Sycope dictionary

We understand how important it is to build the knowledge around the solution we offer - we provide you with extra insights that can help in using the Sycope solution more effectively.

Learn more
Newest additions
Check our vocabulary
Drill-down
A data analysis operation: stepping from a general value down to a more detailed level in a hierarchy; in network monitoring from alert, through flows, to packet.
Learn more >
EDR
Endpoint detection and response (EDR) is a security technology that monitors endpoints for suspicious activity. It detects threats, alerts defenders, and can isolate compromised devices.
Learn more >
Encrypted Traffic Analysis (ETA)
Threat-detection techniques that examine encrypted network traffic without decryption — using TLS metadata, fingerprinting (JA3/JA4), packet sizes and timing, and machine learning.
Learn more >
End User Experience Monitoring
A strategy for optimizing end-users' interactions, focusing on real-time analysis.
Learn more >
False Positive
A false positive is an incorrect alert that flags a safe email, file, or process as a threat. It matters because it can waste time and interrupt normal work.
Learn more >
Fast Flux
A technique where attackers rapidly change IP addresses of malicious servers, using a botnet to evade detection and takedown efforts.
Learn more >
Firewall / NGFW
A network security system that monitors and filters incoming and outgoing traffic based on rules. An NGFW adds deeper inspection of applications and threats to block advanced attacks.
Learn more >
FlowSpec
A BGP extension that distributes precise traffic filtering rules across the network, each with an action (drop, rate-limit, or redirect); used for accurate DDoS mitigation.
Learn more >
Honeypot
A honeypot is a decoy system set up to attract cyberattacks. It helps defenders detect threats and study attacker behavior in a controlled environment.
Learn more >
HTTP / HTTPS
Protocol a browser uses to fetch web resources via request–response (port 80). HTTPS is the same protocol inside a TLS tunnel (port 443): confidentiality, integrity, server identity.
Learn more >
HTTP Flood
HTTP Flood is a DDoS attack overwhelming servers with massive volumes of legitimate-looking HTTP requests from thousands of bots.
Learn more >
ICMP
Network-layer protocol that carries error messages and control information about IP packets; the basis for the ping and traceroute tools.
Learn more >