top of page
Reference

Cyber security glossary: EDR, XDR, SIEM, EPSS, KEV and more.

Every term this site uses, defined once. 18 entries, written to be understood by whoever has to sign the purchase order as well as by the engineer who will run the thing.

ATT&CKMITRE ATT&CK®
A public knowledge base of adversary behaviour. Version 19, released 28 April 2026, catalogues 15 tactics, 222 techniques and 475 sub-techniques for enterprise environments.
CNVMCloud Native Vulnerability Management
Snapshot-based vulnerability scanning of running cloud workloads. Distinct from posture management, and with different platform coverage.
CSPMCloud Security Posture Management
Evaluation of cloud account configuration against hardening benchmarks such as CIS, identifying misconfiguration and drift rather than software vulnerabilities.
CVSSCommon Vulnerability Scoring System
A severity score describing how bad a vulnerability would be if exploited. Its own specification treats the base score as a ceiling, not a measure of risk in your environment.
DaCDetection as Code
Managing detection rules the way software is managed: version-controlled, peer-reviewed and tested before they reach production, so a rule change is traceable to who made it and why.
EASMExternal Attack Surface Management
Outside-in discovery and monitoring of everything an organisation exposes to the internet, including assets no inventory has recorded.
EDREndpoint Detection and Response
Continuous recording of process, file and network activity on the endpoint, so behaviour no prevention engine recognised can still be spotted, investigated and contained.
EPPEndpoint Protection Platform
Prevention at the endpoint: blocking known malware and malicious behaviour at execution, before anything runs.
EPSSExploit Prediction Scoring System
A data-driven model, scored daily by FIRST, estimating the probability that a published CVE will be exploited in the wild within the next 30 days.
KEVKnown Exploited Vulnerabilities catalogue
CISA's published record of vulnerabilities confirmed to be under active exploitation. Presence in KEV is evidence, not prediction.
NormalisationField normalisation
Mapping fields from many different log sources onto one common schema, so a single detection rule works across all of them instead of being rewritten per source.
NSMNetwork Security Monitoring
Observing behaviour across the network rather than enforcing policy at its boundary. Asks what something already inside is doing.
Parallel runParallel run
Running the outgoing and incoming SIEM side by side through a migration, so detection coverage is proven on the new platform before the old one is switched off.
SIEMSecurity Information and Event Management
Centralised collection and correlation of security-relevant events from across an estate, so activity spanning several systems is recognised as a single story.
SOARSecurity Orchestration, Automation and Response
Tooling that automates repetitive response steps and case handling, so analysts spend their time on judgement rather than mechanics.
TTPTactics, Techniques and Procedures
The behavioural signature of an adversary — what they are trying to achieve, how they achieve it, and the specific way they carry it out.
UEBAUser and Entity Behaviour Analytics
Risk scoring of users, hosts and services from their observed behaviour, surfacing anomalies and insider-threat patterns that rule matching does not express well.
XDRExtended Detection and Response
Correlation of endpoint signals with network and cloud telemetry, so an endpoint alert and a network anomaly become one incident rather than two tickets in two consoles.

These definitions describe the category, not a CyberTI product. Where we deliver something in one of these areas it is written up under services, with the scope and the limits stated.

The vocabulary

Every one of these is a moving part of the same system

The acronyms above are not a taxonomy. They are layers of one estate, watched together — which is the whole argument for buying them from one place.

Ready to see your attack surface the way an attacker does?

Book a walkthrough with an Australian-based security engineer. No scripted demo, no obligation.

Both forms deliver to info@cyberti.com.au.

bottom of page