An attack glossary is a reference collection that defines attack types in consistent language and links them to common questions, signals, and defender actions. It helps security teams standardise terminology, improve analyst communication, and recognise recurring threat patterns across incidents and research.
What an attack glossary is used for
An attack glossary gives defenders a shared vocabulary for attack types, so teams can describe threats consistently, compare incidents more reliably, and avoid talking past one another during triage, reporting, and research.
It is especially useful when security work involves many overlapping labels for the same behaviour. A glossary reduces ambiguity by anchoring terms to common signals, attacker objectives, and defender responses, which makes communications between analysts, responders, and architects faster and more precise.
How an attack glossary supports detection and analysis
A strong glossary does more than define words. It helps analysts map an observed event to a broader pattern, such as credential theft, lateral movement, phishing-led compromise, or abuse of exposed services. That mapping improves consistency when a team records cases, writes detections, or compares one incident with another.
It also creates a bridge between plain-language reporting and technical investigation. When a report says an activity pattern resembles a known attack class, investigators can move from the label to the likely techniques, supporting telemetry, and the next questions they should ask.
That usefulness is why attack terminology often sits alongside adversary knowledge bases and incident advisory material, such as MITRE ATT&CK Enterprise Matrix, which helps teams connect observed behaviour to known techniques. For AI-targeted threats, MITRE ATLAS adversarial AI threat matrix plays a similar role for model and agent attack patterns.
Why standardised attack language matters
In practice, the value of an attack glossary is organisational as much as technical. The same incident can be described differently by threat intelligence, SOC, incident response, and risk teams unless there is a shared reference point. A glossary reduces that drift and makes recurring patterns easier to track over time.
Standard language also helps with trend analysis. When defenders classify attacks consistently, they can compare frequency, severity, and control failures across many cases without reinterpreting each report from scratch. That makes the glossary a knowledge layer, not just a dictionary.
For defenders who want a broader operational lens on repeated attack patterns, CISA cyber threat advisories are a useful companion because they translate current threat activity into practical defensive context.
What makes a good attack glossary entry
A useful entry should be specific enough to distinguish one attack type from another, but general enough to survive changing tooling and tactics. It should describe the core behaviour, the common indicators or signals, and the defender actions that normally follow. Definitions that are too narrow become obsolete; definitions that are too broad stop being useful.
Good glossaries also avoid overloading a single term with multiple meanings. If a label is contested across vendors or communities, the glossary should say so plainly and define the local usage being adopted. That prevents the glossary from becoming another source of ambiguity.
Because attack terminology often overlaps with access control, credential abuse, and compromise patterns, a glossary also benefits from broader control references such as NIST SP 800-53 Rev 5 Security and Privacy Controls and NIST Cybersecurity Framework 2.0, which help connect attack classes to governance, detection, and response practice.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and MITRE ATLAS address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | Enterprise Matrix — Enterprise Matrix | Defines adversary techniques that attack glossaries map and standardise. |
| Recommendation — Map glossary attack types to ATT&CK techniques to improve detection and response consistency. | ||
| MITRE ATLAS | ATLAS Matrix — Adversarial AI Threat Matrix | Defines AI attack patterns that extend attack glossaries into AI threat language. |
| Recommendation — Use ATLAS terminology to classify AI attack patterns consistently across teams. | ||
| CIS Controls v8 | CIS-5 — Account Management | Attack glossaries often connect attack classes to credential abuse and access failure modes. |
| Recommendation — Use CIS-5 to align attack terms with account abuse and access-control remediation. | ||
| NIST CSF 2.0 | DE.CM-01 — Monitoring for unauthorized personnel, connections, devices, and software | Attack glossaries support consistent monitoring language for recurring threat signals. |
| RS.AN-01 — Investigations are conducted to ensure effective response and support forensics | Attack glossaries help analysts investigate and compare incidents using shared labels. | |
| Recommendation — Use DE.CM-01 to standardise how recurring attack signals are named and monitored. Use RS.AN-01 to anchor incident analysis to consistent attack terminology. | ||