50.5 SOC, law, AD, malware, mobile/IoT terms
BloodHound awareness, CERT-In, DPDP, CEH exam modules (this book’s preferred phrase for CEH topic maps), Android hygiene. Alphabetical. India context + ethics.
| Term | Meaning | मराठी अर्थ |
|---|---|---|
| Active Directory (AD) | Microsoft directory for users, groups, machines and Kerberos auth. | — (English madhech vapra) |
| Android hardening | Screen lock, updates, limited app sources, MDM mindset on OWN devices. | अँड्रॉइड कडक सुरक्षा |
| BloodHound | Graph tool for AD attack-path awareness (OWN lab AD only). | — (English madhech vapra) |
| Bug bounty (in-scope) | Paid/rewarded finding of weaknesses inside a published programme scope. | बग बाउंटी (फक्त व्याप्तीत) |
| CEH exam modules | Organised topic map for CEH-style study (this book maps chapters to modules). | — (English madhech vapra) |
| CERT-In | Indian Computer Emergency Response Team – advisories and reporting channel. | — (English madhech vapra) |
| DDoS | Distributed Denial of Service – flooding to hurt availability. | वितरित सेवा-इंकार |
| DPDP | Digital Personal Data Protection Act (India) – personal data duties (verify current text). | — (English madhech vapra) |
| IDS evasion | Techniques meant to slip past detectors (Blue tunes signatures / behaviour). | शोध चुकवणे |
| IoT / OT | Internet of Things / Operational Technology – devices and industrial controls. | — (English madhech vapra) |
| IT Act | Information Technology Act (India) – cyber offences and related duties (verify). | — (English madhech vapra) |
| Kerberos | Ticket-based authentication protocol used heavily in AD environments. | — (English madhech vapra) |
| Lateral movement | Moving from one compromised host to others inside a network. | बाजूने प्रसार |
| Responsible disclosure | Reporting a weakness privately to the owner with time to fix before publicity. | जबाबदार खुलासा |
| SCADA (awareness) | Industrial control monitoring class – segment OT; never “test” a live plant. | — (English madhech vapra) |
| Session hijacking | Stealing or predicting a session token to act as another user. | सत्र अपहरण |
| Written authorisation | Paper/email scope that allows a test – required before any offensive step. | अधिकृत परवानगी पत्र |
| Red team (attacker) does | Blue team (defender) detects / stops |
|---|---|
| Treats “bug bounty” as free licence on any site | Reads scope; out-of-scope = stop; responsible disclosure |
| Runs BloodHound against a client AD without paper | Only OWN AD lab; monitors unusual LDAP/Kerberos patterns |
| “Tests” SCADA / hospital IoT for fun | Never; segment OT; change defaults; authorised IR only |
Ravindra Bagale's Tip
CEH study = exam modules – rattlo topic map, control language. Bug bounty = in-scope only; random .in site hack = crime mindset. CERT-In / cybercrime.gov.in / 1930 helpline awareness = Blue citizen skill. Lakshat theva.
Lab
Write a half-page “responsible disclosure” practice email for a fictional bug found on Sahyadri Traders OWN Juice Shop (192.168.56.x) – severity, steps to reproduce, fix suggestion. Do not send it to any real company. Add one CERT-In awareness note in your notebook (verify official site).