🛡️ Cybersecurity Terminology Compendium — Resource Collection
English | 中文
Deep web-wide research | Updated: 2026-07-21
Covers: Chinese term libraries / authoritative English glossaries / acronym quick reference / knowledge frameworks / national standards / vulnerability classification / attack-defense knowledge bases
1. Chinese term compendiums (top picks, 12)
#
Resource
Link
Highlights
1
CyberGlossary 中文版 🥇
https://www.cyberglossary.org/zh
Clear categories (attack/threat/crypto/network/cloud), CVE case studies, frequently updated
2
CN-SEC 中英文术语大全
https://cn-sec.com/archives/3320996.html
A-Z sorted, bilingual, systematic
3
CSDN 网络安全黑话指南
https://blog.csdn.net/shuryuu/article/details/121212187
Most detailed jargon guide — tools/techniques/defense; a must for beginners
4
FreeBuf 专业术语解释
https://m.freebuf.com/articles/network/243201.html
Detailed APT/XSS/DoS concepts; good for intermediates
5
CN-SEC 安全科普词条
https://cn-sec.com/archives/886666.html
Core concepts: POC/EXP/Shellcode/0Day/1Day/NDay
6
腾讯云渗透测试名词
https://cloud.tencent.com/developer/article/2580321
Full attack-defense vocabulary: payloads, vulns, shellcode
7
盾灵导航中英文对照表
https://www.dunling.com/24472.html
Well-categorized (basics/attack/defense/crypto/auth)
8
2026 版 30 个核心术语
https://www.gm7.org/archives/33597
2026 edition: botnets, ransomware, EDR, zero trust, AI security
9
笨熊呆呆瓜 核心术语体系
https://www.bxddg.com/archives/anquanhexishuyu
Structured system: vulns → pentest → defense → APT
10
阿里云 100 个中英文术语
https://developer.aliyun.com/article/1632458
100 terms explained: auth, crypto, pentesting
11
安厦科技 最全术语汇总
http://www.isa-hsse.com/index.php?a=show&catid=192&id=53471
Bilingual, includes CISA/CISM/CISSP certification terms
12
Fortinet 20 种攻击类型
https://www.fortinet.com/cn/resources/cyberglossary/types-of-cyber-attacks
20 common attack types with defense advice
2. Authoritative English glossaries (international standards, 10)
#
Resource
Link
Highlights
1
NIST Cybersecurity Glossary 🥇
https://csrc.nist.gov/glossary
10,113 entries , NIST official, updated through 2026-05-29
2
CISA/NICCS glossary
https://niccs.cisa.gov/resources/glossary
US government official, CSV download
3
NIST IR 7298 Rev.3
https://nvlpubs.nist.gov/nistpubs/ir/2019/NIST.IR.7298r3.pdf
Official PDF, terms extracted from NIST FIPS/SP series
4
SANS glossary
https://www.sans.org/security-resources/glossary-of-terms
A-Z grouped, from the world's top security training org
5
CyberGlossary (EN)
https://www.cyberglossary.org/en
Category browsing + full term list
6
SecurityElites, 1,506 entries
https://securityelites.com/glossary/
1,506 terms across 24 categories (app/cloud/crypto…)
7
Coursera cybersecurity terms
https://www.coursera.org/resources/cybersecurity-terms
Beginner-friendly, updated 2025-08
8
CyberExperts encyclopedia
https://cyberexperts.com/encyclopedia/
870 entries , focused on risk management & compliance
9
Cybersecurity Terms Lexicon
https://cybersecuritytermslexicon.com/
Concept-relationship oriented, not just listings
10
Fortinet cyber glossary
https://www.fortinet.com/cn/resources/cyberglossary
Vendor-maintained, has Chinese version, frequent updates
3. Acronym quick reference (high-frequency in attack & defense, 5)
4. Security frameworks & standards (8)
5. Chinese-English dictionaries (6)
6. Vulnerability classification & attack-pattern libraries (5)
7. Web security knowledge bases (3)
8. Chinese national standards (GB series, 5)
#
Standard
Name
Link
Highlights
1
GB/T 25069-2022
InfoSec technology — terminology
https://www.bzchaxun.com/view/8030070010000000.html
The most authoritative national standard , 176 pages, replaces the 2010 edition
2
GB/T 30279-2020
Vulnerability classification & rating guide
https://ndls.cnis.ac.cn/standard/detail/ca2cbe3e899d9d0c8c294300320f72fc
Vulnerability rating methodology
3
GB/T 22239-2019
MLPS (等保 2.0) baseline requirements
等保 2.0 core standard
Foundation of the MLPS regime
4
GB/T 25070-2019
MLPS security design requirements
等保 2.0 companion
Security design requirements
5
GB/T 28448-2019
MLPS assessment requirements
等保 2.0 companion
Assessment methodology standard
9. Security certifications & professional English (4)
🟢 Beginner (bootcamp students)
Step 1: CSDN jargon guide → learn the lingo (botnet, webshell, privesc, AV evasion)
Step 2: CN-SEC bilingual compendium → build the full framework
Step 3: Aliyun 100 terms → master high-frequency core terms
Step 4: GitHub acronym list → decode everyday unknown acronyms
🟡 Intermediate (practitioners)
Step 1: MITRE ATT&CK 中文版 → understand the attacker lifecycle
Step 2: CWE → master vulnerability classification
Step 3: NIST glossary → authoritative definitions for reports
Step 4: GB/T 25069-2022 → the domestic standards reference
Step 5: Web Security 学习笔记 → complete web security knowledge system
🔴 Expert (security researchers)
Step 1: CAPEC → attack patterns and their counters
Step 2: NVD / CVE → track the latest vulnerabilities
Step 3: NIST CSF 2.0 → enterprise security governance
Step 4: SecurityElites 1,506 terms → deep professional vocabulary
Step 5: MITRE ATT&CK (EN original) → cutting-edge TTPs
11. Penetration-testing tools (12)
Covers recon → scanning → exploitation → post-exploitation, organized by pentest lifecycle.
12. Vulnerability databases & intel platforms (12)
#
Resource
Link
Highlights
1
Seebug 🥇
https://www.seebug.org/
Run by Knownsec, 52,206+ vulns , 44,236 PoCs, China's authoritative vuln DB
2
Exploit-DB
https://www.exploit-db.com/
50,000+ exploits, shellcode, papers; offline via SearchSploit
3
NVD
https://nvd.nist.gov/
US official DB with CVSS and CPE impact analysis
4
CVE.org
https://www.cve.org/
The official CVE numbering program
5
CVE Details
https://www.cvedetails.com/
NVD data visualized: stats/vendor rankings/trends
6
Vulners
https://vulners.com/
Aggregates NVD/Exploit-DB/GitHub etc., free API
7
CVE Tools
https://cve.tools/
347,500+ CVEs , 65,400+ PoCs, 1,600+ CISA KEV, EPSS scores
8
VulnScope
https://vulnscope.dev/zh
Suite-centric CVE lookup, Chinese UI, 76,212 CVEs
9
milw00rm
https://milw00rm.com/
46,496 exploit scripts, graded Critical/High
10
CISA KEV
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
1,622 confirmed-in-the-wild vulns, CSV/JSON
11
expku
https://www.expku.com/
Chinese exploit library: remote/local/web/DoS
12
Vulnify
https://www.vulnify.com/
Open-source security tool search engine with filters
13. Online practice ranges (15)
#
Resource
Link
Highlights
Difficulty
1
HackTheBox 🥇
https://www.hackthebox.com/
World-class pentest training, 2M+ users, real machines
⭐⭐⭐⭐⭐
2
TryHackMe
https://tryhackme.com/
Guided paths, 500+ rooms, browser-based
⭐⭐
3
PentesterLab
https://pentesterlab.com/
Web pentest focus: SQLi/XSS/file upload
⭐⭐⭐
4
VulnHub
https://www.vulnhub.com/
VM-image-based practical ranges, highly realistic
⭐⭐⭐⭐
5
VulnStack (红日安全)
https://github.com/crow821/vulntarget
Internal-network range series simulating enterprise AD
⭐⭐⭐⭐⭐
6
攻防世界
https://adworld.xctf.org.cn/
China's mainstream CTF range, graded beginner→expert
⭐⭐
7
CTFHub
https://www.ctfhub.com/
CTF drills by type (SQLi/XSS/upload…)
⭐⭐
8
RootMe
https://www.root-me.org/
Renowned free CTF range: web/crypto/rev/network
⭐⭐⭐⭐
9
墨者学院
https://www.mozhe.cn/
Chinese range: web/hosts/DB/network/code audit
⭐⭐
10
封神台 (合天网安)
https://www.hetianlab.com/
Advanced Chinese ranges with real vuln reproduction, SRC scenarios
⭐⭐⭐⭐
11
HeaSecWebLab
https://github.com/HeaSec/HeaSecWebLab
85 standalone web ranges, HTTP basics → business-logic vulns, AI-assisted
⭐
12
DVWA
https://github.com/digininja/DVWA
Classic PHP vuln range, the beginner classic
⭐
13
SQLi-Lab / Upload-Lab / XSS-Lab
https://github.com/Audi-1/sqli-labs
Dedicated vuln-drill series, one at a time
⭐⭐
14
Vulhub
https://github.com/vulhub/vulhub
Docker vuln environments for hundreds of CVEs
⭐⭐
15
Vulfocus
https://github.com/cn360cn/vulfocus
Vuln integration platform, online reproduction
⭐⭐
14. Security communities & blogs (8)
15. Blue-team resources (8)
16. Awesome collections (7)
17. SRC / bug-bounty platforms (5)
18. Security certification tracks (6)
Appendix: quick lookup tables
Acronym
Full name
Chinese
APT
Advanced Persistent Threat
高级持续性威胁
CVE
Common Vulnerabilities and Exposures
公共漏洞与暴露
CWE
Common Weakness Enumeration
通用弱点枚举
CAPEC
Common Attack Pattern Enumeration and Classification
通用攻击模式枚举
CVSS
Common Vulnerability Scoring System
通用漏洞评分系统
OWASP
Open Web Application Security Project
开放式 Web 应用安全项目
SIEM
Security Information and Event Management
安全信息与事件管理
EDR
Endpoint Detection and Response
端点检测与响应
XDR
Extended Detection and Response
扩展检测与响应
SOAR
Security Orchestration, Automation and Response
安全编排自动化与响应
WAF
Web Application Firewall
Web 应用防火墙
IDS
Intrusion Detection System
入侵检测系统
IPS
Intrusion Prevention System
入侵防御系统
MFA
Multi-Factor Authentication
多因素认证
IAM
Identity and Access Management
身份与访问管理
PAM
Privileged Access Management
特权访问管理
SOC
Security Operations Center
安全运营中心
NGFW
Next-Generation Firewall
下一代防火墙
DDoS
Distributed Denial of Service
分布式拒绝服务
RCE
Remote Code Execution
远程代码执行
XSS
Cross-Site Scripting
跨站脚本攻击
CSRF
Cross-Site Request Forgery
跨站请求伪造
SSRF
Server-Side Request Forgery
服务端请求伪造
SQLi
SQL Injection
SQL 注入
XXE
XML External Entity
XML 外部实体注入
MITM
Man-in-the-Middle
中间人攻击
PoC
Proof of Concept
概念验证
Homepage screenshots of all 131 resources were auto-generated — view the full gallery:
👉 📸 View the full screenshot gallery (112 site screenshots)
📌 Screenshots auto-generated with Playwright + Chrome; they show homepage appearance only. Some sites may require login or render partially.
📌 Note : all resources are publicly accessible links worth bookmarking; some may require a proxy to reach. All links last verified 2026-07-21.
💡 Tip : consider adding this document to your team wiki (Feishu/Notion) for easy lookup.
Source-Available · All Rights Reserved
This project is source-available and all rights are reserved by the author. The code is provided for viewing and evaluation purposes only — access does not grant any right to copy, modify, redistribute, use commercially, or create derivative works. Unauthorized reuse may carry legal risk. Contact the author for explicit written permission before any other use.
本仓库为「源码可查、权利保留」项目(source-available / all-rights-reserved)。代码仅供查看与评估,未授权任何复制、再分发、修改、商用或衍生创作。擅自借用代码存在法律风险;如有需要请先联系作者获取明确书面许可。