[{"data":1,"prerenderedAt":101},["ShallowReactive",2],{"wissen-index-en":3},[4,12,20,28,36,44,52,60,68,76,84,93],{"path":5,"title":6,"short":7,"synonyms":8},"\u002Fen\u002Fwissen\u002Fattack-surface-management","Attack Surface Management (ASM)","Attack surface management is the continuous discovery, assessment and reduction of every point through which an attacker can reach a company: external, internal and in the cloud.",[9,10,11],"ASM","Attack Surface Monitoring","Attack surface analysis",{"path":13,"title":14,"short":15,"synonyms":16},"\u002Fen\u002Fwissen\u002Fcisa-kev","CISA KEV (Known Exploited Vulnerabilities)","The CISA KEV catalogue is a list maintained by the US agency CISA of vulnerabilities proven to be exploited in real attacks, each with a remediation due date.",[17,18,19],"KEV","Known Exploited Vulnerabilities Catalog","CISA catalogue",{"path":21,"title":22,"short":23,"synonyms":24},"\u002Fen\u002Fwissen\u002Fcontinuous-threat-exposure-management","Continuous Threat Exposure Management (CTEM)","CTEM is a programme described by Gartner with five phases (scoping, discovery, prioritisation, validation, mobilisation) that reduces the attack surface continuously instead of at points in time.",[25,26,27],"CTEM","Exposure management","Threat exposure management",{"path":29,"title":30,"short":31,"synonyms":32},"\u002Fen\u002Fwissen\u002Fdarknet-monitoring","Dark Web Monitoring (Darknet Monitoring)","Dark web monitoring continuously searches underground forums, marketplaces, leak sites and stealer logs for a company's credentials, devices and data and reports hits before they are abused.",[33,34,35],"Darknet monitoring","Dark web surveillance","Credential monitoring",{"path":37,"title":38,"short":39,"synonyms":40},"\u002Fen\u002Fwissen\u002Fepss","EPSS (Exploit Prediction Scoring System)","EPSS is a scoring system by FIRST that estimates for every CVE the probability that it will actually be exploited within the next 30 days, as a value between 0 and 1.",[41,42,43],"Exploit Prediction Scoring System","EPSS score","EPSS percentile",{"path":45,"title":46,"short":47,"synonyms":48},"\u002Fen\u002Fwissen\u002Fexternal-attack-surface-management","External Attack Surface Management (EASM)","External attack surface management inventories and monitors from the outside every internet-facing asset of a company, exactly as an attacker sees it.",[49,50,51],"EASM","External attack surface monitoring","Outside-in attack surface analysis",{"path":53,"title":54,"short":55,"synonyms":56},"\u002Fen\u002Fwissen\u002Finfostealer","Infostealer","An infostealer is malware that collects passwords, session cookies, browser data and files stored on infected devices and sends them to criminals who sell them as logs.",[57,58,59],"Stealer","Information stealer","Stealer malware",{"path":61,"title":62,"short":63,"synonyms":64},"\u002Fen\u002Fwissen\u002Finitial-access-broker","Initial Access Broker (IAB)","An initial access broker is a cybercriminal who obtains access to corporate networks and sells that access on the dark web to other groups, usually ransomware operators.",[65,66,67],"IAB","Access broker","Network access broker",{"path":69,"title":70,"short":71,"synonyms":72},"\u002Fen\u002Fwissen\u002Fnis2","NIS2 Directive","NIS2 is EU Directive 2022\u002F2555 on network and information security, which obliges essential and important entities to risk management, incident reporting and supply chain security.",[73,74,70,75],"NIS-2","Directive (EU) 2022\u002F2555","NISG",{"path":77,"title":78,"short":79,"synonyms":80},"\u002Fen\u002Fwissen\u002Fpenetration-testing-as-a-service","Penetration Testing as a Service (PTaaS)","PTaaS delivers manual penetration tests through a platform instead of a PDF: findings appear continuously, retests are built in, and tests repeat on a regular schedule.",[81,82,83],"PTaaS","Pentest as a service","Continuous penetration testing",{"path":85,"title":86,"short":87,"synonyms":88},"\u002Fen\u002Fwissen\u002Ftyposquatting","Typosquatting (Lookalike Domains)","Typosquatting is the registration of domains that closely resemble a known brand in order to lead users to phishing or fraud pages through typos or deception.",[89,90,91,92],"Lookalike domains","Domain squatting","Cybersquatting","Homoglyph attack",{"path":94,"title":95,"short":96,"synonyms":97},"\u002Fen\u002Fwissen\u002Fvulnerability-management","Vulnerability Management","Vulnerability management is the ongoing process of detecting vulnerabilities in systems, prioritising them by risk, fixing them and evidencing the fix.",[98,99,100],"VM","Vulnerability management process","Vulnerability remediation",1789638254586]