Skip to content

Latest commit

 

History

9 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

🛡️ Cybersecurity Terminology Compendium — Resource Collection

English | 中文

Deep web-wide research | Updated: 2026-07-21 Covers: Chinese term libraries / authoritative English glossaries / acronym quick reference / knowledge frameworks / national standards / vulnerability classification / attack-defense knowledge bases


Contents


1. Chinese term compendiums (top picks, 12)

# Resource Link Highlights
1 CyberGlossary 中文版 🥇 https://www.cyberglossary.org/zh Clear categories (attack/threat/crypto/network/cloud), CVE case studies, frequently updated
2 CN-SEC 中英文术语大全 https://cn-sec.com/archives/3320996.html A-Z sorted, bilingual, systematic
3 CSDN 网络安全黑话指南 https://blog.csdn.net/shuryuu/article/details/121212187 Most detailed jargon guide — tools/techniques/defense; a must for beginners
4 FreeBuf 专业术语解释 https://m.freebuf.com/articles/network/243201.html Detailed APT/XSS/DoS concepts; good for intermediates
5 CN-SEC 安全科普词条 https://cn-sec.com/archives/886666.html Core concepts: POC/EXP/Shellcode/0Day/1Day/NDay
6 腾讯云渗透测试名词 https://cloud.tencent.com/developer/article/2580321 Full attack-defense vocabulary: payloads, vulns, shellcode
7 盾灵导航中英文对照表 https://www.dunling.com/24472.html Well-categorized (basics/attack/defense/crypto/auth)
8 2026 版 30 个核心术语 https://www.gm7.org/archives/33597 2026 edition: botnets, ransomware, EDR, zero trust, AI security
9 笨熊呆呆瓜 核心术语体系 https://www.bxddg.com/archives/anquanhexishuyu Structured system: vulns → pentest → defense → APT
10 阿里云 100 个中英文术语 https://developer.aliyun.com/article/1632458 100 terms explained: auth, crypto, pentesting
11 安厦科技 最全术语汇总 http://www.isa-hsse.com/index.php?a=show&catid=192&id=53471 Bilingual, includes CISA/CISM/CISSP certification terms
12 Fortinet 20 种攻击类型 https://www.fortinet.com/cn/resources/cyberglossary/types-of-cyber-attacks 20 common attack types with defense advice

📸 Site screenshots

CyberGlossary 中文版截图 CN-SEC 术语大全截图


2. Authoritative English glossaries (international standards, 10)

# Resource Link Highlights
1 NIST Cybersecurity Glossary 🥇 https://csrc.nist.gov/glossary 10,113 entries, NIST official, updated through 2026-05-29
2 CISA/NICCS glossary https://niccs.cisa.gov/resources/glossary US government official, CSV download
3 NIST IR 7298 Rev.3 https://nvlpubs.nist.gov/nistpubs/ir/2019/NIST.IR.7298r3.pdf Official PDF, terms extracted from NIST FIPS/SP series
4 SANS glossary https://www.sans.org/security-resources/glossary-of-terms A-Z grouped, from the world's top security training org
5 CyberGlossary (EN) https://www.cyberglossary.org/en Category browsing + full term list
6 SecurityElites, 1,506 entries https://securityelites.com/glossary/ 1,506 terms across 24 categories (app/cloud/crypto…)
7 Coursera cybersecurity terms https://www.coursera.org/resources/cybersecurity-terms Beginner-friendly, updated 2025-08
8 CyberExperts encyclopedia https://cyberexperts.com/encyclopedia/ 870 entries, focused on risk management & compliance
9 Cybersecurity Terms Lexicon https://cybersecuritytermslexicon.com/ Concept-relationship oriented, not just listings
10 Fortinet cyber glossary https://www.fortinet.com/cn/resources/cyberglossary Vendor-maintained, has Chinese version, frequent updates

3. Acronym quick reference (high-frequency in attack & defense, 5)

# Resource Link Highlights
1 Infosec abbreviations list 🥇 https://github.com/truckli/infosec-abbrv 4,732 acronyms spanning ops/defense/R&D/ICT/AI; open source on GitHub
2 DecodeIT security glossary 2025 https://decodeit.app/zh-cn/security/guides/security-glossary AI threats, post-quantum crypto, passwordless auth trends
3 Cybyr Cyberpedia https://cybyr.com/cyberpedia/ Updated 2026-06: terms/acronyms/threats/defense
4 NIST IR7581 acronyms https://nvlpubs.nist.gov/nistpubs/Legacy/IR/nistir7581.pdf ~1,000 cybersecurity acronyms, PDF
5 All Acronyms https://www.allacronyms.com/ Community-driven general acronym database

4. Security frameworks & standards (8)

# Resource Link Highlights
1 MITRE ATT&CK 中文版 🥇 https://www.xiasec.com/wp-content/Attack_CN/ The most authoritative adversarial TTPs knowledge base, with Chinese translation
2 MITRE ATT&CK (EN) https://attack.mitre.org/ Original: 14 tactics, hundreds of techniques
3 CWE v4.20 https://cwe.mitre.org/data/ 944 weakness types, incl. CWE Top 25 (2025)
4 CWE 中文版 v4.20 https://cwe.org.cn/data/index.html Chinese CWE mirror with the full 944-entry list
5 CAPEC https://capec.mitre.org/ Attack-pattern dictionary, cross-linked with CWE/ATT&CK
6 CAPEC glossary https://capec.mitre.org/about/glossary.html Attack-pattern term definitions
7 OWASP Top 10 https://owasp.org/www-project-top-ten/ The international standard for web app risks
8 NIST CSF 2.0 https://www.nist.gov/cyberframework Govern/Identify/Protect/Detect/Respond/Recover

5. Chinese-English dictionaries (6)

# Resource Link Highlights
1 盾灵导航 中英文对照表 https://www.dunling.com/24472.html Well-categorized: basics/attack/defense/crypto/auth/tools
2 阿里云 100 个中英文术语 https://developer.aliyun.com/article/1632458 100 high-frequency bilingual terms
3 孤独剑客 中英文对照 https://www.janker.org/tech/18.html Concise quick-reference table
4 ISACA 中英文术语表 https://www.isaca.org/-/media/files/isacadp/project/isaca/resources/glossary/isaca-glossary-english-chinese-simplified_mis_chi_0615.pdf Official ISACA EN-CN glossary: audit/governance/security
5 香港政府 IT 术语中英对照 https://www.digitalpolicy.gov.hk/tc/our_work/digital_infrastructure/methodology/glossary/doc/IT_Glossary.pdf HK government official IT glossary, many security terms
6 Security Glossary TW https://github.com/astroicers/security-glossary-tw Open-source Traditional Chinese glossary, YAML/JSON/API

6. Vulnerability classification & attack-pattern libraries (5)

# Resource Link Highlights
1 CVE https://cve.mitre.org/ Global vulnerability ID standard, CVE-YYYY-NNNNN
2 NVD https://nvd.nist.gov/ CVSS scores, impact analysis, remediation info
3 CNVD https://www.cnvd.org.cn/ China National Vulnerability Database, Chinese descriptions
4 CNNVD http://www.cnnvd.org.cn/ Maintained by China Information Technology Security Evaluation Center
5 Vulhub https://github.com/vulhub/vulhub One-command Docker vuln labs, incl. CVE-2024-27198

7. Web security knowledge bases (3)

# Resource Link Highlights
1 Web Security 学习笔记 🥇 https://websec.readthedocs.io/zh/latest/index.html Complete web security system: SQLi/XSS/CSRF/SSRF/RCE + defense + tools
2 Web security terminology page https://websec.readthedocs.io/zh/latest/misc/terminology.html Common terms explained in one place
3 OWASP docs https://owasp.org/ The international authority on web app security

8. Chinese national standards (GB series, 5)

# Standard Name Link Highlights
1 GB/T 25069-2022 InfoSec technology — terminology https://www.bzchaxun.com/view/8030070010000000.html The most authoritative national standard, 176 pages, replaces the 2010 edition
2 GB/T 30279-2020 Vulnerability classification & rating guide https://ndls.cnis.ac.cn/standard/detail/ca2cbe3e899d9d0c8c294300320f72fc Vulnerability rating methodology
3 GB/T 22239-2019 MLPS (等保 2.0) baseline requirements 等保 2.0 core standard Foundation of the MLPS regime
4 GB/T 25070-2019 MLPS security design requirements 等保 2.0 companion Security design requirements
5 GB/T 28448-2019 MLPS assessment requirements 等保 2.0 companion Assessment methodology standard

9. Security certifications & professional English (4)

# Resource Link Highlights
1 ISACA 中英文术语表 https://www.isaca.org/-/media/files/isacadp/project/isaca/resources/glossary/isaca-glossary-english-chinese-simplified_mis_chi_0615.pdf CISA/CISM/CGEIT certification terms
2 ISC² glossary https://www.isc2.org/ CISSP-related terminology
3 香港 IT 术语中英对照 https://www.digitalpolicy.gov.hk/tc/our_work/digital_infrastructure/methodology/glossary/doc/IT_Glossary.pdf Extensive bilingual security terms
4 Security Glossary TW https://github.com/astroicers/security-glossary-tw Open-source structured tooling, API support

10. Learning paths

🟢 Beginner (bootcamp students)

Step 1: CSDN jargon guide          → learn the lingo (botnet, webshell, privesc, AV evasion)
Step 2: CN-SEC bilingual compendium → build the full framework
Step 3: Aliyun 100 terms           → master high-frequency core terms
Step 4: GitHub acronym list        → decode everyday unknown acronyms

🟡 Intermediate (practitioners)

Step 1: MITRE ATT&CK 中文版        → understand the attacker lifecycle
Step 2: CWE                        → master vulnerability classification
Step 3: NIST glossary              → authoritative definitions for reports
Step 4: GB/T 25069-2022            → the domestic standards reference
Step 5: Web Security 学习笔记       → complete web security knowledge system

🔴 Expert (security researchers)

Step 1: CAPEC                      → attack patterns and their counters
Step 2: NVD / CVE                  → track the latest vulnerabilities
Step 3: NIST CSF 2.0               → enterprise security governance
Step 4: SecurityElites 1,506 terms → deep professional vocabulary
Step 5: MITRE ATT&CK (EN original) → cutting-edge TTPs

11. Penetration-testing tools (12)

Covers recon → scanning → exploitation → post-exploitation, organized by pentest lifecycle.

# Resource Link Highlights
1 Awesome_Pentest_Tools 🥇 https://github.com/sangnigege/Awesome_Pentest_Tools One-stop pentest/red-team toolkit, organized by MITRE ATT&CK: fingerprinting/scanning/code audit/lateral movement
2 SecToolKit https://github.com/ProbiusOfficial/SecToolKit CTF + pentest tool repo with docs for common and cutting-edge tools
3 awesome-cyber-security https://github.com/alphaSeclab/awesome-cyber-security Huge collection: pentest/AV evasion/C2/post-exploitation/AD/threat hunting
4 awesome-pentest https://github.com/enaqx/awesome-pentest Classic pentest resources: online resources/vuln DBs/report templates
5 awesome-security-tools-2026 https://github.com/spinov001-art/awesome-security-tools-2026 150+ tools: pentest/scanning/network/cloud/container/API/OSINT/forensics
6 网络安全工具箱 100+ https://blog.csdn.net/cui_yonghua/article/details/162704740 120+ tools by Kill Chain, red/blue minimal kit picks
7 RedblueBox https://github.com/pinglanlab/RedblueBox Windows GUI integrated pentest toolkit, plug-and-play
8 渗透师安全导航 https://www.shentoushi.top/knowledge Practitioner portal: vuln platforms/SRC/APT/CTF/online tools/ranges
9 Tool_Summary https://github.com/djytmdj/Tool_Summary Security tooling summary: vuln DBs/exploit tools/scanners/lateral/wordlists
10 Online_tools https://github.com/CuriousLearnerDev/Online_tools 315+ tools with AI-driven automation (HexStrike), app-store style
11 Kali Tools https://www.kali.org/tools/ Official Kali Linux: 600+ tools, each documented
12 HackDB https://hackdb.com/ Red-team/pentest/white-hat resource directory

12. Vulnerability databases & intel platforms (12)

# Resource Link Highlights
1 Seebug 🥇 https://www.seebug.org/ Run by Knownsec, 52,206+ vulns, 44,236 PoCs, China's authoritative vuln DB
2 Exploit-DB https://www.exploit-db.com/ 50,000+ exploits, shellcode, papers; offline via SearchSploit
3 NVD https://nvd.nist.gov/ US official DB with CVSS and CPE impact analysis
4 CVE.org https://www.cve.org/ The official CVE numbering program
5 CVE Details https://www.cvedetails.com/ NVD data visualized: stats/vendor rankings/trends
6 Vulners https://vulners.com/ Aggregates NVD/Exploit-DB/GitHub etc., free API
7 CVE Tools https://cve.tools/ 347,500+ CVEs, 65,400+ PoCs, 1,600+ CISA KEV, EPSS scores
8 VulnScope https://vulnscope.dev/zh Suite-centric CVE lookup, Chinese UI, 76,212 CVEs
9 milw00rm https://milw00rm.com/ 46,496 exploit scripts, graded Critical/High
10 CISA KEV https://www.cisa.gov/known-exploited-vulnerabilities-catalog 1,622 confirmed-in-the-wild vulns, CSV/JSON
11 expku https://www.expku.com/ Chinese exploit library: remote/local/web/DoS
12 Vulnify https://www.vulnify.com/ Open-source security tool search engine with filters

13. Online practice ranges (15)

# Resource Link Highlights Difficulty
1 HackTheBox 🥇 https://www.hackthebox.com/ World-class pentest training, 2M+ users, real machines ⭐⭐⭐⭐⭐
2 TryHackMe https://tryhackme.com/ Guided paths, 500+ rooms, browser-based ⭐⭐
3 PentesterLab https://pentesterlab.com/ Web pentest focus: SQLi/XSS/file upload ⭐⭐⭐
4 VulnHub https://www.vulnhub.com/ VM-image-based practical ranges, highly realistic ⭐⭐⭐⭐
5 VulnStack (红日安全) https://github.com/crow821/vulntarget Internal-network range series simulating enterprise AD ⭐⭐⭐⭐⭐
6 攻防世界 https://adworld.xctf.org.cn/ China's mainstream CTF range, graded beginner→expert ⭐⭐
7 CTFHub https://www.ctfhub.com/ CTF drills by type (SQLi/XSS/upload…) ⭐⭐
8 RootMe https://www.root-me.org/ Renowned free CTF range: web/crypto/rev/network ⭐⭐⭐⭐
9 墨者学院 https://www.mozhe.cn/ Chinese range: web/hosts/DB/network/code audit ⭐⭐
10 封神台 (合天网安) https://www.hetianlab.com/ Advanced Chinese ranges with real vuln reproduction, SRC scenarios ⭐⭐⭐⭐
11 HeaSecWebLab https://github.com/HeaSec/HeaSecWebLab 85 standalone web ranges, HTTP basics → business-logic vulns, AI-assisted ⭐
12 DVWA https://github.com/digininja/DVWA Classic PHP vuln range, the beginner classic ⭐
13 SQLi-Lab / Upload-Lab / XSS-Lab https://github.com/Audi-1/sqli-labs Dedicated vuln-drill series, one at a time ⭐⭐
14 Vulhub https://github.com/vulhub/vulhub Docker vuln environments for hundreds of CVEs ⭐⭐
15 Vulfocus https://github.com/cn360cn/vulfocus Vuln integration platform, online reproduction ⭐⭐

14. Security communities & blogs (8)

# Resource Link Highlights
1 The Hacker News 🥇 https://thehackernews.com/ Daily updates, 5M+ monthly readers, incident/disclosure/trend analysis
2 Seebug Paper https://paper.seebug.org/ High-quality vuln analysis & attack-defense writing
3 0x00sec https://0x00sec.org/ Deep technical: exploit dev/malware analysis/reverse engineering
4 小迪渗透吧 https://www.xiaodi8.com/ Knowledge base incl. OWASP LLM range/cloud security/red-blue/payload platforms
5 渗透师导航 https://www.shentoushi.top/knowledge Practitioner portal aggregating platforms/SRC/blogs/tools/communities
6 FreeBuf https://www.freebuf.com/ Well-known Chinese security media: vuln analysis/research/industry news
7 先知社区 https://xz.aliyun.com/ Alibaba security community: articles/reproductions/CTF writeups
8 安全客 https://www.anquanke.com/ Security news/tech blogs/vuln analysis/events

15. Blue-team resources (8)

# Resource Link Highlights
1 蓝队资源大合集 🥇 https://blue.y1ng.org/0x1_blue_team-resources/ Blue-team megacollection: DevSecOps/EDR/SIEM/honeypots/threat hunting/forensics
2 Wazuh https://github.com/wazuh/wazuh Open-source HIDS + SIEM, cross-platform agents, blue-team entry point
3 Security Onion https://github.com/Security-Onion-Solutions/security-onion Free GNU/Linux distro for intrusion detection/monitoring/log management
4 Suricata https://github.com/OISF/suricata High-performance IDS/IPS with NSM mode, Snort-compatible rules
5 Zeek https://github.com/zeek/zeek Network security monitor for suspicious traffic
6 TheHive https://github.com/TheHive-Project/TheHive Scalable free incident-response platform, MISP-integrated
7 MISP https://github.com/MISP/MISP Open-source threat-intel sharing, core blue-team/CSIRT tool
8 Velociraptor https://github.com/Velocidex/velociraptor Endpoint forensics & digital investigation, IR essential

16. Awesome collections (7)

# Resource Link Highlights
1 Awesome-Hacking 🥇 https://github.com/Hack-with-Github/Awesome-Hacking 80,000+ stars, curated security resource links, community-maintained
2 awesome-pentest https://github.com/enaqx/awesome-pentest Classic pentest list: online resources/vuln DBs/report templates
3 awesome-cyber-security https://github.com/alphaSeclab/awesome-cyber-security Mega collection: pentest/AV evasion/C2/post-exploitation/AD/threat hunting
4 awesome-security-tools-2026 https://github.com/spinov001-art/awesome-security-tools-2026 150+ 2026 tools: pentest/scanning/network/cloud/container/API/OSINT
5 Awesome_Pentest_Tools https://github.com/sangnigege/Awesome_Pentest_Tools Full-lifecycle pentest tools, MITRE ATT&CK organized
6 SecLists https://github.com/danielmiessler/SecLists Pentest wordlists, a researcher essential
7 PayloadsAllTheThings https://github.com/swisskyrepo/PayloadsAllTheThings Payload cheat sheets: web injection/LFI/XXE/SSRF etc.

17. SRC / bug-bounty platforms (5)

# Resource Link Highlights
1 HackerOne 🥇 https://www.hackerone.com/ The largest bounty platform: $230M+ paid, 1M+ researchers
2 Bugcrowd https://www.bugcrowd.com/ Renowned bounty platform: crowdsourced testing/disclosure
3 补天平台 https://butian.360.cn/ 360's vulnerability response platform, among China's largest SRCs
4 漏洞盒子 https://www.vulbox.com/ Crowdsourced security testing & enterprise SRC services
5 CNVD https://www.cnvd.org.cn/ National vulnerability sharing platform: submission & validation

18. Security certification tracks (6)

# Certification Body Link Highlights
1 OSCP / OSWE / OSEP / OSED 🥇 Offensive Security https://www.offensive-security.com/ The most respected hands-on certs, "Try Harder" exam model
2 CISSP ISC² https://www.isc2.org/ Senior practitioner cert, highest global recognition
3 CISA / CISM / CGEIT ISACA https://www.isaca.org/ Audit/management/governance track, enterprise first choice
4 CEH EC-Council https://www.eccouncil.org/ Entry-level ethical hacking cert
5 Security+ / CySA+ CompTIA https://www.comptia.org/ Foundational certs, career switcher entry
6 CCSK / CCSP CSA / ISC² https://cloudsecurityalliance.org/ Cloud security track

Appendix: quick lookup tables

Common security acronyms

Acronym Full name Chinese
APT Advanced Persistent Threat 高级持续性威胁
CVE Common Vulnerabilities and Exposures 公共漏洞与暴露
CWE Common Weakness Enumeration 通用弱点枚举
CAPEC Common Attack Pattern Enumeration and Classification 通用攻击模式枚举
CVSS Common Vulnerability Scoring System 通用漏洞评分系统
OWASP Open Web Application Security Project 开放式 Web 应用安全项目
SIEM Security Information and Event Management 安全信息与事件管理
EDR Endpoint Detection and Response 端点检测与响应
XDR Extended Detection and Response 扩展检测与响应
SOAR Security Orchestration, Automation and Response 安全编排自动化与响应
WAF Web Application Firewall Web 应用防火墙
IDS Intrusion Detection System 入侵检测系统
IPS Intrusion Prevention System 入侵防御系统
MFA Multi-Factor Authentication 多因素认证
IAM Identity and Access Management 身份与访问管理
PAM Privileged Access Management 特权访问管理
SOC Security Operations Center 安全运营中心
NGFW Next-Generation Firewall 下一代防火墙
DDoS Distributed Denial of Service 分布式拒绝服务
RCE Remote Code Execution 远程代码执行
XSS Cross-Site Scripting 跨站脚本攻击
CSRF Cross-Site Request Forgery 跨站请求伪造
SSRF Server-Side Request Forgery 服务端请求伪造
SQLi SQL Injection SQL 注入
XXE XML External Entity XML 外部实体注入
MITM Man-in-the-Middle 中间人攻击
PoC Proof of Concept 概念验证

🖼️ Screenshot gallery

Homepage screenshots of all 131 resources were auto-generated — view the full gallery:

👉 📸 View the full screenshot gallery (112 site screenshots)

A few previews

CyberGlossary CN-SEC CSDN jargon guide

MITRE ATT&CK CWE Seebug

HackTheBox Kali Tools Awesome-Hacking

📌 Screenshots auto-generated with Playwright + Chrome; they show homepage appearance only. Some sites may require login or render partially.


📌 Note: all resources are publicly accessible links worth bookmarking; some may require a proxy to reach. All links last verified 2026-07-21.

💡 Tip: consider adding this document to your team wiki (Feishu/Notion) for easy lookup.


License & Usage Notice

Source-Available · All Rights Reserved

This project is source-available and all rights are reserved by the author. The code is provided for viewing and evaluation purposes only — access does not grant any right to copy, modify, redistribute, use commercially, or create derivative works. Unauthorized reuse may carry legal risk. Contact the author for explicit written permission before any other use.

本仓库为「源码可查、权利保留」项目(source-available / all-rights-reserved)。代码仅供查看与评估,未授权任何复制、再分发、修改、商用或衍生创作。擅自借用代码存在法律风险;如有需要请先联系作者获取明确书面许可。

About

Cybersecurity terminology resource navigation - glossary, acronyms, frameworks, standards collection

Topics

Resources

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages