How can
we help?
Want to know more about Uptycs? Curious about cloud native security? Maybe you’d like to know more about unified CNAPP and XDR? Well, you’ve come to the right place.
Master Glossary
Organized into five sections, Cybersecurity Platforms and Management, Cybersecurity Operations and Processes, Telemetry and Analytics, AI-Native Security and Investigation, and Security Monitoring and Compliance, this guide provides a practical reference for securing modern cloud and hybrid environments.
This section covers terms related to various platforms and management strategies used to safeguard applications, data, and infrastructure in cloud and hybrid environments. It includes concepts like Cloud-Native Application Protection Platforms (CNAPP), Cloud Workload Protection Platforms (CWPP), and Zero Trust Architecture.
- Application Security Posture Management
A security approach that identifies, correlates, and prioritizes application risks across the software development lifecycle. ASPM brings together findings from code, cloud configurations, identities, workloads, runtime activity, and other sources to help teams focus remediation on the risks that matter most. - Cloud Detection and Response (CDR)
Cloud Detection and Response continuously analyzes cloud activity to identify anomalous or malicious behavior. Uptycs CDR correlates activity across cloud APIs, workloads, and threat intelligence to deliver higher-fidelity detections and support faster investigation and response. - Cloud Infrastructure Entitlement Management (CIEM)
Manage cloud permissions by identifying excessive access, visualizing identity relationships, and supporting least privilege. CIEM helps teams detect identity misconfigurations, privilege escalation paths, credential exposure, and other access risks. - Cloud Security Posture Management (CSPM)
Cloud Security Posture Management continuously identifies and helps remediate cloud misconfigurations, vulnerabilities, compliance gaps, and risky resource relationships. CSPM provides ongoing visibility into cloud assets and configuration changes across AWS, Microsoft Azure, and Google Cloud. - Cloud Workload Protection Platform (CWPP)
A Cloud Workload Protection Platform protects workloads across cloud, hybrid, and multi-cloud environments. CWPP capabilities can include workload visibility, vulnerability management, runtime threat detection, malware detection, and protection for virtual machines, containers, and serverless workloads. - Cloud-Native Application Protection Platform (CNAPP)
A Cloud-Native Application Protection Platform is a unified suite of security capabilities designed to protect cloud applications and infrastructure across the development and runtime lifecycle. CNAPP brings together capabilities such as CSPM, CWPP, CIEM, vulnerability management, and cloud detection and response to reduce security silos and provide connected risk context. - DevSecOps
The practice of integrating security into every phase of the software development lifecycle, fostering collaboration between development, security, and operations teams. - Endpoint Security
The technologies and practices used to protect endpoint devices, including laptops, desktops, and servers, from threats, vulnerabilities, and unauthorized activity. Uptycs extends endpoint visibility and security across developer systems and the workloads they access and support. - Ephemeral Infrastructure
Infrastructure in which workloads, containers, instances, or other resources are created and destroyed dynamically, often existing for only short periods. Because these resources change rapidly, effective security requires continuous visibility rather than point-in-time assessment alone. - Extended Detection and Response (XDR)
Extended Detection and Response unifies security data across multiple sources to improve threat detection, investigation, and response. Uptycs XDR provides visibility from the developer laptops used to build applications to the Linux servers and other workloads that run them, supporting threat detection, vulnerability management, security hygiene, compliance, and remediation. - Hybrid Cloud Security
Measures and solutions implemented to secure applications, data, and infrastructure in a hybrid cloud environment that combines on-premises and cloud-based resources. - Identity Federation
A method for securely sharing identity information across different organizations or systems, enabling users to access multiple services using a single set of credentials. Identity federation simplifies authentication in hybrid and multi-cloud environments while maintaining security and user convenience. - Kubequery
An extension of osquery designed specifically for Kubernetes environments to enhance security and visibility. - Managed Detection and Response Services (MDR)
Managed Detection and Response provides continuous security monitoring, investigation, and response support through an external team of security professionals. Uptycs Managed Services can extend internal security operations with round-the-clock detection and response across an organization’s attack surface. - osquery
An open-source operating system instrumentation framework that exposes operating system data through a SQL-based query language. Security and IT teams can use osquery to collect and investigate endpoint and workload data for security, compliance, asset management, and operational use cases. - Security Automation and Orchestration (SOAR)
Platforms that integrate and automate security operations, incident response, and threat intelligence to streamline workflows and enhance threat detection and remediation capabilities. SOAR enables teams to focus on critical issues by reducing manual effort and improving operational efficiency. - Shift Up Security
A cybersecurity methodology focused on eliminating tool, team, and infrastructure silos through a unified approach to security operations, data, and intelligence. - Single Sign-On (SSO)
An authentication technology that allows users to access multiple applications or systems with a single set of login credentials. SSO enhances user experience by eliminating the need for repeated logins while reducing password management risks. - Zero Trust Architecture
A security architecture based on the principle that no user, device, workload, or connection should be trusted automatically. Access is continuously evaluated using identity, device, context, and policy, with least privilege applied to reduce unnecessary exposure.
Understanding operations and processes in cybersecurity is important for effective threat management and incident response. This section introduces terms such as Computer Security Incident Response Teams (CSIRT), Threat Hunting, and Vulnerability Management, along with methodologies like Shift Left Security Controls and Risk Prioritization.
- Attack Path Analysis
The process of identifying and analyzing the connected weaknesses, permissions, exposures, and relationships an attacker could use to reach a critical asset. Uptycs combines attack path context with real-time security signals to help teams prioritize the risks most likely to lead to compromise. - Behavior-Based Threat Detection
A detection approach that identifies suspicious or malicious activity by analyzing deviations from expected workload, process, identity, or network behavior rather than relying exclusively on known signatures or static rules. - Behavioral Detection
A detection method that identifies potentially malicious activity by analyzing behaviors and changes rather than relying only on known signatures. Behavioral detection can reveal unusual user, process, network, endpoint, or workload activity across hybrid environments. - Build-to-Runtime Provenance
The ability to trace a vulnerability, security finding, or runtime threat back through the software development pipeline to its source, such as a code commit, image layer, or third-party dependency. This context helps security and development teams investigate root causes and remediate issues at the source. - Cloud Compliance
Ensuring that cloud environments and operations adhere to relevant regulatory and industry standards and best practices. - Code-to-Cloud Security
A security approach that connects risks and activity across source code, build pipelines, cloud configurations, deployed workloads, and runtime behavior. Code-to-cloud context helps teams trace security findings to their origin and remediate issues at the appropriate point in the development lifecycle. - Computer Security Incident Response Team (CSIRT)
A team responsible for preparing for, investigating, containing, and helping organizations recover from cybersecurity incidents. CSIRTs rely on accurate, timely information to determine an incident’s scope, severity, affected assets, and required response actions. - Infrastructure as Code (IaC) Security
The practice of reviewing Infrastructure as Code templates and deployment configurations for vulnerabilities, misconfigurations, compliance violations, and security policy issues before infrastructure is provisioned. - Internet Exposure
The vulnerabilities that arise from misconfigured cloud resources, such as EC2 instances with overly permissive security settings, which serve as entry points for attackers. - Lateral Movement
The concept of lateral movement stems from the understanding that modern networks typically comprise numerous interconnected devices and systems. Once an attacker manages to breach the perimeter security or gains initial access to one machine, their goal is to stealthily navigate through the network, moving laterally from one device to another and progressively escalating their privileges. - Post-Exploit Detection
The identification of malicious activity that occurs after an attacker has successfully exploited a vulnerability or gained initial access, including privilege escalation, lateral movement, persistence, and unauthorized process execution. - Proactive Threat Hunting
Actively searching for signs of malicious activity within an environment, beyond automated alerts. - Risk Prioritization
A unified approach to evaluating and ranking security risks using multiple sources of context, including posture findings, vulnerabilities, identities, attack paths, business importance, and runtime activity. This helps teams focus remediation on risks that are both exploitable and consequential. - Supply Chain Security
The practice of securing the end-to-end software development and delivery pipeline, including dependencies, third-party components, and build systems. Supply chain security aims to prevent tampering, unauthorized code insertion, and vulnerabilities in the software supply chain. - Threat Hunting
The proactive process of searching security data for evidence of malicious or suspicious activity that may not have triggered an automated alert. Threat hunters form hypotheses, query current and historical telemetry, and investigate patterns that could indicate compromise. - Threat Intelligence Matches
Correlating observed activities within an organization's environment with known threat intelligence data to identify potential threats. - TTPs (Tactics, Techniques, and Procedures)
Patterns of behavior used by cyber adversaries, including methods of attack and tools used. - Uptycs Academy
Uptycs Academy provides training, guidance, and resources that help users strengthen their knowledge of the Uptycs platform, improve productivity, and apply its capabilities effectively. - Uptycs Security Policies
Rules and controls configured within the Uptycs platform to identify, monitor, and respond to security, compliance, and configuration conditions across supported environments. - Vulnerability Management
Full vulnerability lifecycle management from build to runtime across servers, hosts, containers, VMs, and serverless.
Telemetry and analytics play a key role in monitoring and analyzing security data to detect and respond to threats. This section provides insights into terms like Security Analytics, Cloud-Based Security Analytics, and Unified Data Models, as well as tools like Flight Recorder and YARA Rule Scanning.
- Bloatware
Refers to pre-installed software that takes up excessive storage and system resources without providing meaningful value. It often slows down device performance and occupies space with unnecessary apps or trial programs. - CI/CD Process Security
The implementation of security measures within Continuous Integration and Continuous Deployment pipelines to ensure the integrity and security of code throughout the development lifecycle. - CIS Benchmarks
Consensus-based configuration guidelines developed by the Center for Internet Security to help organizations securely configure operating systems, cloud services, applications, containers, and other technologies. - Cloud-Based Security Analytics
Security analysis conducted in the cloud, leveraging cloud resources for data processing, threat detection, and response. - Container Runtimes
Software responsible for running and managing containers on a host system. Monitoring container runtime activity helps security teams identify threats such as container escapes, privilege escalation, malicious processes, and unauthorized changes. - Flight Recorder
A continuously maintained record of system and workload activity that enables teams to investigate current and historical security events, reconstruct timelines, and analyze activity that occurred before an alert was generated. - Kubernetes Security Posture Management (KSPM)
Tools and practices used to continuously assess and improve the security posture of Kubernetes clusters, workloads, configurations, identities, and policies. KSPM helps identify misconfigurations, compliance gaps, excessive permissions, and risks affecting namespaces, pods, nodes, and container images. - Live and Historical Query Investigations
The ability to perform real-time and retrospective analysis of system data to identify security incidents or performance issues. - Managed Container Orchestration Platforms
Services that simplify the deployment, scaling, and management of containerized workloads, including Amazon EKS and ECS, Microsoft AKS, Google GKE, and Red Hat OpenShift. - Query Packs
Predefined sets of queries in osquery to automate the collection and analysis of security data. - Runtime Telemetry
Data collected from workloads while they are actively running, including process execution, network activity, system behavior, file changes, identity activity, and other events. Runtime telemetry provides the evidence needed to detect and investigate threats based on actual workload behavior. - Scalability
The ability of a system or service to increase or decrease resources as workloads, data volumes, or operational requirements change without significantly affecting performance or reliability. - SDLC Policy Controls
Security measures integrated into the Software Development Life Cycle (SDLC) to ensure compliance with security policies and best practices. - Security Analytics
The use of data collection, aggregation, and analysis tools to detect and respond to security threats in real time. - Security Graph
A data model and visual representation of relationships among cloud resources, workloads, identities, vulnerabilities, and other security entities. Uptycs Security Graph helps teams understand connected risks, identify attack paths, and investigate how individual findings relate to the broader environment. - Self-managed Kubernetes
Kubernetes clusters that are deployed, managed, and maintained by an organization's internal team rather than by a third-party provider. - Serverless Technologies
Cloud services that allow developers to build and run applications without managing server infrastructure, such as AWS Lambda and Azure Functions. - Service Mesh
A dedicated infrastructure layer that controls service-to-service communication over a network, offering features like load balancing, encryption, and observability. - Structured Telemetry
Telemetry collected and organized using consistent schemas so it can be searched, correlated, and analyzed across security domains. Structured telemetry supports real-time detection, machine learning, and natural-language investigation without requiring extensive data transformation. - Telemetry
The automated collection and transmission of data about system, application, identity, network, cloud, or workload activity for monitoring, analysis, detection, and investigation. - Unified Data Model
A standardized structure that normalizes information from different sources so it can be consistently searched, correlated, analyzed, and reported across security domains. - YARA Scans
Scans that use YARA rules to identify files, processes, or memory patterns associated with malware and other suspicious activity.
AI-Native Security and Investigation
Artificial intelligence is increasingly integrated into cybersecurity platforms to help teams interpret complex data, investigate threats, and make faster decisions. This section covers AI-assisted security analysis, verifiable findings, ontology-driven reasoning, and the technologies that help AI operate with relevant security context.
- Agentic Investigation
An investigation approach in which an AI system develops a plan, executes queries, evaluates the results, tests multiple hypotheses, and adjusts its next steps as new evidence becomes available. - AI-Assisted Investigation
The use of artificial intelligence to help security analysts interpret findings, correlate signals, generate and execute queries, test hypotheses, reconstruct activity, and identify evidence relevant to an investigation. - AI-Native Security
An architectural approach in which artificial intelligence is integrated into a security platform’s data, context, analytics, and investigation layers rather than added as a separate interface or feature. AI-native security relies on structured, connected, and queryable security data to support analysis and decision-making. - AI Security Architecture
The underlying design used to structure, normalize, connect, and query security data for AI-driven analysis. A strong AI security architecture enables AI systems to reason across cloud, endpoint, identity, Kubernetes, container, and runtime environments while supporting traceable and verifiable conclusions. - AI Security Posture Management (AI-SPM)
A continuous approach to discovering AI-related assets, assessing their configurations, exposure, access, data usage, and dependencies, and prioritizing security and governance risks across the AI lifecycle. AI-SPM covers models, data, services, development pipelines, and the cloud infrastructure that supports them, and works alongside CNAPP and other security controls. - Cybersecurity Ontology
A formal, machine-readable model of security entities and their relationships across domains such as cloud infrastructure, endpoints, Kubernetes, containers, workloads, processes, and identities. A cybersecurity ontology gives AI systems consistent context for correlating data and reasoning across an environment. - Dynamic Reasoning
The process by which an AI system develops and adapts an investigation plan based on the evidence it discovers. Dynamic reasoning allows the system to test hypotheses, rule out possibilities, and determine the next appropriate query or action rather than following a fixed workflow. - Glass-Box AI
An AI approach that makes the evidence, queries, data sources, hypotheses, and reasoning behind its conclusions visible and inspectable. Glass-box AI allows analysts to examine how an answer was reached rather than accepting an unexplained output. - Juno AI Analyst
Uptycs’ integrated, verifiable AI security analyst that helps teams investigate detections, understand risk, correlate signals, and reach evidence-backed conclusions. Juno exposes the supporting queries, data, and reasoning so analysts can review and verify its findings. - Verifiable Security AI
Security AI that supports its findings with inspectable evidence, queries, source data, and reasoning so analysts can understand, reproduce, and validate how a conclusion was reached.
Effective security monitoring and compliance are necessary for maintaining the integrity and security of cloud and container environments. This section includes terms such as Real-time Container Security Visibility, Infrastructure as Code (IaC) Scans, and Compliance Automation, highlighting the importance of continuous monitoring and adherence to security policies.
- Access Request Tracking
Monitoring and logging requests for access to cloud resources to ensure proper authorization and traceability. - Audit Checks
Systematic reviews and evaluations of cloud resources and configurations to ensure compliance with security policies and standards. - Automatic Threat Detection and Response
The use of analytics, behavioral detections, policies, and automated workflows to identify threats and initiate appropriate response actions. Automation can help security teams reduce manual effort, contain threats faster, and apply consistent response procedures. - Best-Practice Guardrails
Predefined policies and controls designed to enforce industry best practices within cloud environments. - Centralized Visibility and Control
A unified interface for monitoring and managing security across multiple cloud environments and services. - Cloud-Native Security Principles
Foundational strategies designed to secure cloud-native environments by leveraging principles like least privilege, zero trust, and automation. - Cloud Anomaly Detection
The identification of unusual cloud activity, behaviors, or configuration changes that deviate from expected patterns and may indicate a security threat, compromised identity, or policy violation. - Cloud IAM Policy Analysis
Uptycs evaluates the identity risk posture of your cloud accounts by analyzing cloud identity and access management (IAM) policies, considering factors such as credential rotation, potential privilege escalation, and credential exposure. - Compliance Automation
The use of automated assessments, monitoring, evidence collection, and reporting to help organizations continuously evaluate their environments against regulatory, industry, and organizational requirements. - Configuration and Settings Monitoring
The process of overseeing and verifying cloud configurations and settings to ensure compliance and security. - Continuous Workload Visibility
Continuous insight into processes, network activity, system behavior, and other events occurring within active hosts, containers, serverless functions, and cloud workloads. It enables teams to understand how workloads behave after deployment rather than relying only on periodic scans or configuration snapshots. - Credential Escalation
The process by which attackers increase their access privileges within a compromised environment, often by exploiting misconfigurations or vulnerabilities. - Credential Exposure Analysis
Assessing the risk of credentials being exposed to unauthorized entities, potentially leading to security breaches. - Credential Rotation Monitoring
Keeping track of how often and effectively credentials are rotated to minimize the risk of compromise. - Custom Compliance Checks
Tailored assessments that ensure cloud environments meet specific regulatory and organizational compliance requirements. - Data Exfiltration
The unauthorized transfer of data from a compromised system to an external location controlled by the attacker. - Data Privacy
The practice of ensuring that personal and sensitive data is collected, stored, and processed in compliance with legal and regulatory frameworks, such as GDPR and CCPA. Data privacy focuses on protecting individuals' rights and maintaining transparency in how data is used. - Data Security
Measures and technologies implemented to protect data from unauthorized access, alteration, or destruction. Data security encompasses encryption, access controls, and other safeguards to ensure the confidentiality, integrity, and availability of information. - Graphical Kubernetes Overview
A visual representation of a Kubernetes environment, displaying the relationships and status of various components such as nodes, pods, and services. - Historical Trend Data
The analysis of past data to identify patterns and trends in cloud resource usage and security incidents. - Identity Misconfiguration Detection
Identifying incorrect or risky configurations in identity and access management settings that could lead to security breaches. - Identity Relationship Mapping
Visualizing and analyzing the relationships between different identities and their access rights within a cloud environment. - Identity Risk Posture
An assessment of the overall security risk associated with an organization's identity and access management practices. - Incident Response Playbooks
Documented procedures outlining steps to take during a security incident to respond effectively. - Indicators of Compromise (IoC)
Data points or evidence that suggest a system may have been breached or is under attack, used for threat detection and response. - Infrastructure as Code (IaC) Scans
Automated checks of IaC configurations to detect and remediate security vulnerabilities and misconfigurations in infrastructure provisioning scripts. - Insights Dashboards
Visual interfaces that present security findings, trends, assets, and operational metrics to help teams monitor their environment and identify issues requiring attention. - Least Privilege Implementation
Ensuring that users and services have the minimum level of access necessary to perform their functions, reducing the risk of security incidents. - Namespace, Pod, and Image Risk Assessment
The evaluation of security risks associated with Kubernetes namespaces, pods, and container images to identify and mitigate potential vulnerabilities. - OPA Gatekeeper Policy Controls
The use of Open Policy Agent (OPA) Gatekeeper to enforce security and compliance policies within Kubernetes environments. - Privilege Escalation
The process of gaining permissions beyond those originally granted, often by exploiting vulnerabilities, misconfigurations, excessive access, or compromised credentials. - Privilege Escalation Detection
Identifying attempts to gain unauthorized access to higher privilege levels within a cloud environment. - Real-Time ATT&CK-Mapped Detections
Behavioral detections mapped to the MITRE ATT&CK framework to help teams understand the tactics and techniques associated with suspicious activity and guide investigation and response. - Real-time Cloud Inventory
Continuous tracking and management of cloud resources to provide up-to-date information about all assets within a cloud environment. - Real-time Container Security Visibility
The capability to monitor and analyze the security status of containers in real time, identifying potential threats and vulnerabilities as they occur. - Resource Relationship Analysis
Examination of how different cloud resources interact and relate to one another to identify potential security risks and dependencies. - Runtime Security
The continuous monitoring and protection of applications, containers, hosts, and cloud workloads while they are actively running. Runtime security detects malicious processes, credential misuse, suspicious network activity, exploitation attempts, lateral movement, and other threats that may not be visible through pre-deployment scans or posture assessments. - Runtime Threat Detection
The identification of malicious or suspicious activity as it occurs within active applications, containers, hosts, or cloud workloads. It uses runtime behavior and contextual signals to detect threats that may bypass preventive or static controls. - Shift Left Security Controls
Security practices integrated early into the software development process, enabling the identification and resolution of security issues before deployment. - Software Development Lifecycle (SDLC) Security
Security measures implemented throughout the software development lifecycle to ensure code integrity and compliance with security policies. - Unified API Monitoring
The centralized monitoring and analysis of API activity across cloud services to identify suspicious behavior, unauthorized access, configuration issues, and potential security threats. - Vulnerability Prioritization
The process of evaluating vulnerabilities using factors such as severity, exploitability, asset exposure, runtime activity, business importance, and attack paths to determine which issues should be remediated first. - YARA Rule Scanning
Scans that use built-in or customized YARA rules to identify files, processes, or memory patterns associated with malware and other suspicious activity during incident response.
