

    A quantitative OSSTMM security metric that mathematically derives the real effectiveness of controls within an operational channel as a …

    bug_report

    Fuzzing

    An automated software testing technique that repeatedly injects random or malformed input into a target and monitors for crashes to uncover …

    flag

    CTF Categories

    Capture The Flag competitions that test hands-on security skill across multiple domains by solving challenges to find a hidden flag string.

    groups

    Red Teaming

    A group or activity that mimics real attacker TTPs to run unannounced, realistic attacks against an organization in order to validate its …


    © 2026 Cybersecurity Knowledge Base. Built with Lotus Docs