Ravindra BagaleCourses & study guides

50. Glossary (Marathi column)

50.5 SOC, law, AD, malware, mobile/IoT terms

BloodHound awareness, CERT-In, DPDP, CEH exam modules (this book’s preferred phrase for CEH topic maps), Android hygiene. Alphabetical. India context + ethics.

Term Meaning मराठी अर्थ
Active Directory (AD) Microsoft directory for users, groups, machines and Kerberos auth. — (English madhech vapra)
Android hardening Screen lock, updates, limited app sources, MDM mindset on OWN devices. अँड्रॉइड कडक सुरक्षा
BloodHound Graph tool for AD attack-path awareness (OWN lab AD only). — (English madhech vapra)
Bug bounty (in-scope) Paid/rewarded finding of weaknesses inside a published programme scope. बग बाउंटी (फक्त व्याप्तीत)
CEH exam modules Organised topic map for CEH-style study (this book maps chapters to modules). — (English madhech vapra)
CERT-In Indian Computer Emergency Response Team – advisories and reporting channel. — (English madhech vapra)
DDoS Distributed Denial of Service – flooding to hurt availability. वितरित सेवा-इंकार
DPDP Digital Personal Data Protection Act (India) – personal data duties (verify current text). — (English madhech vapra)
IDS evasion Techniques meant to slip past detectors (Blue tunes signatures / behaviour). शोध चुकवणे
IoT / OT Internet of Things / Operational Technology – devices and industrial controls. — (English madhech vapra)
IT Act Information Technology Act (India) – cyber offences and related duties (verify). — (English madhech vapra)
Kerberos Ticket-based authentication protocol used heavily in AD environments. — (English madhech vapra)
Lateral movement Moving from one compromised host to others inside a network. बाजूने प्रसार
Responsible disclosure Reporting a weakness privately to the owner with time to fix before publicity. जबाबदार खुलासा
SCADA (awareness) Industrial control monitoring class – segment OT; never “test” a live plant. — (English madhech vapra)
Session hijacking Stealing or predicting a session token to act as another user. सत्र अपहरण
Written authorisation Paper/email scope that allows a test – required before any offensive step. अधिकृत परवानगी पत्र
Red team (attacker) does Blue team (defender) detects / stops
Treats “bug bounty” as free licence on any site Reads scope; out-of-scope = stop; responsible disclosure
Runs BloodHound against a client AD without paper Only OWN AD lab; monitors unusual LDAP/Kerberos patterns
“Tests” SCADA / hospital IoT for fun Never; segment OT; change defaults; authorised IR only

Ravindra Bagale's Tip

CEH study = exam modules – learn the topic map and the language of controls. Bug bounty = in-scope only; hacking a random .in site = a criminal mindset. Awareness of CERT-In / cybercrime.gov.in / the 1930 helpline = a Blue citizen skill. Remember this.

Lab

Write a half-page “responsible disclosure” practice email for a fictional bug found on Sahyadri Traders OWN Juice Shop (192.168.56.x) – severity, steps to reproduce, fix suggestion. Do not send it to any real company. Add one CERT-In awareness note in your notebook (verify official site).