PuReAIpureAi
Free scan

Research

Glossary of exposure and risk terminology

This category runs on acronyms. Here is what each one actually means, and how it shows up inside PuReAI.

Terms

External Attack Surface Management (EASM)

Continuous discovery and monitoring of everything an organization exposes to the internet, from an attacker's viewpoint, without agents or credentials.

Attack Surface Management (ASM)

The broader discipline of inventorying, monitoring and reducing every way an organization can be attacked, of which external management is one half.

Continuous Threat Exposure Management (CTEM)

A five-stage program, defined by Gartner, for continuously scoping, discovering, prioritizing, validating and mobilizing responses to exposure rather than running periodic assessments.

CISA Known Exploited Vulnerabilities Catalog (CISA KEV)

A US government catalog of vulnerabilities with confirmed real-world exploitation, used to prioritize patching above severity score alone.

MITRE ATT&CK

A public knowledge base of adversary tactics and techniques observed in real intrusions, used as a common language for describing attacker behavior.

Tactics, Techniques and Procedures (TTP)

How an adversary behaves, from high-level goal down to specific implementation, rather than which specific tool or indicator they used.

ICT Third-Party Risk

The DORA term for risk arising from an organization's information and communication technology suppliers, requiring an ongoing register and continuous oversight.

Supply Chain Security

Protecting an organization from risk introduced through vendors, software dependencies and other third parties rather than direct attacks on its own systems.

Typosquatting

Registering a domain that visually or phonetically resembles a real brand, typically to support phishing, fraud or brand impersonation.

Credential Stuffing

An automated attack that tries usernames and passwords leaked from other breaches against a target's login systems, exploiting password reuse.

Dark Web Monitoring

Continuously scanning criminal marketplaces, breach forums and paste sites for an organization's leaked credentials, data or mentions.

Common Vulnerabilities and Exposures (CVE)

The public identifier system for tracking a specific vulnerability in a specific product, used as the common reference across nearly every security tool and database.

Common Vulnerability Scoring System (CVSS)

A standardized 0-10 scale for rating the technical severity of a vulnerability, based on factors like attack complexity and impact, independent of real-world exploitation.

Exploit Prediction Scoring System (EPSS)

A data-driven score estimating the probability that a specific vulnerability will be exploited in the wild in the next 30 days.

Shadow IT

Internet-facing systems, applications or services in use without the security team's knowledge or approval, and therefore outside normal controls.