Reference · Glossary
Glossary
Every term we use in outside readings and assessments, in one sentence each. Patterns are grouped at the end.
Terms 14Patterns 14By LeakTrace
Email authentication4 terms
Business Email Compromise (BEC)
Business email compromise: a fraud in which someone poses as a trusted person by email to redirect a payment.
Term
DKIM
A signature added to each email that proves it was sent by your domain and not changed on the way.
Term
DMARC
A published rule telling mail servers what to do with email that fails your domain’s checks.
Term
SPF
A list, published in your domain’s records, of the servers allowed to send email for your domain.
Term
Exposure5 terms
Credential exposure
A work address and a password used with it appear in a breach database someone else can read.
Term
Dark web monitoring
The industry term for watching criminal marketplaces, forums and paste sites for a person’s or firm’s details.
Term
Data broker
A company that collects and resells personal details such as home addresses, phone numbers and relatives.
Term
EASM
External attack surface management: finding and re-checking everything a firm exposes to the internet, from outside.
Term
Domains3 terms
Advisor tenant
An outside adviser, such as an accountant, lawyer or broker, whose email and systems handle a client’s information or payments.
Term
Wire-fraud precursor
A public sign that someone is preparing a payment fraud against a firm, seen before any money moves.
Term
Evidence2 terms
Attribution
Tracing a hostile website, account or campaign back to the person or group running it.
Term
Chain of custody
A documented record of who collected a piece of digital evidence, when and how, and everyone who handled it after.
Term
Patterns14 patterns
The openings we find most often from outside, each with a check anyone can run and the direction of the fix.
Outside adviser with no DMARC on its sending domain
A firm’s accountant, lawyer or broker sends mail from a domain with no DMARC policy, so email in that adviser’s name can be forged to ask the firm for a payment.
Third-party / vendor risk
API keys committed to public GitHub repositories
Employee or contractor GitHub accounts host public repositories containing plaintext API keys, cloud credentials, or database connection strings for the corporate tenant.
Code / repository leak
Application admin panel exposed to the public internet
A CMS or application admin login page (WordPress, Django, phpMyAdmin, GitLab, custom SaaS) is reachable from any IP without authentication gating, IP allowlisting, or VPN.
Infrastructure
Credentials in monitored breach databases reused on production login
Employee credentials appearing in monitored breach databases are still active on the corporate SSO or VPN, giving attackers a direct password-spray path.
Credential exposure
Departed employee retains SSO or SaaS access post-departure
A former employee's corporate SSO, individual SaaS accounts, or personal-device-linked corporate app access remains active after their departure date.
Insider threat
DKIM signing absent on the primary mail sender
A domain's outbound mail is not cryptographically signed, so receivers cannot verify integrity or authenticity beyond IP-based SPF.
Email authentication
Executive email addresses harvested from paste sites
Public paste-site archives contain executive email addresses paired with breached passwords, providing an off-the-shelf target list for BEC.
Paste site leak
Exposed .git directory on a production web server
A production web server exposes its `.git/` directory over HTTP, allowing anyone to reconstruct the full source tree, including secrets committed to history.
Code / repository leak
Lookalike domain registered against the corporate brand
A recently-registered domain uses a visual or typographical variation of the corporate name (typo-squat, IDN homograph, tenant-suffix squat) and is likely being staged for wire-fraud pretext.
Phishing infrastructure
Public TLS certificate approaching expiry without automated renewal
A production-facing TLS certificate is within the browser warning window and shows no evidence of ACME/auto-renewal, risking a hard outage and browser trust warnings.
Infrastructure
S3 bucket permissions allowing anonymous list
A production or backup S3 bucket is configured to allow anonymous LIST operations, exposing the object inventory (and often the object contents) to any unauthenticated caller.
Cloud misconfiguration
SPF configured without DMARC alignment
A domain publishes an SPF record but no DMARC policy, leaving receivers with no instruction on how to handle unauthenticated mail.
Email authentication
Subdomain takeover risk on abandoned CNAME
A DNS CNAME record points to a third-party service (Heroku, S3, GitHub Pages, Zendesk, etc.) that no longer claims the subdomain, allowing anyone to register it and impersonate the parent domain.
Infrastructure
Unmaintained marketing vendor with historical corporate data access
A marketing, analytics, or engagement vendor that once had customer or employee data access remains contracted (paying) or connected (integration live), despite no active use, extending the exposure surface.
Supply chain
See what is open from outside before anyone else does. Check my firm →