Investigative Definitions & Glossary

    Authoritative reference for intelligence, investigations & cybersecurity disciplines

    243 terms

    Showing 243 of 243 terms

    ACINT (Acoustic Intelligence)

    Intelligence Collection

    Intelligence derived from the analysis of acoustic phenomena, particularly underwater sound for submarine detection.

    MilitaryNational Security
    Related:

    Advanced Persistent Threat (APT)

    Cyber Threat Intelligence

    Also known as: APT

    A sophisticated, well-resourced, and often state-sponsored threat actor that conducts prolonged, targeted cyber campaigns against specific organizations or nations. APTs are characterized by their ...

    A sophisticated, well-resourced, and often state-sponsored threat actor that conducts prolonged, targeted cyber campaigns against specific organizations or nations. APTs are characterized by their persistence, use of advanced tools and techniques, careful operational security, and strategic objectives.
    CybersecurityNational Security
    Related:

    Affidavit

    Law Enforcement & Investigations

    A written sworn statement of facts submitted by an investigator to a judge in support of a request for a search warrant, arrest warrant, or other court order.

    Law EnforcementLegal
    Related:

    All-Source Intelligence

    Intelligence Analysis

    Also known as: All-Source Analysis, Fused Intelligence

    Intelligence products and organizations that incorporate all sources of information in the production of finished intelligence. All-source analysis fuses information from HUMINT, SIGINT, IMINT, MAS...

    Intelligence products and organizations that incorporate all sources of information in the production of finished intelligence. All-source analysis fuses information from HUMINT, SIGINT, IMINT, MASINT, OSINT, and other collection disciplines to produce the most complete and accurate intelligence assessment possible.
    MilitaryNational SecurityLaw Enforcement
    Related:

    Analysis of Competing Hypotheses (ACH)

    Intelligence Analysis

    Also known as: ACH

    A structured analytic technique that identifies a complete set of alternative hypotheses, systematically evaluates data for consistency with each hypothesis, and focuses analysis on disproving hypo...

    A structured analytic technique that identifies a complete set of alternative hypotheses, systematically evaluates data for consistency with each hypothesis, and focuses analysis on disproving hypotheses rather than confirming a favored one. Developed by Richards Heuer at the CIA to mitigate cognitive biases in intelligence analysis.
    Intelligence AnalysisLaw EnforcementAcademic Research
    Related:

    Anti-Money Laundering (AML)

    Financial Crimes & Fraud

    Also known as: AML

    A set of laws, regulations, procedures, and controls designed to prevent criminals from disguising illegally obtained funds as legitimate income. AML frameworks require financial institutions to im...

    A set of laws, regulations, procedures, and controls designed to prevent criminals from disguising illegally obtained funds as legitimate income. AML frameworks require financial institutions to implement customer due diligence, transaction monitoring, suspicious activity reporting, and compliance programs.
    Financial CrimesCompliance
    Related:

    API (Application Programming Interface)

    OSINT & Digital Research

    A defined interface that enables automated access to platform data and services, used extensively in OSINT for programmatic data collection.

    OSINTCybersecurityData Science
    Related:

    Asset

    Counterintelligence & Espionage

    Also known as: Agent, Recruited Source, Recruited Agent

    A person — typically a foreign national — recruited by an intelligence service to provide secret information or to perform clandestine tasks. An asset is not an employee of the intelligence service...

    A person — typically a foreign national — recruited by an intelligence service to provide secret information or to perform clandestine tasks. An asset is not an employee of the intelligence service but rather a source who has been developed, recruited, and is managed by an intelligence officer.
    National SecurityCounterintelligence
    Related:

    Asset Tracing

    Financial Crimes & Fraud

    The investigative process of identifying, locating, and documenting assets belonging to a subject of investigation. Asset tracing follows the movement of funds and property through multiple account...

    The investigative process of identifying, locating, and documenting assets belonging to a subject of investigation. Asset tracing follows the movement of funds and property through multiple accounts, jurisdictions, and ownership structures.
    Financial CrimesLaw Enforcement
    Related:

    Association Matrix

    Analytical Methodologies

    A tabular analytical tool used to identify and display the relationships between entities (people, organizations, events, locations) in an investigation. The matrix arranges entities along both axe...

    A tabular analytical tool used to identify and display the relationships between entities (people, organizations, events, locations) in an investigation. The matrix arranges entities along both axes and records the nature and strength of observed connections in the intersecting cells.
    Intelligence AnalysisLaw Enforcement
    Related:

    Attack Surface

    Cybersecurity & Digital Forensics

    The total number of points where an unauthorized user can attempt to enter or extract data from a system, including network interfaces, software, APIs, and human factors.

    Cybersecurity
    Related:

    Attribution

    Cyber Threat Intelligence

    The process of identifying the responsible party behind a cyber operation or attack. Attribution is technically challenging and politically sensitive, requiring correlation of technical indicators,...

    The process of identifying the responsible party behind a cyber operation or attack. Attribution is technically challenging and politically sensitive, requiring correlation of technical indicators, tradecraft analysis, human intelligence, and sometimes geopolitical context.
    CybersecurityCyber Threat IntelligenceNational Security
    Related:

    Authentication

    Evidence & Forensics

    The process of establishing that evidence is what it purports to be. Digital evidence authentication may involve hash verification, metadata analysis, chain of custody documentation, and expert tes...

    The process of establishing that evidence is what it purports to be. Digital evidence authentication may involve hash verification, metadata analysis, chain of custody documentation, and expert testimony.
    LegalDigital Forensics
    Related:

    Background Investigation

    Corporate & Private Investigations

    A systematic inquiry into an individual's history and character, typically conducted as part of employment screening, security clearance processing, or tenancy evaluation. Background investigations...

    A systematic inquiry into an individual's history and character, typically conducted as part of employment screening, security clearance processing, or tenancy evaluation. Background investigations may examine criminal records, employment history, education verification, credit history, and reference checks.
    Corporate SecurityHuman ResourcesGovernment
    Related:

    Bank Secrecy Act (BSA)

    Financial Crimes & Fraud

    The primary U.S. anti-money laundering law that requires financial institutions to maintain records of cash transactions and report suspicious activities to FinCEN.

    Financial CrimesCompliance
    Related:

    Beneficial Ownership

    Financial Crimes & Fraud

    The natural person(s) who ultimately own, control, or benefit from a legal entity or financial arrangement, even if the entity is legally owned through intermediaries, shell companies, or nominees.

    Financial CrimesComplianceLaw Enforcement
    Related:

    Biometrics

    Evidence & Forensics

    Automated methods of recognizing or verifying the identity of a living person based on physiological or behavioral characteristics. Biometric modalities include fingerprints, facial recognition, ir...

    Automated methods of recognizing or verifying the identity of a living person based on physiological or behavioral characteristics. Biometric modalities include fingerprints, facial recognition, iris scanning, voice recognition, DNA profiling, gait analysis, and keystroke dynamics.
    Law EnforcementSecurityForensics
    Related:

    Blockchain

    Financial Crimes & Fraud

    A distributed, immutable digital ledger that records transactions across a network of computers. Each block contains a cryptographic hash of the previous block, creating a tamper-evident chain used...

    A distributed, immutable digital ledger that records transactions across a network of computers. Each block contains a cryptographic hash of the previous block, creating a tamper-evident chain used by cryptocurrencies and increasingly in supply chain, identity, and record management.
    Financial CrimesCybersecurity
    Related:

    Botnet

    Cybersecurity & Digital Forensics

    A network of compromised computers (bots or zombies) controlled remotely by an attacker, typically used for DDoS attacks, spam distribution, or credential stuffing.

    CybersecurityLaw Enforcement
    Related:

    Brady Material

    Legal & Compliance

    Also known as: Brady Disclosure, Exculpatory Evidence

    Evidence in the possession of the prosecution that is favorable to the defendant and material to either guilt or punishment. Under the Brady v. Maryland Supreme Court ruling, the prosecution has a ...

    Evidence in the possession of the prosecution that is favorable to the defendant and material to either guilt or punishment. Under the Brady v. Maryland Supreme Court ruling, the prosecution has a constitutional obligation to disclose such evidence to the defense.
    Law EnforcementLegal
    Related:

    Brush Pass

    Counterintelligence & Espionage

    A brief, prearranged moment of physical proximity during which materials are discreetly transferred between an intelligence officer and an asset without observable direct contact.

    National SecurityCounterintelligence
    Related:

    Burn Notice

    Counterintelligence & Espionage

    An official statement that an intelligence source or agent is unreliable, has been compromised, or should no longer be trusted or used for intelligence purposes.

    National SecurityCounterintelligence
    Related:

    Business Email Compromise (BEC)

    Financial Crimes & Fraud

    Also known as: BEC, CEO Fraud, Email Account Compromise

    A sophisticated fraud scheme in which criminals use email — often after compromising or spoofing a legitimate business email account — to impersonate executives, vendors, or attorneys and trick emp...

    A sophisticated fraud scheme in which criminals use email — often after compromising or spoofing a legitimate business email account — to impersonate executives, vendors, or attorneys and trick employees into making wire transfers or divulging sensitive information.
    CybersecurityFinancial CrimesLaw Enforcement
    Related:

    Cached Content

    OSINT & Digital Research

    Stored copies of web pages maintained by search engines and web archives that preserve content even after the original has been modified or deleted.

    OSINT
    Related:

    CARVER Matrix

    Analytical Methodologies

    Also known as: CARVER

    A target analysis and vulnerability assessment methodology that evaluates potential targets based on six criteria: Criticality, Accessibility, Recuperability, Vulnerability, Effect, and Recognizabi...

    A target analysis and vulnerability assessment methodology that evaluates potential targets based on six criteria: Criticality, Accessibility, Recuperability, Vulnerability, Effect, and Recognizability. Originally developed for military targeting, CARVER is now widely used in critical infrastructure protection and counterterrorism.
    MilitaryHomeland SecurityCritical Infrastructure
    Related:

    Case Officer

    Counterintelligence & Espionage

    Also known as: Handler, Operations Officer

    A professional intelligence officer responsible for recruiting, managing, and directing human intelligence assets. The case officer develops relationships with potential sources, assesses their acc...

    A professional intelligence officer responsible for recruiting, managing, and directing human intelligence assets. The case officer develops relationships with potential sources, assesses their access and reliability, handles the tradecraft of clandestine communications.
    National SecurityCounterintelligence
    Related:

    CBRN (Chemical, Biological, Radiological, Nuclear)

    Homeland Security & Counterterrorism

    The categorization of weapons of mass destruction and hazardous materials by their type. CBRN defense encompasses detection, protection, decontamination, and medical countermeasures.

    MilitaryHomeland Security
    Related:

    Chain of Custody

    Cybersecurity & Digital Forensics

    The documented chronological history of the seizure, custody, control, transfer, analysis, and disposition of evidence. A proper chain of custody establishes that evidence has been handled in a man...

    The documented chronological history of the seizure, custody, control, transfer, analysis, and disposition of evidence. A proper chain of custody establishes that evidence has been handled in a manner that prevents tampering or contamination, and is essential for evidence admissibility in court.
    Law EnforcementDigital Forensics
    Related:

    Classification

    Legal & Compliance

    The system by which national security information is designated at levels reflecting the damage that unauthorized disclosure could cause. The three classification levels are Confidential (damage), ...

    The system by which national security information is designated at levels reflecting the damage that unauthorized disclosure could cause. The three classification levels are Confidential (damage), Secret (serious damage), and Top Secret (exceptionally grave damage).
    National SecurityLegal
    Related:

    Cognitive Bias

    Intelligence Analysis

    Systematic patterns of deviation from rational judgment that affect intelligence analysis. Common biases include confirmation bias (favoring information that confirms existing beliefs), anchoring b...

    Systematic patterns of deviation from rational judgment that affect intelligence analysis. Common biases include confirmation bias (favoring information that confirms existing beliefs), anchoring bias (over-relying on initial information), mirror imaging (assuming others think like you), and availability heuristic (overweighting readily recalled information).
    Intelligence AnalysisLaw EnforcementPsychology
    Related:

    Cognitive Interview

    Interview & Interrogation

    A structured interviewing technique developed by Fisher and Geiselman that uses cognitive psychological principles to enhance witness memory retrieval. The technique employs mental reinstatement of...

    A structured interviewing technique developed by Fisher and Geiselman that uses cognitive psychological principles to enhance witness memory retrieval. The technique employs mental reinstatement of context, reporting everything regardless of perceived importance, recalling events in different orders, and changing perspectives.
    Law EnforcementPsychology
    Related:

    Collection Management

    Intelligence Collection

    The process of converting intelligence requirements into collection requirements, establishing priorities, tasking or coordinating with appropriate collection sources or agencies, monitoring result...

    The process of converting intelligence requirements into collection requirements, establishing priorities, tasking or coordinating with appropriate collection sources or agencies, monitoring results, and retasking as necessary to satisfy the intelligence consumer's needs.
    Intelligence AnalysisMilitary
    Related:

    Collection Plan

    Intelligence Collection

    A systematic document that identifies the intelligence gaps, determines the appropriate collection capabilities, assigns specific collection tasks, and establishes timelines for collecting the requ...

    A systematic document that identifies the intelligence gaps, determines the appropriate collection capabilities, assigns specific collection tasks, and establishes timelines for collecting the required information to satisfy intelligence requirements.
    Intelligence AnalysisMilitaryLaw Enforcement
    Related:

    Collection Posture

    Intelligence Collection

    The current state and readiness of an organization's intelligence collection capabilities against specific targets or requirements.

    Intelligence AnalysisMilitary
    Related:

    COMINT (Communications Intelligence)

    Intelligence Collection

    Also known as: Communications Intelligence

    Intelligence derived from the intercept of foreign communications by other than the intended recipients. COMINT includes the monitoring, recording, and exploitation of foreign voice, data, fax, and...

    Intelligence derived from the intercept of foreign communications by other than the intended recipients. COMINT includes the monitoring, recording, and exploitation of foreign voice, data, fax, and other transmissions.
    MilitaryNational SecurityCybersecurity
    Related:

    Command and Control (C2)

    Cyber Threat Intelligence

    Also known as: C2, C&C

    The infrastructure and communication channels used by an attacker to maintain contact with and issue instructions to compromised systems within a target network. C2 mechanisms range from simple dir...

    The infrastructure and communication channels used by an attacker to maintain contact with and issue instructions to compromised systems within a target network. C2 mechanisms range from simple direct connections to sophisticated networks using encrypted channels, domain fronting, social media, and steganography.
    CybersecurityCyber Threat Intelligence
    Related:

    Compartmentation

    Counterintelligence & Espionage

    The principle of limiting access to information to only those persons who require it for their specific roles, even among individuals with the same security clearance level.

    National SecurityCounterintelligence
    Related:

    Competitive Intelligence

    Corporate & Private Investigations

    Also known as: CI (Business), Business Intelligence

    The systematic collection and analysis of information about competitors, market conditions, and industry trends using legally and ethically obtained sources. Competitive intelligence informs strate...

    The systematic collection and analysis of information about competitors, market conditions, and industry trends using legally and ethically obtained sources. Competitive intelligence informs strategic business decisions and is distinguished from industrial espionage by its reliance on legitimate, publicly available information.
    CorporateBusiness Strategy
    Related:

    Confidence Level

    Intelligence Analysis

    The degree of certainty an analyst has in an intelligence assessment or judgment. Typically expressed as high, moderate, or low confidence based on the quality and quantity of available information...

    The degree of certainty an analyst has in an intelligence assessment or judgment. Typically expressed as high, moderate, or low confidence based on the quality and quantity of available information, the strength of underlying logic, and the degree of analyst agreement.
    All disciplines
    Related:

    Controlled Delivery

    Law Enforcement & Investigations

    An investigative technique in which law enforcement allows an illegal or suspect shipment to continue under surveillance to identify all parties involved in the criminal activity.

    Law Enforcement
    Related:

    Counterintelligence (CI)

    Counterintelligence & Espionage

    Also known as: CI

    Activities conducted to identify, assess, neutralize, and exploit the intelligence collection efforts of foreign adversaries, terrorist organizations, and other hostile entities. CI encompasses bot...

    Activities conducted to identify, assess, neutralize, and exploit the intelligence collection efforts of foreign adversaries, terrorist organizations, and other hostile entities. CI encompasses both defensive measures (protecting one's own information) and offensive operations (exploiting and disrupting adversary intelligence services).
    National SecurityMilitaryLaw Enforcement
    Related:

    Countersurveillance

    Surveillance & Countersurveillance

    Active measures taken by an individual or team to detect, identify, and evade surveillance. Countersurveillance techniques include surveillance detection routes (SDRs), counter-technical surveillan...

    Active measures taken by an individual or team to detect, identify, and evade surveillance. Countersurveillance techniques include surveillance detection routes (SDRs), counter-technical surveillance sweeps, and behavioral awareness.
    CounterintelligenceLaw Enforcement
    Related:

    Credential Breach

    OSINT & Digital Research

    Also known as: Data Breach, Credential Dump, Combo List

    An incident in which user authentication data — typically email addresses and passwords — is exposed through a data breach and subsequently made available on the internet or dark web. Investigators...

    An incident in which user authentication data — typically email addresses and passwords — is exposed through a data breach and subsequently made available on the internet or dark web. Investigators use breach databases to identify password reuse patterns, discover associated accounts, and map a subject's digital presence.
    OSINTCybersecurity
    Related:

    Critical Infrastructure

    Homeland Security & Counterterrorism

    The physical and cyber systems and assets so vital to a nation that their incapacitation or destruction would have a debilitating impact on national security, economic stability, public health, or ...

    The physical and cyber systems and assets so vital to a nation that their incapacitation or destruction would have a debilitating impact on national security, economic stability, public health, or safety. The U.S. designates 16 critical infrastructure sectors.
    Homeland SecurityCybersecurity
    Related:

    Cryptocurrency Tracing

    Financial Crimes & Fraud

    The process of analyzing blockchain transactions to follow the movement of cryptocurrency between wallets and identify the parties involved. Despite the pseudonymous nature of most cryptocurrencies...

    The process of analyzing blockchain transactions to follow the movement of cryptocurrency between wallets and identify the parties involved. Despite the pseudonymous nature of most cryptocurrencies, blockchain analysis tools can cluster addresses, identify exchanges, and connect wallet activity to real-world identities.
    Financial CrimesCybersecurityLaw Enforcement
    Related:

    Currency Transaction Report (CTR)

    Financial Crimes & Fraud

    Also known as: CTR

    A mandatory report filed by financial institutions with FinCEN for each cash transaction exceeding $10,000. CTRs capture information about the transaction and the parties involved. Structuring tran...

    A mandatory report filed by financial institutions with FinCEN for each cash transaction exceeding $10,000. CTRs capture information about the transaction and the parties involved. Structuring transactions to avoid CTR thresholds is itself a federal crime.
    Financial CrimesCompliance
    Related:

    Current Intelligence

    Intelligence Analysis

    Intelligence of immediate interest to consumers concerning events and developments that are ongoing or have recently occurred.

    All disciplines
    Related:

    Customer Due Diligence (CDD)

    Financial Crimes & Fraud

    The process of verifying customer identity, understanding their business, and assessing the risk level they present for money laundering or terrorist financing.

    Financial CrimesCompliance
    Related:

    Cyber Kill Chain

    Cyber Threat Intelligence

    Also known as: Kill Chain

    A framework developed by Lockheed Martin that describes the stages of a cyberattack from initial reconnaissance through actions on objectives. The seven stages are: reconnaissance, weaponization, d...

    A framework developed by Lockheed Martin that describes the stages of a cyberattack from initial reconnaissance through actions on objectives. The seven stages are: reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives.
    Cybersecurity
    Related:

    CYBINT (Cyber Intelligence)

    Intelligence Collection

    Intelligence derived from cyberspace operations and cyber threat data.

    CybersecurityNational Security
    Related:

    Dangle

    Counterintelligence & Espionage

    A person intentionally presented to a foreign intelligence service as a potential recruit, either to gather intelligence about the service's recruitment methods or to feed disinformation.

    National SecurityCounterintelligence
    Related:

    Dark Web

    Cybersecurity & Digital Forensics

    The portion of the internet that is intentionally hidden and inaccessible through standard web browsers, requiring specialized software (such as Tor) to access. The dark web hosts both legitimate p...

    The portion of the internet that is intentionally hidden and inaccessible through standard web browsers, requiring specialized software (such as Tor) to access. The dark web hosts both legitimate privacy-focused services and illicit marketplaces for stolen data, drugs, weapons, and hacking services.
    CybersecurityLaw EnforcementOSINT
    Related:

    Data Broker

    OSINT & Digital Research

    A business that collects, aggregates, and sells personal information from public records, social media, and commercial sources to third parties.

    OSINTPrivacy
    Related:

    Daubert Standard

    Evidence & Forensics

    The legal standard for admissibility of expert testimony and scientific evidence in federal courts, established by Daubert v. Merrell Dow Pharmaceuticals. Under Daubert, the trial judge evaluates w...

    The legal standard for admissibility of expert testimony and scientific evidence in federal courts, established by Daubert v. Merrell Dow Pharmaceuticals. Under Daubert, the trial judge evaluates whether expert testimony is based on reliable methodology by considering testability, peer review, known error rates, and general acceptance.
    LegalForensic Science
    Related:

    DDoS (Distributed Denial of Service)

    Cybersecurity & Digital Forensics

    An attack that overwhelms a target system, service, or network with traffic from multiple compromised sources, rendering it unavailable to legitimate users.

    Cybersecurity
    Related:

    Dead Drop

    Counterintelligence & Espionage

    A method of clandestine communication in which materials (documents, funds, instructions) are left at a prearranged hidden location for later retrieval by another party, avoiding the need for direc...

    A method of clandestine communication in which materials (documents, funds, instructions) are left at a prearranged hidden location for later retrieval by another party, avoiding the need for direct personal contact.
    National SecurityCounterintelligence
    Related:

    Deconfliction

    Law Enforcement & Investigations

    The process of determining whether multiple law enforcement agencies or units are investigating the same subject, location, or event, in order to prevent operational conflicts, officer safety issue...

    The process of determining whether multiple law enforcement agencies or units are investigating the same subject, location, or event, in order to prevent operational conflicts, officer safety issues, and compromised investigations.
    Law Enforcement
    Related:

    Digital Exhaust

    OSINT & Digital Research

    The passive data trail generated by a person's online activities without their deliberate intent, including metadata from files, IP address logs, browser fingerprints, device identifiers, location ...

    The passive data trail generated by a person's online activities without their deliberate intent, including metadata from files, IP address logs, browser fingerprints, device identifiers, location data from photos, and behavioral patterns tracked by analytics.
    OSINTCybersecurity
    Related:

    Digital Footprint

    OSINT & Digital Research

    The trail of data a person or entity leaves behind through their digital activities, including websites visited, social media activity, emails sent, online purchases, and data shared with services....

    The trail of data a person or entity leaves behind through their digital activities, including websites visited, social media activity, emails sent, online purchases, and data shared with services. Digital footprints can be active (deliberately created) or passive (collected without the user's knowledge), and serve as a foundational resource in OSINT investigations.
    OSINTCybersecurityLaw Enforcement
    Related:

    Digital Forensics

    Cybersecurity & Digital Forensics

    Also known as: Computer Forensics, Cyber Forensics

    The scientific process of identifying, preserving, collecting, analyzing, and presenting digital evidence from electronic devices and digital storage media in a manner that is legally admissible. D...

    The scientific process of identifying, preserving, collecting, analyzing, and presenting digital evidence from electronic devices and digital storage media in a manner that is legally admissible. Digital forensics encompasses computer forensics, mobile forensics, network forensics, and cloud forensics.
    Law EnforcementCybersecurity
    Related:

    Discovery

    Evidence & Forensics

    The pretrial legal process in which parties to a lawsuit can obtain evidence and information from each other and from third parties through depositions, interrogatories, requests for documents, and...

    The pretrial legal process in which parties to a lawsuit can obtain evidence and information from each other and from third parties through depositions, interrogatories, requests for documents, and subpoenas.
    Legal
    Related:

    Dissemination

    Intelligence Analysis

    The timely delivery of finished intelligence to authorized consumers in the appropriate format and through authorized channels.

    All disciplines
    Related:

    Domain Fronting

    OSINT & Digital Research

    A technique that uses different domain names at different layers of communication to circumvent censorship or disguise the true destination of traffic.

    OSINTCybersecurity
    Related:

    Dork / Google Dorking

    OSINT & Digital Research

    Also known as: Google Hacking, Advanced Search Operators

    The technique of using advanced search operators and specialized queries to locate specific information on the internet that is not easily discoverable through basic searches. Operators like site:,...

    The technique of using advanced search operators and specialized queries to locate specific information on the internet that is not easily discoverable through basic searches. Operators like site:, filetype:, intitle:, inurl:, and Boolean operators can reveal exposed documents, login portals, configuration files, and other sensitive data indexed by search engines.
    OSINTCybersecurity
    Related:

    Double Agent

    Counterintelligence & Espionage

    An agent who has been turned or recruited by a second intelligence service to work against their original service while maintaining the appearance of loyalty. Double agents can provide valuable cou...

    An agent who has been turned or recruited by a second intelligence service to work against their original service while maintaining the appearance of loyalty. Double agents can provide valuable counterintelligence information and feed disinformation to the adversary.
    National SecurityCounterintelligence
    Related:

    Due Diligence

    Corporate & Private Investigations

    A comprehensive investigation and analysis conducted to evaluate a person, business, or transaction before entering into a contractual agreement, partnership, investment, or employment relationship...

    A comprehensive investigation and analysis conducted to evaluate a person, business, or transaction before entering into a contractual agreement, partnership, investment, or employment relationship. Due diligence examines financial records, legal standing, reputation, regulatory compliance, and litigation history.
    Corporate SecurityFinancial
    Related:

    Elicitation

    Interview & Interrogation

    The strategic use of conversational techniques to extract information from a person without their awareness that they are being specifically targeted for intelligence purposes. Elicitation exploits...

    The strategic use of conversational techniques to extract information from a person without their awareness that they are being specifically targeted for intelligence purposes. Elicitation exploits natural human tendencies such as the desire to appear knowledgeable, correct perceived errors, or respond to flattery.
    HUMINTCounterintelligenceLaw Enforcement
    Related:

    ELINT (Electronic Intelligence)

    Intelligence Collection

    Also known as: Electronic Intelligence

    Intelligence derived from foreign non-communications electromagnetic radiations emanating from sources other than nuclear detonations or radioactive sources. Primarily concerned with radar emission...

    Intelligence derived from foreign non-communications electromagnetic radiations emanating from sources other than nuclear detonations or radioactive sources. Primarily concerned with radar emissions and other electronic systems used for tracking, guidance, and weapons control.
    MilitaryNational Security
    Related:

    Encryption

    Cybersecurity & Digital Forensics

    The process of converting plaintext data into an unreadable format (ciphertext) using a mathematical algorithm and a key, so that only authorized parties with the correct decryption key can access ...

    The process of converting plaintext data into an unreadable format (ciphertext) using a mathematical algorithm and a key, so that only authorized parties with the correct decryption key can access the original information. Encryption is fundamental to data protection, communications security, and is a frequent challenge in forensic investigations.
    CybersecurityDigital Forensics
    Related:

    Enhanced Due Diligence (EDD)

    Financial Crimes & Fraud

    Heightened scrutiny and additional verification measures applied to higher-risk customers, such as politically exposed persons (PEPs), foreign correspondents, and customers from high-risk jurisdict...

    Heightened scrutiny and additional verification measures applied to higher-risk customers, such as politically exposed persons (PEPs), foreign correspondents, and customers from high-risk jurisdictions.
    Financial CrimesCompliance
    Related:

    Entrapment

    Law Enforcement & Investigations

    An illegal law enforcement practice in which an officer or agent induces a person to commit a crime that they would not have otherwise committed. Entrapment is an affirmative defense; the defendant...

    An illegal law enforcement practice in which an officer or agent induces a person to commit a crime that they would not have otherwise committed. Entrapment is an affirmative defense; the defendant must show that the government originated the criminal design.
    Law EnforcementLegal
    Related:

    Espionage

    Counterintelligence & Espionage

    The clandestine practice of obtaining secret or confidential information from a government, military, corporation, or other entity without the permission of the holder. Espionage may be conducted b...

    The clandestine practice of obtaining secret or confidential information from a government, military, corporation, or other entity without the permission of the holder. Espionage may be conducted by foreign intelligence services, corporate competitors, or individuals.
    National SecurityLaw EnforcementCounterintelligence
    Related:

    Estimative Intelligence

    Intelligence Analysis

    Intelligence that projects future developments and outcomes, identifying what might happen and its implications.

    All disciplines
    Related:

    Event Charting

    Analytical Methodologies

    An analytical visualization technique that displays events in chronological order along a timeline, showing the relationships between activities, actors, and outcomes. Event charts help investigato...

    An analytical visualization technique that displays events in chronological order along a timeline, showing the relationships between activities, actors, and outcomes. Event charts help investigators identify cause-and-effect relationships and spot gaps in the investigative record.
    Intelligence AnalysisLaw Enforcement
    Related:

    Evidence Preservation

    Evidence & Forensics

    The procedures and measures taken to protect physical and digital evidence from contamination, alteration, loss, or destruction from the point of collection through court presentation. Proper prese...

    The procedures and measures taken to protect physical and digital evidence from contamination, alteration, loss, or destruction from the point of collection through court presentation. Proper preservation maintains the integrity and admissibility of evidence.
    Law EnforcementDigital Forensics
    Related:

    Exclusionary Rule

    Legal & Compliance

    A legal principle that prohibits evidence obtained in violation of the Fourth Amendment from being used in criminal prosecution. The rule is designed to deter unconstitutional police conduct. Excep...

    A legal principle that prohibits evidence obtained in violation of the Fourth Amendment from being used in criminal prosecution. The rule is designed to deter unconstitutional police conduct. Exceptions include the good faith exception, inevitable discovery, and independent source doctrines.
    Law EnforcementLegal
    Related:

    EXIF Data

    OSINT & Digital Research

    Also known as: EXIF, Exchangeable Image File Format

    Exchangeable Image File Format data embedded in digital photographs that can contain the camera model, date and time the photo was taken, GPS coordinates, exposure settings, and software used to ed...

    Exchangeable Image File Format data embedded in digital photographs that can contain the camera model, date and time the photo was taken, GPS coordinates, exposure settings, and software used to edit the image. EXIF data is a critical resource in OSINT investigations for verifying image authenticity, determining location, and establishing timelines.
    OSINTDigital ForensicsLaw Enforcement
    Related:

    Exigent Circumstances

    Law Enforcement & Investigations

    Emergency conditions that justify law enforcement taking immediate action without a warrant, such as imminent destruction of evidence, hot pursuit of a suspect, or threat to life.

    Law Enforcement
    Related:

    Expert Witness

    Evidence & Forensics

    A person with specialized knowledge, skill, experience, training, or education who is qualified to provide opinion testimony on matters within their expertise to assist the trier of fact.

    LegalForensic Science
    Related:

    Exploit

    Cybersecurity & Digital Forensics

    A piece of code, technique, or sequence of commands that takes advantage of a vulnerability to cause unintended behavior, including unauthorized access or code execution.

    Cybersecurity
    Related:

    False Flag

    Counterintelligence & Espionage

    An operation designed to appear as if it were carried out by a party other than the actual perpetrator, used in both intelligence operations and cyberattacks to misdirect attribution.

    National SecurityCounterintelligenceCybersecurity
    Related:

    FinCEN (Financial Crimes Enforcement Network)

    Financial Crimes & Fraud

    The bureau of the U.S. Department of the Treasury responsible for collecting and analyzing financial transaction data to combat money laundering, terrorist financing, and other financial crimes.

    Financial CrimesCompliance
    Related:

    FININT (Financial Intelligence)

    Intelligence Collection

    Also known as: Financial Intelligence

    Intelligence gathered from analysis of financial transactions, monetary flows, and economic data to detect illicit financing, money laundering, sanctions evasion, terrorist financing, and other fin...

    Intelligence gathered from analysis of financial transactions, monetary flows, and economic data to detect illicit financing, money laundering, sanctions evasion, terrorist financing, and other financial crimes. Sources include banking records, wire transfers, suspicious activity reports, and financial regulatory filings.
    Law EnforcementNational SecurityFinancial Crimes
    Related:

    Finished Intelligence

    Intelligence Analysis

    The final product of the intelligence cycle — analyzed, evaluated, and interpreted information that has been converted into intelligence suitable for the customer's use. Finished intelligence provi...

    The final product of the intelligence cycle — analyzed, evaluated, and interpreted information that has been converted into intelligence suitable for the customer's use. Finished intelligence provides context, draws conclusions, and makes assessments that go beyond raw reporting.
    All disciplines
    Related:

    Firewall

    Cybersecurity & Digital Forensics

    A network security device or software that monitors and controls incoming and outgoing network traffic based on predetermined security rules, establishing a barrier between trusted and untrusted ne...

    A network security device or software that monitors and controls incoming and outgoing network traffic based on predetermined security rules, establishing a barrier between trusted and untrusted networks.
    Cybersecurity
    Related:

    FISA (Foreign Intelligence Surveillance Act)

    Legal & Compliance

    Also known as: FISA

    A federal law that establishes procedures for the physical and electronic surveillance and collection of foreign intelligence information between foreign powers and agents of foreign powers. FISA c...

    A federal law that establishes procedures for the physical and electronic surveillance and collection of foreign intelligence information between foreign powers and agents of foreign powers. FISA created the Foreign Intelligence Surveillance Court (FISC).
    National SecurityLegal
    Related:

    Force Protection

    Military & Defense Intelligence

    Preventive measures taken to mitigate hostile actions against military personnel, resources, facilities, and critical information. Force protection encompasses security operations, personal protect...

    Preventive measures taken to mitigate hostile actions against military personnel, resources, facilities, and critical information. Force protection encompasses security operations, personal protective measures, threat assessments, vulnerability reduction, and emergency management.
    Military
    Related:

    Force Protection Condition (FPCON)

    Military & Defense Intelligence

    Also known as: FPCON

    A system of progressive security measures implemented by the Department of Defense when a terrorist threat exists. The five FPCON levels are Normal, Alpha (general threat), Bravo (increased and pre...

    A system of progressive security measures implemented by the Department of Defense when a terrorist threat exists. The five FPCON levels are Normal, Alpha (general threat), Bravo (increased and predictable threat), Charlie (incident occurred or likely), and Delta (imminent or ongoing attack).
    MilitaryHomeland Security
    Related:

    Foreign Intelligence Service (FIS)

    Counterintelligence & Espionage

    Also known as: FIS

    An organ of a foreign government responsible for collecting intelligence outside its own borders, conducting espionage, and carrying out covert operations.

    National SecurityCounterintelligence
    Related:

    Forensic Accounting

    Financial Crimes & Fraud

    The specialized practice of applying accounting, auditing, and investigative skills to examine financial records for use in legal proceedings. Forensic accountants trace funds, quantify losses, det...

    The specialized practice of applying accounting, auditing, and investigative skills to examine financial records for use in legal proceedings. Forensic accountants trace funds, quantify losses, detect fraud schemes, reconstruct incomplete records, and present financial evidence.
    Financial CrimesLaw Enforcement
    Related:

    Forensic Image

    Cybersecurity & Digital Forensics

    Also known as: Bit-Stream Copy, Disk Image, Forensic Copy

    A bit-for-bit exact copy of a digital storage device that captures every sector including deleted files, file fragments, slack space, and unallocated space. Forensic images are created using valida...

    A bit-for-bit exact copy of a digital storage device that captures every sector including deleted files, file fragments, slack space, and unallocated space. Forensic images are created using validated tools and verified through hash value comparison to ensure the copy is identical to the original evidence.
    Digital ForensicsLaw Enforcement
    Related:

    Forensic Timeline Analysis

    Evidence & Forensics

    Also known as: Super Timeline, Timeline Reconstruction

    The reconstruction of a chronological sequence of events using data from multiple digital sources including file system timestamps, log entries, browser history, email headers, and metadata. Timeli...

    The reconstruction of a chronological sequence of events using data from multiple digital sources including file system timestamps, log entries, browser history, email headers, and metadata. Timeline analysis correlates events across different systems and time zones.
    Digital ForensicsLaw Enforcement
    Related:

    Fourth Amendment

    Legal & Compliance

    The amendment to the U.S. Constitution that protects individuals against unreasonable searches and seizures by the government. It requires that warrants be issued only upon probable cause, supporte...

    The amendment to the U.S. Constitution that protects individuals against unreasonable searches and seizures by the government. It requires that warrants be issued only upon probable cause, supported by oath or affirmation, and particularly describe the place to be searched and the persons or things to be seized.
    Law EnforcementLegal
    Related:

    Fraud Examination

    Corporate & Private Investigations

    The process of resolving allegations of fraud by obtaining evidence, taking statements, writing reports, and assisting in the detection, investigation, and prevention of fraud. Fraud examiners comb...

    The process of resolving allegations of fraud by obtaining evidence, taking statements, writing reports, and assisting in the detection, investigation, and prevention of fraud. Fraud examiners combine accounting, legal, and investigative skills.
    Corporate InvestigationsFinancial Crimes
    Related:

    Fruit of the Poisonous Tree

    Legal & Compliance

    A legal doctrine that extends the exclusionary rule to make inadmissible any evidence derived from an initial illegal search, seizure, or interrogation. If the original evidence was obtained uncons...

    A legal doctrine that extends the exclusionary rule to make inadmissible any evidence derived from an initial illegal search, seizure, or interrogation. If the original evidence was obtained unconstitutionally, then any subsequently discovered evidence is likewise tainted.
    Law EnforcementLegal
    Related:

    Fusion Center

    Intelligence Analysis

    A collaborative effort of two or more agencies that provide resources, expertise, and information to a central location to maximize the ability to detect, prevent, investigate, and respond to crimi...

    A collaborative effort of two or more agencies that provide resources, expertise, and information to a central location to maximize the ability to detect, prevent, investigate, and respond to criminal and terrorist activity. Fusion centers serve as focal points for the receipt, analysis, and sharing of threat-related information.
    Law EnforcementHomeland Security
    Related:

    Geofence Warrant

    Surveillance & Countersurveillance

    Also known as: Reverse Location Warrant

    A court order that compels technology companies to provide information about all devices that were present within a defined geographic area during a specified time period. These warrants have faced...

    A court order that compels technology companies to provide information about all devices that were present within a defined geographic area during a specified time period. These warrants have faced significant legal challenges regarding scope and privacy.
    Law EnforcementLegal
    Related:

    GEOINT (Geospatial Intelligence)

    Intelligence Collection

    Also known as: Geospatial Intelligence

    Intelligence derived from the exploitation and analysis of imagery and geospatial data to describe, assess, and visually depict physical features and geographically referenced activities on the ear...

    Intelligence derived from the exploitation and analysis of imagery and geospatial data to describe, assess, and visually depict physical features and geographically referenced activities on the earth. Encompasses imagery intelligence (IMINT), imagery-derived MASINT, and geospatial data and information.
    MilitaryNational Security
    Related:

    Geolocation

    OSINT & Digital Research

    The process of determining the physical geographic location of a person, device, or object using digital evidence. Methods include analyzing EXIF metadata from photographs, correlating IP addresses...

    The process of determining the physical geographic location of a person, device, or object using digital evidence. Methods include analyzing EXIF metadata from photographs, correlating IP addresses to geographic regions, examining social media check-ins, comparing visual landmarks in imagery, and triangulating wireless signals.
    OSINTLaw EnforcementMilitary
    Related:

    Geospatial Analysis

    Analytical Methodologies

    The examination and interpretation of geographic data patterns to understand spatial relationships, identify trends, and support decision-making. In investigations, geospatial analysis maps crime p...

    The examination and interpretation of geographic data patterns to understand spatial relationships, identify trends, and support decision-making. In investigations, geospatial analysis maps crime patterns, traces suspect movements, correlates events to locations, and supports predictive models using GIS tools.
    Intelligence AnalysisLaw EnforcementMilitary
    Related:

    Grand Jury

    Law Enforcement & Investigations

    A body of citizens convened to evaluate whether sufficient evidence exists to bring criminal charges (indictment) against a suspect. Grand jury proceedings are conducted in secret, and the standard...

    A body of citizens convened to evaluate whether sufficient evidence exists to bring criminal charges (indictment) against a suspect. Grand jury proceedings are conducted in secret, and the standard for indictment is probable cause. Grand juries have broad subpoena powers.
    Law Enforcement
    Related:

    Gray Literature

    Intelligence Collection

    Published or unpublished materials that are not controlled by commercial publishers and are often difficult to locate through conventional bibliographic means. Includes technical reports, working p...

    Published or unpublished materials that are not controlled by commercial publishers and are often difficult to locate through conventional bibliographic means. Includes technical reports, working papers, government documents, conference proceedings, theses, and preprints. Valuable in intelligence analysis for providing niche or specialized information.
    Intelligence AnalysisOSINTAcademic Research
    Related:

    Groupthink

    Intelligence Analysis

    A psychological phenomenon in which the desire for harmony in a group leads to irrational or dysfunctional decision-making, suppressing dissent and critical evaluation of alternatives.

    Intelligence AnalysisPsychology
    Related:

    Hash Value

    Cybersecurity & Digital Forensics

    A fixed-length numerical value produced by a mathematical algorithm from input data. In digital forensics, hash values (typically MD5, SHA-1, or SHA-256) serve as digital fingerprints to verify dat...

    A fixed-length numerical value produced by a mathematical algorithm from input data. In digital forensics, hash values (typically MD5, SHA-1, or SHA-256) serve as digital fingerprints to verify data integrity and confirm that evidence has not been altered.
    Digital ForensicsCybersecurity
    Related:

    Hawala

    Homeland Security & Counterterrorism

    An informal value transfer system based on trust and personal networks that operates outside of traditional banking channels. In hawala, a customer gives money to a broker (hawaladar) in one locati...

    An informal value transfer system based on trust and personal networks that operates outside of traditional banking channels. In hawala, a customer gives money to a broker (hawaladar) in one location, and a corresponding broker in the destination pays the equivalent to the intended recipient. While legal in many jurisdictions, hawala has been exploited for money laundering and terrorist financing.
    Financial CrimesCounterterrorism
    Related:

    Homegrown Violent Extremist (HVE)

    Homeland Security & Counterterrorism

    A person who is inspired by, but not directed by, a foreign terrorist organization to plan or commit acts of violence within their home country.

    CounterterrorismLaw Enforcement
    Related:

    Honey Trap

    Counterintelligence & Espionage

    An intelligence recruitment or compromise operation that uses romantic or sexual enticement to gain access to a target, extract information, or create leverage for blackmail.

    National SecurityCounterintelligence
    Related:

    HUMINT (Human Intelligence)

    Intelligence Collection

    Also known as: Human Intelligence, Human Source Intelligence

    Intelligence gathered through interpersonal contact and human sources. Includes information obtained from diplomats, recruited agents, travelers, prisoners of war, refugees, and any person with acc...

    Intelligence gathered through interpersonal contact and human sources. Includes information obtained from diplomats, recruited agents, travelers, prisoners of war, refugees, and any person with access to valuable information. HUMINT is considered the oldest form of intelligence collection and remains essential for understanding intentions, plans, and capabilities that technical collection methods cannot reveal.
    MilitaryNational SecurityLaw Enforcement
    Related:

    Identity Theft

    Financial Crimes & Fraud

    The fraudulent acquisition and use of another person's personal identifying information to commit crimes, make purchases, obtain credit, or assume the victim's identity.

    Law EnforcementFinancial CrimesCybersecurity
    Related:

    IMINT (Imagery Intelligence)

    Intelligence Collection

    Also known as: Imagery Intelligence

    Intelligence derived from the exploitation of visual representations produced by optical, electro-optical, radar, infrared, and multispectral sensors. Imagery can be collected from satellite, airbo...

    Intelligence derived from the exploitation of visual representations produced by optical, electro-optical, radar, infrared, and multispectral sensors. Imagery can be collected from satellite, airborne, or ground-based platforms and is analyzed to detect changes, identify objects, and characterize facilities and terrain.
    MilitaryNational Security
    Related:

    Incident Response

    Cybersecurity & Digital Forensics

    Also known as: IR

    The organized approach to addressing and managing the aftermath of a security breach or cyberattack. Incident response aims to limit damage, reduce recovery time and costs, and learn from the incid...

    The organized approach to addressing and managing the aftermath of a security breach or cyberattack. Incident response aims to limit damage, reduce recovery time and costs, and learn from the incident. The standard phases are preparation, identification, containment, eradication, recovery, and lessons learned.
    Cybersecurity
    Related:

    Indications and Warning (I&W)

    Intelligence Analysis

    The intelligence activities intended to detect and report time-sensitive intelligence information on foreign developments that could pose a threat. I&W includes identifying and reporting indicators...

    The intelligence activities intended to detect and report time-sensitive intelligence information on foreign developments that could pose a threat. I&W includes identifying and reporting indicators of hostile intent or capability, monitoring situations that could escalate.
    MilitaryNational Security
    Related:

    Indicator

    Intelligence Analysis

    An observable action, condition, or fact that suggests an adversary has adopted or is preparing a specific course of action. Indicators are used in intelligence analysis to provide warning of impen...

    An observable action, condition, or fact that suggests an adversary has adopted or is preparing a specific course of action. Indicators are used in intelligence analysis to provide warning of impending hostile activities, changes in capability, or shifts in intent.
    All disciplines
    Related:

    Indicator of Attack (IOA)

    Cybersecurity & Digital Forensics

    Also known as: IOA

    Proactive indicators that focus on identifying the intent and techniques of an adversary rather than the artifacts left behind. IOAs describe active attack behaviors such as code execution patterns...

    Proactive indicators that focus on identifying the intent and techniques of an adversary rather than the artifacts left behind. IOAs describe active attack behaviors such as code execution patterns, lateral movement attempts, and privilege escalation activities. Unlike IOCs, IOAs can detect novel attacks for which no specific artifact signatures exist.
    CybersecurityCyber Threat Intelligence
    Related:

    Indicator of Compromise (IOC)

    Cybersecurity & Digital Forensics

    Also known as: IOC

    An artifact observed on a network or in a system that indicates, with high confidence, that a security breach or malicious activity has occurred. IOCs include malicious IP addresses, domain names, ...

    An artifact observed on a network or in a system that indicates, with high confidence, that a security breach or malicious activity has occurred. IOCs include malicious IP addresses, domain names, URLs, file hashes, email addresses, registry key modifications, and behavioral patterns.
    CybersecurityCyber Threat Intelligence
    Related:

    Informant

    Law Enforcement & Investigations

    Also known as: Confidential Informant, CI, Source, Cooperating Witness

    A person who provides information about criminal activity to law enforcement, typically in exchange for reduced charges, monetary compensation, or other consideration. Their identities are protecte...

    A person who provides information about criminal activity to law enforcement, typically in exchange for reduced charges, monetary compensation, or other consideration. Their identities are protected, and their information must be corroborated.
    Law Enforcement
    Related:

    Insider Threat

    Counterintelligence & Espionage

    The risk posed by individuals within an organization who use their authorized access to intentionally or unintentionally harm the organization through espionage, sabotage, unauthorized disclosure, ...

    The risk posed by individuals within an organization who use their authorized access to intentionally or unintentionally harm the organization through espionage, sabotage, unauthorized disclosure, fraud, or other malicious activities.
    CounterintelligenceCybersecurityCorporate Security
    Related:

    Intelligence Community (IC)

    Intelligence Analysis

    The collective of government agencies and organizations responsible for intelligence activities. In the U.S., the IC comprises 18 member organizations.

    National Security
    Related:

    Intelligence Cycle

    Intelligence Analysis

    The process by which information is acquired, converted into finished intelligence, and made available to policymakers and commanders. The cycle consists of five phases: planning and direction, col...

    The process by which information is acquired, converted into finished intelligence, and made available to policymakers and commanders. The cycle consists of five phases: planning and direction, collection, processing and exploitation, analysis and production, and dissemination and integration. Though depicted as a linear cycle, in practice these phases often overlap and recur.
    All disciplines
    Related:

    Intelligence Estimate

    Intelligence Analysis

    A formal assessment of a situation, condition, or capability of a foreign entity, produced by an intelligence organization. Intelligence estimates synthesize available information to provide judgme...

    A formal assessment of a situation, condition, or capability of a foreign entity, produced by an intelligence organization. Intelligence estimates synthesize available information to provide judgment about the current state and probable future developments of a given issue.
    MilitaryNational Security
    Related:

    Intelligence Fusion

    Intelligence Analysis

    Also known as: Fusion

    The process of combining and integrating multiple intelligence sources and disciplines into a cohesive, comprehensive picture. Fusion centers bring together information from federal, state, local, ...

    The process of combining and integrating multiple intelligence sources and disciplines into a cohesive, comprehensive picture. Fusion centers bring together information from federal, state, local, tribal, and private sector partners to produce unified intelligence products and enhance situational awareness.
    All disciplines
    Related:

    Intelligence Gain/Loss (IGL)

    Intelligence Analysis

    Also known as: IGL

    An assessment of the potential intelligence value gained from continuing an operation or surveillance against the risk of losing access, compromising sources, or alerting the target. IGL calculatio...

    An assessment of the potential intelligence value gained from continuing an operation or surveillance against the risk of losing access, compromising sources, or alerting the target. IGL calculations inform decisions about when to act on intelligence versus continuing collection for greater value.
    Law EnforcementNational SecurityCounterintelligence
    Related:

    Intelligence Preparation of the Battlefield (IPB)

    Intelligence Analysis

    Also known as: IPB, Intelligence Preparation of the Environment (IPOE)

    A systematic approach to analyzing the threat and environment in a specific geographic area. IPB is designed to support military decision-making by defining the operational environment, describing ...

    A systematic approach to analyzing the threat and environment in a specific geographic area. IPB is designed to support military decision-making by defining the operational environment, describing environmental effects, evaluating the threat, and determining threat courses of action.
    Military
    Related:

    Intelligence Requirement

    Intelligence Analysis

    A statement of need for specific intelligence information to support decision-making, often categorized as Priority Intelligence Requirements (PIR).

    All disciplines
    Related:

    Internal Investigation

    Corporate & Private Investigations

    A formal inquiry conducted within an organization to examine allegations of policy violations, misconduct, fraud, harassment, data breaches, or other concerns. Internal investigations typically inv...

    A formal inquiry conducted within an organization to examine allegations of policy violations, misconduct, fraud, harassment, data breaches, or other concerns. Internal investigations typically involve document review, witness interviews, digital forensics, and a written report with findings.
    CorporateLegalHuman Resources
    Related:

    Key Assumptions Check

    Intelligence Analysis

    A structured analytic technique that identifies and examines the fundamental assumptions underlying an analysis. The purpose is to make hidden assumptions explicit, evaluate their validity, and con...

    A structured analytic technique that identifies and examines the fundamental assumptions underlying an analysis. The purpose is to make hidden assumptions explicit, evaluate their validity, and consider the impact on analytical conclusions if one or more key assumptions prove incorrect.
    Intelligence Analysis
    Related:

    Know Your Customer (KYC)

    Financial Crimes & Fraud

    Also known as: KYC

    The regulatory requirement and process by which financial institutions verify the identity of their customers, understand the nature of their business relationships, and assess the risk they pose f...

    The regulatory requirement and process by which financial institutions verify the identity of their customers, understand the nature of their business relationships, and assess the risk they pose for money laundering and terrorist financing.
    Financial CrimesCompliance
    Related:

    Lateral Movement

    Cybersecurity & Digital Forensics

    Techniques used by an attacker after initial access to move through a network, accessing additional systems and escalating privileges to reach their ultimate objective.

    Cybersecurity
    Related:

    Legend

    Counterintelligence & Espionage

    A fabricated personal history and documentation created to support the cover identity of an intelligence officer or covert operative.

    National SecurityCounterintelligence
    Related:

    Locard's Exchange Principle

    Evidence & Forensics

    A foundational forensic science principle established by Dr. Edmond Locard stating that every contact between two entities results in an exchange of material. When a person interacts with a scene, ...

    A foundational forensic science principle established by Dr. Edmond Locard stating that every contact between two entities results in an exchange of material. When a person interacts with a scene, they both leave traces and take traces with them. This principle underpins all forensic investigation, including digital forensics.
    Forensic ScienceLaw Enforcement
    Related:

    Log Analysis

    Cybersecurity & Digital Forensics

    The examination of recorded events from systems, applications, networks, and security devices to detect anomalies, investigate incidents, and reconstruct timelines. Logs from firewalls, servers, au...

    The examination of recorded events from systems, applications, networks, and security devices to detect anomalies, investigate incidents, and reconstruct timelines. Logs from firewalls, servers, authentication systems, databases, and applications provide the evidentiary foundation for most cybersecurity investigations.
    CybersecurityDigital Forensics
    Related:

    Lone Wolf

    Homeland Security & Counterterrorism

    Also known as: Lone Actor, Solo Actor

    An individual who plans and carries out an act of violence independently, without direct orders, direction, or material support from a formal terrorist organization or group. Lone wolves may be ins...

    An individual who plans and carries out an act of violence independently, without direct orders, direction, or material support from a formal terrorist organization or group. Lone wolves may be inspired by extremist ideologies through online propaganda.
    CounterterrorismLaw Enforcement
    Related:

    Malware

    Cybersecurity & Digital Forensics

    Software intentionally designed to cause damage, gain unauthorized access, disrupt operations, or otherwise compromise computer systems. Categories include viruses, worms, trojans, ransomware, spyw...

    Software intentionally designed to cause damage, gain unauthorized access, disrupt operations, or otherwise compromise computer systems. Categories include viruses, worms, trojans, ransomware, spyware, adware, rootkits, keyloggers, and fileless malware.
    Cybersecurity
    Related:

    MASINT (Measurement and Signature Intelligence)

    Intelligence Collection

    Also known as: Measurement and Signature Intelligence

    Intelligence obtained by quantitative and qualitative analysis of physical attributes of targets and events to characterize, locate, and identify them. MASINT employs a broad range of disciplines i...

    Intelligence obtained by quantitative and qualitative analysis of physical attributes of targets and events to characterize, locate, and identify them. MASINT employs a broad range of disciplines including radar, nuclear, geophysical, optical, radio frequency, materials, and biological intelligence to produce specialized technical intelligence.
    MilitaryNational Security
    Related:

    MEDINT (Medical Intelligence)

    Intelligence Collection

    Also known as: Medical Intelligence

    Intelligence derived from the collection, evaluation, analysis, and interpretation of foreign medical, bio-scientific, and environmental information that is of interest to strategic planning for me...

    Intelligence derived from the collection, evaluation, analysis, and interpretation of foreign medical, bio-scientific, and environmental information that is of interest to strategic planning for medical and military purposes.
    MilitaryPublic Health
    Related:

    Metadata

    OSINT & Digital Research

    Data that provides information about other data. In investigative contexts, metadata from files, communications, and digital activities can reveal authorship, creation and modification dates, devic...

    Data that provides information about other data. In investigative contexts, metadata from files, communications, and digital activities can reveal authorship, creation and modification dates, device information, location data, and other attributes without examining the actual content. Metadata analysis is often as valuable as content analysis in investigations.
    OSINTDigital ForensicsCybersecurity
    Related:

    Miranda Rights

    Legal & Compliance

    The constitutional rights that law enforcement must communicate to suspects in custodial interrogation, as established by Miranda v. Arizona. These include the right to remain silent, the warning t...

    The constitutional rights that law enforcement must communicate to suspects in custodial interrogation, as established by Miranda v. Arizona. These include the right to remain silent, the warning that statements may be used against them, the right to an attorney, and the right to appointed counsel.
    Law EnforcementLegal
    Related:

    Mirror Imaging

    Intelligence Analysis

    A cognitive bias in which an analyst assumes that the subject of analysis will act or think in the same way the analyst would in similar circumstances. This bias can lead to significant errors when...

    A cognitive bias in which an analyst assumes that the subject of analysis will act or think in the same way the analyst would in similar circumstances. This bias can lead to significant errors when analyzing adversaries from different cultures, ideologies, or strategic frameworks.
    Intelligence Analysis
    Related:

    MITRE ATT&CK

    Cyber Threat Intelligence

    A comprehensive knowledge base and framework of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. ATT&CK catalogs the specific methods threat actors use across ...

    A comprehensive knowledge base and framework of adversary tactics, techniques, and procedures (TTPs) based on real-world observations. ATT&CK catalogs the specific methods threat actors use across the attack lifecycle.
    CybersecurityCyber Threat Intelligence
    Related:

    Modus Operandi (MO)

    Law Enforcement & Investigations

    The particular method or pattern of behavior a criminal uses to commit crimes, reflecting their learned habits and practical choices. Distinguished from signature, which reflects psychological needs.

    Law Enforcement
    Related:

    Mole

    Counterintelligence & Espionage

    A long-term penetration agent who has been recruited or placed within an intelligence service, government agency, or other target organization to secretly provide information to a foreign intellige...

    A long-term penetration agent who has been recruited or placed within an intelligence service, government agency, or other target organization to secretly provide information to a foreign intelligence service. Moles are among the most damaging threats because of their trusted access.
    National SecurityCounterintelligence
    Related:

    Money Laundering

    Financial Crimes & Fraud

    The process of making illegally obtained money appear legitimate by disguising its true origin. Money laundering typically involves three stages: placement (introducing illicit funds into the finan...

    The process of making illegally obtained money appear legitimate by disguising its true origin. Money laundering typically involves three stages: placement (introducing illicit funds into the financial system), layering (moving funds through complex transactions to obscure the trail), and integration (reintroducing the funds into the legitimate economy).
    Law EnforcementFinancial Crimes
    Related:

    Multi-Factor Authentication (MFA)

    Cybersecurity & Digital Forensics

    A security mechanism that requires two or more independent verification factors (something you know, have, or are) to authenticate a user's identity.

    Cybersecurity
    Related:

    National Crime Information Center (NCIC)

    Law Enforcement & Investigations

    The FBI-managed centralized database of criminal justice information including wanted persons, stolen property, missing persons, and criminal history records accessible to law enforcement nationwide.

    Law Enforcement
    Related:

    National Intelligence Estimate (NIE)

    Intelligence Analysis

    Also known as: NIE

    The most authoritative written judgment of the U.S. intelligence community concerning national security issues. NIEs contain the coordinated judgments of the intelligence community regarding the pr...

    The most authoritative written judgment of the U.S. intelligence community concerning national security issues. NIEs contain the coordinated judgments of the intelligence community regarding the probable course of future events. They are issued by the Director of National Intelligence.
    National Security
    Related:

    Need-to-Know

    Counterintelligence & Espionage

    The determination that a prospective recipient of classified information requires access to perform their official duties, applied in addition to and beyond having the requisite security clearance.

    National SecurityCounterintelligence
    Related:

    No-Fly List

    Homeland Security & Counterterrorism

    A U.S. government list of individuals who are prohibited from boarding commercial aircraft due to their assessed threat to aviation or national security.

    Homeland Security
    Related:

    OFAC (Office of Foreign Assets Control)

    Homeland Security & Counterterrorism

    Also known as: OFAC, Office of Foreign Assets Control

    An agency of the U.S. Department of the Treasury responsible for administering and enforcing economic and trade sanctions programs against targeted countries, regimes, terrorists, and international...

    An agency of the U.S. Department of the Treasury responsible for administering and enforcing economic and trade sanctions programs against targeted countries, regimes, terrorists, and international narcotics traffickers. OFAC maintains the Specially Designated Nationals (SDN) list.
    ComplianceFinancial CrimesNational Security
    Related:

    Operational Security (OPSEC)

    Counterintelligence & Espionage

    Also known as: OPSEC

    A systematic process for identifying, controlling, and protecting critical information that could be used by an adversary to compromise operations, intelligence activities, or personnel. The five-s...

    A systematic process for identifying, controlling, and protecting critical information that could be used by an adversary to compromise operations, intelligence activities, or personnel. The five-step OPSEC process includes identifying critical information, analyzing threats, analyzing vulnerabilities, assessing risks, and applying appropriate countermeasures.
    All disciplines
    Related:

    Operational Security (OPSEC) for OSINT

    OSINT & Digital Research

    The measures and tradecraft an OSINT investigator employs to conduct research without alerting the target or compromising the investigation. Includes using VPNs, dedicated research machines, manage...

    The measures and tradecraft an OSINT investigator employs to conduct research without alerting the target or compromising the investigation. Includes using VPNs, dedicated research machines, managed personas, avoiding direct interactions that generate notifications, and maintaining strict separation between personal and operational activities.
    OSINTLaw Enforcement
    Related:

    Order of Battle (OOB)

    Military & Defense Intelligence

    Also known as: OOB, OB

    The identification, strength, command structure, equipment, disposition, and combat effectiveness of military forces. Maintaining an accurate and current order of battle for adversary forces is a f...

    The identification, strength, command structure, equipment, disposition, and combat effectiveness of military forces. Maintaining an accurate and current order of battle for adversary forces is a fundamental intelligence task.
    Military
    Related:

    OSINT (Open Source Intelligence)

    Intelligence Collection

    Also known as: Open Source Intelligence

    Intelligence produced from publicly available information that is collected, exploited, and disseminated in a timely manner to an appropriate audience. Sources include news media, social media, pub...

    Intelligence produced from publicly available information that is collected, exploited, and disseminated in a timely manner to an appropriate audience. Sources include news media, social media, public government data, academic publications, commercial databases, internet content, and gray literature. OSINT has become increasingly critical as the volume of publicly accessible digital information has expanded.
    All disciplines
    Related:

    Passive DNS

    OSINT & Digital Research

    A system that records DNS resolution data observed over time, creating a historical database of which domain names resolved to which IP addresses and when. Unlike active DNS queries, passive DNS do...

    A system that records DNS resolution data observed over time, creating a historical database of which domain names resolved to which IP addresses and when. Unlike active DNS queries, passive DNS does not interact directly with name servers. Investigators use passive DNS to track infrastructure changes, identify related domains, and uncover threat actor networks.
    OSINTCybersecurity
    Related:

    Pattern of Life Analysis

    Intelligence Analysis

    Also known as: POL, Pattern of Life

    The systematic study of an individual's or group's routine activities, behaviors, movements, and associations over time to establish baseline norms. Deviations from established patterns may indicat...

    The systematic study of an individual's or group's routine activities, behaviors, movements, and associations over time to establish baseline norms. Deviations from established patterns may indicate changes in intent, operational security measures, or imminent activity. Widely used in both physical and cyber surveillance.
    MilitaryLaw EnforcementCybersecurity
    Related:

    PEACE Model

    Interview & Interrogation

    A non-coercive investigative interviewing framework widely used in the UK and internationally, standing for Planning and preparation, Engage and explain, Account (clarify and challenge), Closure, a...

    A non-coercive investigative interviewing framework widely used in the UK and internationally, standing for Planning and preparation, Engage and explain, Account (clarify and challenge), Closure, and Evaluate. PEACE emphasizes information gathering over confession-seeking.
    Law Enforcement
    Related:

    Pen Register / Trap and Trace

    Legal & Compliance

    Surveillance tools and their corresponding court orders that capture communications metadata. A pen register records outgoing dialing information (numbers called), while a trap and trace device cap...

    Surveillance tools and their corresponding court orders that capture communications metadata. A pen register records outgoing dialing information (numbers called), while a trap and trace device captures incoming information (numbers calling). These collect metadata only, not content.
    Law EnforcementLegal
    Related:

    Pen Register Order

    Law Enforcement & Investigations

    A court order authorizing the collection of outgoing communications metadata (numbers dialed, email addresses contacted) from a specific account or device.

    Law Enforcement
    Related:

    Penetration Testing

    Cybersecurity & Digital Forensics

    Also known as: Pen Test, Ethical Hacking

    An authorized simulated cyberattack performed against a computer system, network, or application to evaluate its security posture. Penetration testers use the same tools and techniques as malicious...

    An authorized simulated cyberattack performed against a computer system, network, or application to evaluate its security posture. Penetration testers use the same tools and techniques as malicious hackers to identify exploitable vulnerabilities before real attackers do.
    Cybersecurity
    Related:

    Persona Management

    OSINT & Digital Research

    The creation, maintenance, and operational employment of fictitious online identities for intelligence collection or investigation purposes.

    OSINTLaw Enforcement
    Related:

    Phishing

    Cybersecurity & Digital Forensics

    A social engineering attack that uses deceptive electronic communications to trick recipients into revealing sensitive information, clicking malicious links, or downloading malware. Variants includ...

    A social engineering attack that uses deceptive electronic communications to trick recipients into revealing sensitive information, clicking malicious links, or downloading malware. Variants include spear phishing (targeted at specific individuals), whaling (targeting executives), vishing (voice phishing), and smishing (SMS phishing).
    CybersecurityLaw Enforcement
    Related:

    Physical Surveillance

    Surveillance & Countersurveillance

    The systematic observation of persons, places, or activities by law enforcement or intelligence personnel using visual and electronic means. Physical surveillance is conducted on foot or by vehicle...

    The systematic observation of persons, places, or activities by law enforcement or intelligence personnel using visual and electronic means. Physical surveillance is conducted on foot or by vehicle and may be stationary (fixed point) or mobile.
    Law EnforcementNational Security
    Related:

    Pivot

    OSINT & Digital Research

    The act of using one discovered data point to uncover additional connected information during an investigation. An investigator may pivot from an email address to find associated usernames, from a ...

    The act of using one discovered data point to uncover additional connected information during an investigation. An investigator may pivot from an email address to find associated usernames, from a phone number to locate social media profiles, or from a domain to identify linked infrastructure. Effective pivoting is the core skill of OSINT analysis.
    OSINTCybersecurityLaw Enforcement
    Related:

    Plea Agreement

    Law Enforcement & Investigations

    A negotiated agreement between the prosecution and defense in which the defendant agrees to plead guilty to specified charges in exchange for concessions such as reduced charges or sentencing recom...

    A negotiated agreement between the prosecution and defense in which the defendant agrees to plead guilty to specified charges in exchange for concessions such as reduced charges or sentencing recommendations.
    Law EnforcementLegal
    Related:

    Politically Exposed Person (PEP)

    Financial Crimes & Fraud

    An individual who holds or has held a prominent public position, along with their family members and close associates, who present elevated risk for money laundering and corruption.

    Financial CrimesCompliance
    Related:

    Ponzi Scheme

    Financial Crimes & Fraud

    A fraudulent investment operation in which returns to existing investors are paid from funds contributed by new investors rather than from legitimate business profits. Named after Charles Ponzi, th...

    A fraudulent investment operation in which returns to existing investors are paid from funds contributed by new investors rather than from legitimate business profits. Named after Charles Ponzi, these schemes inevitably collapse when new investment slows.
    Financial CrimesLaw Enforcement
    Related:

    Predication

    Law Enforcement & Investigations

    The factual basis that reasonably indicates criminal activity has occurred, is occurring, or will occur, and that justifies the initiation of an investigation. Predication standards vary by agency ...

    The factual basis that reasonably indicates criminal activity has occurred, is occurring, or will occur, and that justifies the initiation of an investigation. Predication standards vary by agency and investigation type but require more than mere suspicion.
    Law Enforcement
    Related:

    Priority Intelligence Requirement (PIR)

    Intelligence Analysis

    The intelligence needs identified by a commander or decision-maker as being critical to accomplishing the mission, prioritized above other requirements.

    MilitaryNational Security
    Related:

    Privilege Escalation

    Cybersecurity & Digital Forensics

    The exploitation of vulnerabilities or misconfigurations to gain elevated access rights beyond what was initially authorized, moving from standard user to administrator level.

    Cybersecurity
    Related:

    Probable Cause

    Law Enforcement & Investigations

    A legal standard requiring sufficient facts and circumstances that would lead a reasonable person to believe that a crime has been, is being, or will be committed, and that the person, place, or th...

    A legal standard requiring sufficient facts and circumstances that would lead a reasonable person to believe that a crime has been, is being, or will be committed, and that the person, place, or thing to be searched or seized is connected to that criminal activity. Probable cause is required for arrest warrants, search warrants, and indictments.
    Law Enforcement
    Related:

    Proffer

    Law Enforcement & Investigations

    Also known as: Queen for a Day, Proffer Agreement

    A formal meeting between a suspect or defendant and prosecutors, typically under a proffer agreement (queen-for-a-day agreement), in which the individual provides information about criminal activit...

    A formal meeting between a suspect or defendant and prosecutors, typically under a proffer agreement (queen-for-a-day agreement), in which the individual provides information about criminal activity in exchange for limited use immunity.
    Law EnforcementLegal
    Related:

    Publicly Available Information (PAI)

    Intelligence Collection

    Also known as: PAI

    Information that has been published or broadcast for general public consumption, is available on request to the public, is accessible online or otherwise to the public, is available to the public b...

    Information that has been published or broadcast for general public consumption, is available on request to the public, is accessible online or otherwise to the public, is available to the public by subscription or purchase, could be seen or heard by any casual observer, or is made available at a meeting open to the public.
    All disciplines
    Related:

    Radicalization

    Homeland Security & Counterterrorism

    The process by which an individual adopts increasingly extreme political, social, or religious ideologies that may lead to the acceptance or advocacy of violence as a legitimate means of achieving ...

    The process by which an individual adopts increasingly extreme political, social, or religious ideologies that may lead to the acceptance or advocacy of violence as a legitimate means of achieving goals. Radicalization pathways vary significantly and may be influenced by personal grievances, social networks, online propaganda, and perceived injustice.
    CounterterrorismLaw EnforcementPsychology
    Related:

    Ransomware

    Cybersecurity & Digital Forensics

    A type of malware that encrypts a victim's files or systems and demands payment (typically in cryptocurrency) for the decryption key. Modern ransomware operations often employ double extortion, whe...

    A type of malware that encrypts a victim's files or systems and demands payment (typically in cryptocurrency) for the decryption key. Modern ransomware operations often employ double extortion, where attackers also exfiltrate data and threaten to publish it if the ransom is not paid.
    CybersecurityLaw Enforcement
    Related:

    Rapport Building

    Interview & Interrogation

    The process of establishing a positive interpersonal connection with an interview subject to facilitate communication, cooperation, and information sharing. Research demonstrates that rapport-based...

    The process of establishing a positive interpersonal connection with an interview subject to facilitate communication, cooperation, and information sharing. Research demonstrates that rapport-based approaches yield more complete and accurate information than confrontational methods.
    Law EnforcementIntelligencePsychology
    Related:

    Raw Intelligence

    Intelligence Analysis

    Collected information that has not yet been processed, analyzed, or converted into finished intelligence. Raw intelligence may be fragmentary, unverified, and potentially unreliable until it underg...

    Collected information that has not yet been processed, analyzed, or converted into finished intelligence. Raw intelligence may be fragmentary, unverified, and potentially unreliable until it undergoes processing and all-source analysis.
    All disciplines
    Related:

    Reasonable Suspicion

    Law Enforcement & Investigations

    A legal standard lower than probable cause, based on specific and articulable facts that would lead a reasonable person to suspect criminal activity. Reasonable suspicion justifies brief investigat...

    A legal standard lower than probable cause, based on specific and articulable facts that would lead a reasonable person to suspect criminal activity. Reasonable suspicion justifies brief investigative stops (Terry stops), but not full searches or arrests.
    Law Enforcement
    Related:

    Red Team Analysis

    Intelligence Analysis

    Also known as: Red Teaming, Devil's Advocacy

    A structured analytic approach where a group adopts the perspective and mindset of an adversary or competitor to challenge established assumptions, expose vulnerabilities, and test plans and hypoth...

    A structured analytic approach where a group adopts the perspective and mindset of an adversary or competitor to challenge established assumptions, expose vulnerabilities, and test plans and hypotheses. Red teaming provides alternative perspectives that help identify blind spots in analysis.
    Intelligence AnalysisMilitaryCybersecurity
    Related:

    Reid Technique

    Interview & Interrogation

    A structured interrogation method developed in the 1960s that involves a two-phase process: a non-accusatory interview using Behavior Analysis Interview (BAI) techniques, followed by a nine-step ac...

    A structured interrogation method developed in the 1960s that involves a two-phase process: a non-accusatory interview using Behavior Analysis Interview (BAI) techniques, followed by a nine-step accusatory interrogation process designed to overcome denials and elicit confessions. The technique has faced criticism regarding false confessions.
    Law Enforcement
    Related:

    RICO (Racketeer Influenced and Corrupt Organizations Act)

    Law Enforcement & Investigations

    Also known as: RICO

    A federal law enacted in 1970 that provides for extended criminal penalties and civil causes of action for acts performed as part of an ongoing criminal organization. RICO allows prosecutors to cha...

    A federal law enacted in 1970 that provides for extended criminal penalties and civil causes of action for acts performed as part of an ongoing criminal organization. RICO allows prosecutors to charge leaders of criminal enterprises for crimes they ordered others to commit.
    Law EnforcementLegal
    Related:

    Risk Assessment

    Intelligence Analysis

    A systematic process that identifies and evaluates potential threats, vulnerabilities, and the consequences of adverse events to determine the overall level of risk. Risk is typically calculated as...

    A systematic process that identifies and evaluates potential threats, vulnerabilities, and the consequences of adverse events to determine the overall level of risk. Risk is typically calculated as the intersection of threat, vulnerability, and impact/consequence.
    All disciplines
    Related:

    Rootkit

    Cybersecurity & Digital Forensics

    Malware designed to provide continued privileged access to a system while actively hiding its presence from administrators and security tools.

    Cybersecurity
    Related:

    Rules of Engagement (ROE)

    Military & Defense Intelligence

    Also known as: ROE

    Directives issued by competent military authority that delineate the circumstances and limitations under which forces will initiate or continue combat engagement with hostile forces. ROE govern the...

    Directives issued by competent military authority that delineate the circumstances and limitations under which forces will initiate or continue combat engagement with hostile forces. ROE govern the use of force and are shaped by legal, policy, and operational considerations.
    MilitaryLegal
    Related:

    Sandbox

    Cybersecurity & Digital Forensics

    An isolated environment used to safely execute and observe the behavior of suspicious files, programs, or code without risk to production systems.

    Cybersecurity
    Related:

    Search Warrant

    Law Enforcement & Investigations

    A court order issued by a judge or magistrate authorizing law enforcement to search a specific location, person, or digital account and seize specified evidence. A search warrant must be supported ...

    A court order issued by a judge or magistrate authorizing law enforcement to search a specific location, person, or digital account and seize specified evidence. A search warrant must be supported by probable cause, describe with particularity the place to be searched and items to be seized.
    Law Enforcement
    Related:

    Selector

    OSINT & Digital Research

    A unique identifier used to search for or track an individual, entity, or piece of infrastructure across databases and platforms. Common selectors include email addresses, phone numbers, usernames,...

    A unique identifier used to search for or track an individual, entity, or piece of infrastructure across databases and platforms. Common selectors include email addresses, phone numbers, usernames, IP addresses, social media handles, cryptocurrency wallet addresses, and domain names.
    OSINTIntelligence CollectionCybersecurity
    Related:

    Sensitive Activities

    Military & Defense Intelligence

    Operations, programs, or activities that due to their sensitive nature require special access controls, enhanced security measures, and restricted knowledge. These may include clandestine operation...

    Operations, programs, or activities that due to their sensitive nature require special access controls, enhanced security measures, and restricted knowledge. These may include clandestine operations, covert actions, special access programs, and other activities where unauthorized disclosure could cause exceptionally grave damage.
    MilitaryNational Security
    Related:

    Sensitive Compartmented Information (SCI)

    Legal & Compliance

    Also known as: SCI

    Classified information concerning or derived from intelligence sources, methods, or analytical processes that requires handling within formal access control systems beyond those used for regular cl...

    Classified information concerning or derived from intelligence sources, methods, or analytical processes that requires handling within formal access control systems beyond those used for regular classified information.
    National SecurityLegal
    Related:

    Shell Company

    Financial Crimes & Fraud

    A legal entity that has no active business operations, significant assets, or employees but exists on paper to hold assets, facilitate transactions, or obscure the identity of the true owner. While...

    A legal entity that has no active business operations, significant assets, or employees but exists on paper to hold assets, facilitate transactions, or obscure the identity of the true owner. While shell companies have legitimate uses, they are frequently exploited for money laundering, tax evasion, and sanctions evasion.
    Financial CrimesLaw Enforcement
    Related:

    SIEM (Security Information and Event Management)

    Cybersecurity & Digital Forensics

    A platform that collects, correlates, and analyzes security event data from across an enterprise to detect threats and support incident response.

    Cybersecurity
    Related:

    SIGINT (Signals Intelligence)

    Intelligence Collection

    Also known as: Signals Intelligence

    Intelligence derived from the interception of electronic signals and communications. Encompasses COMINT (Communications Intelligence) from intercepted voice and data transmissions, and ELINT (Elect...

    Intelligence derived from the interception of electronic signals and communications. Encompasses COMINT (Communications Intelligence) from intercepted voice and data transmissions, and ELINT (Electronic Intelligence) from non-communications electromagnetic emissions such as radar. SIGINT provides critical insights into adversary command structures, operational plans, and technical capabilities.
    MilitaryNational SecurityCybersecurity
    Related:

    Signals Intelligence Directorate (SID)

    Military & Defense Intelligence

    The organizational component within a signals intelligence agency responsible for the collection, processing, and reporting of SIGINT. The SID manages collection priorities, technical capabilities,...

    The organizational component within a signals intelligence agency responsible for the collection, processing, and reporting of SIGINT. The SID manages collection priorities, technical capabilities, and dissemination of intercepted communications.
    MilitaryNational Security
    Related:

    Signature (Criminal)

    Law Enforcement & Investigations

    A distinctive behavior or action performed by a criminal that goes beyond what is necessary to commit the crime and reflects the offender's psychological needs or desires. Signatures remain relativ...

    A distinctive behavior or action performed by a criminal that goes beyond what is necessary to commit the crime and reflects the offender's psychological needs or desires. Signatures remain relatively consistent across crimes by the same offender.
    Law Enforcement
    Related:

    Social Engineering

    Cybersecurity & Digital Forensics

    The psychological manipulation of people to perform actions or divulge confidential information. Social engineering exploits human trust, authority, urgency, and other psychological principles rath...

    The psychological manipulation of people to perform actions or divulge confidential information. Social engineering exploits human trust, authority, urgency, and other psychological principles rather than technical vulnerabilities. Techniques include pretexting, baiting, tailgating, quid pro quo, and phishing.
    CybersecurityLaw EnforcementCounterintelligence
    Related:

    Social Network Analysis (SNA)

    Analytical Methodologies

    Also known as: SNA, Network Analysis

    A quantitative and qualitative methodology for mapping and measuring relationships and information flows between people, groups, organizations, or other entities. SNA identifies network structures,...

    A quantitative and qualitative methodology for mapping and measuring relationships and information flows between people, groups, organizations, or other entities. SNA identifies network structures, key influencers, communication patterns, subgroups, and vulnerabilities using metrics such as centrality, betweenness, density, and clustering.
    Intelligence AnalysisLaw EnforcementCybersecurity
    Related:

    Sock Puppet

    OSINT & Digital Research

    A fictitious online identity created by an investigator or threat actor to conduct covert research, infiltrate communities, or engage with targets without revealing their true identity. In legitima...

    A fictitious online identity created by an investigator or threat actor to conduct covert research, infiltrate communities, or engage with targets without revealing their true identity. In legitimate OSINT operations, sock puppets are carefully managed personas with realistic background details, activity history, and social connections to maintain cover during investigations.
    OSINTLaw Enforcement
    Related:

    SOCMINT (Social Media Intelligence)

    Intelligence Collection

    Also known as: Social Media Intelligence

    Intelligence derived from monitoring, collecting, and analyzing publicly available social media content. Used to identify networks, track narratives, detect threats, assess sentiment, and gather in...

    Intelligence derived from monitoring, collecting, and analyzing publicly available social media content. Used to identify networks, track narratives, detect threats, assess sentiment, and gather information on persons or groups of interest through their digital social interactions and postings.
    Law EnforcementNational SecurityOSINTCybersecurity
    Related:

    Soft Target

    Homeland Security & Counterterrorism

    A location, facility, or event with limited security measures that is vulnerable to attack and may contain large concentrations of people, such as shopping centers, transportation hubs, and public ...

    A location, facility, or event with limited security measures that is vulnerable to attack and may contain large concentrations of people, such as shopping centers, transportation hubs, and public gatherings.
    Homeland SecurityLaw Enforcement
    Related:

    Source Evaluation

    Intelligence Analysis

    Also known as: Source Rating, Admiralty Code, NATO System

    The process of assessing the reliability of an intelligence source and the credibility of the information provided. Commonly uses a standardized alphanumeric rating system where a letter (A through...

    The process of assessing the reliability of an intelligence source and the credibility of the information provided. Commonly uses a standardized alphanumeric rating system where a letter (A through F) rates source reliability and a number (1 through 6) rates information accuracy, such as B2 indicating a usually reliable source providing probably true information.
    All disciplines
    Related:

    Spoliation

    Evidence & Forensics

    The intentional, reckless, or negligent destruction, alteration, or concealment of evidence relevant to a legal proceeding. Spoliation can result in adverse inference instructions, sanctions, or se...

    The intentional, reckless, or negligent destruction, alteration, or concealment of evidence relevant to a legal proceeding. Spoliation can result in adverse inference instructions, sanctions, or separate criminal charges.
    LegalLaw Enforcement
    Related:

    Statement Analysis

    Interview & Interrogation

    Also known as: Linguistic Statement Analysis, SCAN (Scientific Content Analysis)

    The systematic examination of written or verbal statements to detect deception, identify omissions, and assess the reliability of an account. Analysts examine linguistic indicators including change...

    The systematic examination of written or verbal statements to detect deception, identify omissions, and assess the reliability of an account. Analysts examine linguistic indicators including changes in language, pronoun usage, verb tense shifts, lack of conviction, and structural gaps.
    Law EnforcementIntelligence Analysis
    Related:

    Stingray / Cell-Site Simulator

    Surveillance & Countersurveillance

    Also known as: IMSI Catcher, Cell-Site Simulator, Hailstorm

    An electronic surveillance device that mimics a legitimate cell tower to trick mobile phones in the area into connecting to it, thereby allowing the operator to identify phones in the vicinity, cap...

    An electronic surveillance device that mimics a legitimate cell tower to trick mobile phones in the area into connecting to it, thereby allowing the operator to identify phones in the vicinity, capture metadata, and in some cases intercept communications content.
    Law EnforcementNational Security
    Related:

    STIX / TAXII

    Cyber Threat Intelligence

    Also known as: Structured Threat Information Expression, Trusted Automated Exchange of Intelligence Information

    Standardized frameworks for sharing cyber threat intelligence. STIX (Structured Threat Information Expression) is a language for describing threat information including indicators, TTPs, threat act...

    Standardized frameworks for sharing cyber threat intelligence. STIX (Structured Threat Information Expression) is a language for describing threat information including indicators, TTPs, threat actors, and campaigns. TAXII (Trusted Automated Exchange of Intelligence Information) defines the protocols for how STIX data is exchanged between systems and organizations.
    CybersecurityCyber Threat Intelligence
    Related:

    Structured Analytic Techniques (SATs)

    Intelligence Analysis

    Also known as: SATs

    A set of formalized methods for analyzing intelligence problems that help analysts overcome cognitive limitations, manage complexity, and produce more rigorous assessments. SATs include brainstormi...

    A set of formalized methods for analyzing intelligence problems that help analysts overcome cognitive limitations, manage complexity, and produce more rigorous assessments. SATs include brainstorming, devil's advocacy, red team analysis, key assumptions check, analysis of competing hypotheses, and many others. They promote transparency in analytical reasoning.
    Intelligence Analysis
    Related:

    Structuring

    Financial Crimes & Fraud

    Also known as: Smurfing

    The illegal practice of breaking up financial transactions into smaller amounts specifically to avoid triggering mandatory reporting thresholds, such as the $10,000 CTR requirement. Also known as s...

    The illegal practice of breaking up financial transactions into smaller amounts specifically to avoid triggering mandatory reporting thresholds, such as the $10,000 CTR requirement. Also known as smurfing, structuring is a federal crime regardless of whether the underlying funds are legitimate or illicit.
    Financial CrimesLaw Enforcement
    Related:

    Subpoena

    Law Enforcement & Investigations

    A legal document commanding a person to appear before a court or other legal body to give testimony (subpoena ad testificandum) or produce documents and records (subpoena duces tecum). In investiga...

    A legal document commanding a person to appear before a court or other legal body to give testimony (subpoena ad testificandum) or produce documents and records (subpoena duces tecum). In investigations, administrative and grand jury subpoenas are used to compel production of business records, communications metadata, and financial documents.
    Law EnforcementLegal
    Related:

    Surveillance Detection

    Counterintelligence & Espionage

    Systematic measures employed by a person or team to determine whether they are under surveillance, using deliberate route variations, observation points, and behavioral awareness.

    CounterintelligenceLaw Enforcement
    Related:

    Surveillance Detection Route (SDR)

    Surveillance & Countersurveillance

    Also known as: SDR, Cleaning Route

    A preplanned route designed to identify surveillance while appearing natural and unremarkable to any observer. SDRs incorporate deliberate turns, stops, directional changes, varied environments, an...

    A preplanned route designed to identify surveillance while appearing natural and unremarkable to any observer. SDRs incorporate deliberate turns, stops, directional changes, varied environments, and observation points that force any surveillance team to expose themselves.
    CounterintelligenceLaw Enforcement
    Related:

    Suspicious Activity Report (SAR - LE)

    Homeland Security & Counterterrorism

    In law enforcement context, a report filed by citizens, businesses, or officers documenting behavior or activities that may be indicative of criminal or terrorist pre-operational planning. Distinct...

    In law enforcement context, a report filed by citizens, businesses, or officers documenting behavior or activities that may be indicative of criminal or terrorist pre-operational planning. Distinct from the financial SAR.
    Law EnforcementHomeland Security
    Related:

    Suspicious Activity Report (SAR)

    Financial Crimes & Fraud

    Also known as: SAR

    A regulatory filing that financial institutions are required to submit to FinCEN when they detect a transaction or pattern of transactions that they know, suspect, or have reason to suspect involve...

    A regulatory filing that financial institutions are required to submit to FinCEN when they detect a transaction or pattern of transactions that they know, suspect, or have reason to suspect involves illegal activity, attempts to evade reporting requirements, or has no lawful purpose.
    Financial CrimesLaw Enforcement
    Related:

    Tactics, Techniques, and Procedures (TTP)

    Cyber Threat Intelligence

    Also known as: TTP

    The patterns of behavior and methods used by threat actors in conducting cyber operations. Tactics describe the adversary's goals, techniques describe how those goals are achieved, and procedures a...

    The patterns of behavior and methods used by threat actors in conducting cyber operations. Tactics describe the adversary's goals, techniques describe how those goals are achieved, and procedures are the specific implementations of techniques.
    CybersecurityCyber Threat Intelligence
    Related:

    Target Package

    Intelligence Analysis

    A comprehensive compilation of intelligence information about a specific target, assembled to support operational planning and decision-making. A target package typically includes identification de...

    A comprehensive compilation of intelligence information about a specific target, assembled to support operational planning and decision-making. A target package typically includes identification details, known associates, patterns of life, vulnerabilities, threat assessment, and recommended courses of action.
    MilitaryLaw EnforcementNational Security
    Related:

    Task Force

    Law Enforcement & Investigations

    A multi-agency law enforcement team assembled to address a specific criminal problem, threat, or investigation that crosses jurisdictional boundaries.

    Law Enforcement
    Related:

    TECHINT (Technical Intelligence)

    Intelligence Collection

    Also known as: Technical Intelligence

    Intelligence derived from the collection, processing, analysis, and exploitation of data and information pertaining to foreign equipment and materiel. The purpose is to prevent technological surpri...

    Intelligence derived from the collection, processing, analysis, and exploitation of data and information pertaining to foreign equipment and materiel. The purpose is to prevent technological surprise, assess foreign scientific and technical capabilities, and develop countermeasures.
    MilitaryNational Security
    Related:

    Technical Surveillance Countermeasures (TSCM)

    Surveillance & Countersurveillance

    Also known as: TSCM, Bug Sweep, Debugging

    The systematic physical and electronic examination of a facility, vehicle, or device to detect technical surveillance devices (bugs, hidden cameras, GPS trackers, compromised phones). TSCM sweeps u...

    The systematic physical and electronic examination of a facility, vehicle, or device to detect technical surveillance devices (bugs, hidden cameras, GPS trackers, compromised phones). TSCM sweeps use specialized equipment including radio frequency detectors, non-linear junction detectors, and spectrum analyzers.
    CounterintelligenceCorporate SecurityExecutive Protection
    Related:

    Temporal Analysis

    Analytical Methodologies

    The study of time-based patterns in data to identify trends, cycles, anomalies, and relationships between events. In investigations, temporal analysis examines the timing and sequencing of activiti...

    The study of time-based patterns in data to identify trends, cycles, anomalies, and relationships between events. In investigations, temporal analysis examines the timing and sequencing of activities, communications, and transactions to detect patterns and establish timelines.
    Intelligence AnalysisLaw EnforcementFinancial Crimes
    Related:

    Terrorist Financing

    Homeland Security & Counterterrorism

    The process by which terrorist organizations raise, store, move, and spend funds to support their operations, recruitment, propaganda, and attacks. Terrorist financing may involve both illegal sour...

    The process by which terrorist organizations raise, store, move, and spend funds to support their operations, recruitment, propaganda, and attacks. Terrorist financing may involve both illegal sources and the diversion of legitimate funds through charities, businesses, or informal value transfer systems like hawala.
    CounterterrorismFinancial Crimes
    Related:

    Terry Stop

    Law Enforcement & Investigations

    A brief, investigative detention of a person by law enforcement based on reasonable suspicion of criminal activity, as authorized by Terry v. Ohio.

    Law Enforcement
    Related:

    Threat Actor

    Cyber Threat Intelligence

    An individual, group, or organization that conducts or has the intent and capability to conduct malicious activities against targets in cyberspace. Threat actor categories include nation-states, cy...

    An individual, group, or organization that conducts or has the intent and capability to conduct malicious activities against targets in cyberspace. Threat actor categories include nation-states, cybercriminals, hacktivists, insider threats, and terrorist organizations.
    CybersecurityCyber Threat Intelligence
    Related:

    Threat Assessment

    Intelligence Analysis

    The formal evaluation of the nature, likelihood, and severity of a potential threat. Threat assessments consider the intent, capability, and opportunity of threat actors to harm a specific target, ...

    The formal evaluation of the nature, likelihood, and severity of a potential threat. Threat assessments consider the intent, capability, and opportunity of threat actors to harm a specific target, and inform security planning and resource allocation decisions.
    All disciplines
    Related:

    Threat Hunting

    Cyber Threat Intelligence

    The proactive and iterative practice of searching through networks and systems to detect advanced threats that have evaded existing automated security controls. Unlike reactive incident response, t...

    The proactive and iterative practice of searching through networks and systems to detect advanced threats that have evaded existing automated security controls. Unlike reactive incident response, threat hunting assumes that adversaries may already be present.
    Cybersecurity
    Related:

    Threat Level / Advisory System

    Homeland Security & Counterterrorism

    A standardized system for communicating the current assessed level of terrorist or security threat to the public and government agencies. Threat level systems provide a common framework for underst...

    A standardized system for communicating the current assessed level of terrorist or security threat to the public and government agencies. Threat level systems provide a common framework for understanding the threat environment and trigger corresponding protective measures.
    Homeland Security
    Related:

    Title III Wiretap

    Legal & Compliance

    Also known as: Title III, Wire Intercept

    Court-authorized electronic surveillance conducted under Title III of the Omnibus Crime Control and Safe Streets Act of 1968. Title III wiretaps require a showing of probable cause, exhaustion of o...

    Court-authorized electronic surveillance conducted under Title III of the Omnibus Crime Control and Safe Streets Act of 1968. Title III wiretaps require a showing of probable cause, exhaustion of other investigative methods, specific identification of communications to be intercepted, and strict minimization.
    Law EnforcementLegal
    Related:

    Tor (The Onion Router)

    Cybersecurity & Digital Forensics

    Also known as: The Onion Router, Onion Routing

    A free, open-source software and network that enables anonymous communication by directing internet traffic through a worldwide volunteer overlay network of relays. Tor conceals a user's location a...

    A free, open-source software and network that enables anonymous communication by directing internet traffic through a worldwide volunteer overlay network of relays. Tor conceals a user's location and usage from surveillance and traffic analysis by encrypting data in multiple layers.
    CybersecurityOSINTLaw Enforcement
    Related:

    Trade-Based Money Laundering (TBML)

    Financial Crimes & Fraud

    The process of disguising the proceeds of crime by manipulating international trade transactions through over-invoicing, under-invoicing, multiple invoicing, or misrepresenting the quality or quant...

    The process of disguising the proceeds of crime by manipulating international trade transactions through over-invoicing, under-invoicing, multiple invoicing, or misrepresenting the quality or quantity of goods.
    Financial CrimesLaw Enforcement
    Related:

    Tradecraft

    Counterintelligence & Espionage

    The methods, techniques, and procedures used in intelligence operations to conduct activities clandestinely and securely. Tradecraft encompasses surveillance detection, clandestine communications, ...

    The methods, techniques, and procedures used in intelligence operations to conduct activities clandestinely and securely. Tradecraft encompasses surveillance detection, clandestine communications, dead drops, brush passes, disguise, counter-surveillance, document handling, and operational security practices.
    National SecurityCounterintelligenceLaw Enforcement
    Related:

    Undercover Operation

    Law Enforcement & Investigations

    An investigative technique in which a law enforcement officer or agent assumes a false identity to infiltrate a criminal organization, gather evidence, and build cases against suspects. Undercover ...

    An investigative technique in which a law enforcement officer or agent assumes a false identity to infiltrate a criminal organization, gather evidence, and build cases against suspects. Undercover operations involve significant legal, ethical, and safety considerations.
    Law Enforcement
    Related:

    Volatile Data

    Cybersecurity & Digital Forensics

    Digital information that is lost when a device is powered off or restarted. Volatile data includes running processes, network connections, logged-in users, system time, clipboard contents, and the ...

    Digital information that is lost when a device is powered off or restarted. Volatile data includes running processes, network connections, logged-in users, system time, clipboard contents, and the contents of RAM. Forensic investigators must capture volatile data before non-volatile data according to the order of volatility principle.
    Digital ForensicsIncident Response
    Related:

    VPN (Virtual Private Network)

    Cybersecurity & Digital Forensics

    A technology that creates an encrypted tunnel between a user's device and a remote server, masking the user's IP address and protecting data in transit.

    CybersecurityOSINT
    Related:

    Vulnerability

    Cybersecurity & Digital Forensics

    A weakness in a system, application, network, or process that could be exploited by a threat actor to gain unauthorized access or cause harm. Vulnerabilities may exist in software code, hardware, c...

    A weakness in a system, application, network, or process that could be exploited by a threat actor to gain unauthorized access or cause harm. Vulnerabilities may exist in software code, hardware, configurations, operational procedures, or human behavior. They are cataloged using the Common Vulnerabilities and Exposures (CVE) system.
    Cybersecurity
    Related:

    Watch List

    Homeland Security & Counterterrorism

    A database of known or suspected individuals of concern maintained by law enforcement and intelligence agencies to facilitate screening at borders, airports, and other checkpoints.

    Homeland SecurityLaw Enforcement
    Related:

    Wayback Machine

    OSINT & Digital Research

    The Internet Archive's web archiving service that captures and stores snapshots of web pages over time. Investigators use it to view historical versions of websites, recover deleted content, verify...

    The Internet Archive's web archiving service that captures and stores snapshots of web pages over time. Investigators use it to view historical versions of websites, recover deleted content, verify past claims, track changes to a subject's online presence, and preserve evidence that may be removed from the live internet.
    OSINTLaw Enforcement
    Related:

    Weapons of Mass Destruction (WMD)

    Homeland Security & Counterterrorism

    Also known as: WMD, CBRN (Chemical, Biological, Radiological, Nuclear)

    Weapons capable of causing death or serious injury to a significant number of people through their explosive, incendiary, poisonous, chemical, biological, radiological, or nuclear properties.

    National SecurityHomeland SecurityMilitary
    Related:

    Web Scraping

    OSINT & Digital Research

    The automated extraction of data from websites using software tools or scripts. In investigative contexts, web scraping is used to collect large volumes of publicly available data from forums, soci...

    The automated extraction of data from websites using software tools or scripts. In investigative contexts, web scraping is used to collect large volumes of publicly available data from forums, social media, directories, and other online sources for analysis. Legal and ethical considerations vary by jurisdiction and platform terms of service.
    OSINTCybersecurityData Science
    Related:

    Whistleblower

    Corporate & Private Investigations

    An individual who reports illegal, unethical, or unsafe practices within an organization to internal authorities, regulatory bodies, law enforcement, or the public. Whistleblower protection laws in...

    An individual who reports illegal, unethical, or unsafe practices within an organization to internal authorities, regulatory bodies, law enforcement, or the public. Whistleblower protection laws in many jurisdictions shield these individuals from retaliation.
    CorporateLegalLaw Enforcement
    Related:

    WHOIS

    OSINT & Digital Research

    A query-and-response protocol used to look up domain name registration information, including registrant name, organization, contact details, registration and expiration dates, name servers, and th...

    A query-and-response protocol used to look up domain name registration information, including registrant name, organization, contact details, registration and expiration dates, name servers, and the registrar. While GDPR and privacy services have increasingly redacted registrant details, historical WHOIS records remain a valuable investigative resource.
    OSINTCybersecurity
    Related:

    Wire Fraud

    Financial Crimes & Fraud

    A federal crime involving the use of electronic communications (wire, radio, television, internet) to execute a scheme to defraud. Wire fraud carries significant penalties and is one of the most co...

    A federal crime involving the use of electronic communications (wire, radio, television, internet) to execute a scheme to defraud. Wire fraud carries significant penalties and is one of the most commonly charged federal offenses.
    Law EnforcementFinancial Crimes
    Related:

    Write Blocker

    Cybersecurity & Digital Forensics

    A hardware or software tool that prevents any write operations to a storage device while allowing read access. Write blockers are essential in digital forensics to ensure that the process of examin...

    A hardware or software tool that prevents any write operations to a storage device while allowing read access. Write blockers are essential in digital forensics to ensure that the process of examining digital evidence does not alter the original media, preserving its evidentiary integrity.
    Digital Forensics
    Related:

    Zero-Day

    Cybersecurity & Digital Forensics

    Also known as: 0-Day

    A previously unknown software vulnerability that has not been publicly disclosed or patched by the vendor. The term refers to the fact that the vendor has had zero days to develop and release a fix...

    A previously unknown software vulnerability that has not been publicly disclosed or patched by the vendor. The term refers to the fact that the vendor has had zero days to develop and release a fix. Zero-day exploits are highly valued by both offensive security operators and malicious actors because no defenses exist against them.
    CybersecurityCyber Threat Intelligence
    Related:

    We use cookies to analyze traffic and personalize content. You can opt out at any time. See our Cookie Policy.