Glossary

Short definitions of every term you meet in the EyalSec dashboard and this guide, in alphabetical order, each with a link to the page that explains it fully.

A to C

The terms from A to C.

Activity log

A record of actions on your account, with the time, action, target, IP address, how you were signed in, and the outcome; see Activity log.

The panel on the events page for a precise time range, a scope, and field-by-field conditions, beyond the quick filters in the toolbar. See Advanced search.

Agent

The part of EyalSec that runs on your computer or server, watches your program, and sends events to the dashboard. Each product is an agent for one language or platform, for example es-python for Python programs.

API key

A token, starting with es2_, that lets a script use the EyalSec API on your behalf without a browser sign-in. It is shown only once when you generate it, can be read-only, and can be revoked at any time; see API keys.

Backup code

A one-time code, shown when you set up two-factor authentication, that you can type instead of your authenticator app's code if you lose the device. See Backup codes.

Blacklist and whitelist

The two text filters on the events toolbar. A whitelist shows only the events that match its pattern; a blacklist hides the ones that match. See Filtering events.

Blocked event

An event you chose to stop seeing with the row menu's Block actions (this sink, this source, or one of its impact tags). Block is offered on es-chromium; es-python's row menu writes a rule instead. Blocked events are listed on the es-chromium Filters page, where you can unblock them; see Blocked events.

Build version

A label identifying exactly which EyalSec build a machine is running. The Machines page compares it with the newest build and shows up to date or newer build available; reinstalling takes the newer one. See Build badge.

Clone warning

A clone badge on a machine means its install was seen from a second computer, or showed signs of tampering. The machine's events are refused until you reinstall it; see Machine badges.

Command line

The command that started the program that produced an event, for example es-python app.py --port 8080. It is sent with each event by default, with secret-looking values masked; see Sent with each event.

Conditional

A sanitization result meaning the value was made safe in a way that holds only under some conditions. Such an event stays visible so you can judge it; see Suppressed events.

Configure

The modal, opened from a machine's row or the Filters page, where you choose which sources a machine watches, what is sent with each event, and its rules. See Configure.

Count

The number on an event row saying how many times that same event happened. Repeats of an event are counted on one row instead of filling the list; what counts as "the same" is set by Unique event. See Events.

CVE

Short for Common Vulnerabilities and Exposures, the public naming scheme for known security flaws (for example CVE-2021-44228).

D to M

The terms from D to M.

Dashboard

The EyalSec website you sign in to. It also names its first page, which summarizes your machines and recent events; see Dashboard.

Data flow

The block in an event's detail that shows how the untrusted value was built up on its way to the sink. See Event detail.

Default rules

The two Don't send rules every account starts with, with the patterns re and write. They drop matching events at the machine until you change or delete them; see Default rules.

Drop

The Don't send mode of a rule: the machine does not send matching events at all. A dropped event is never stored, cannot be recovered, does not count against your quota and is not billed. See Don't send.

es-python

The EyalSec Python runtime: you run your Python programs with es-python instead of python, and it reports what it finds. See Running es-python.

Event

One finding: a record that untrusted data from a source reached a sink in your program, with where it happened and what the value was. Events appear on the events page; see How it works and Events.

Events list

The events page for one product. Each product your account has gets its own list in the sidebar, folded into an Events group when you have more than three. See Events.

Foreign code

Python code loaded from a file that another user on the computer can change. Loading it is a risk because that user could change what your program does; the foreign source reports it. See foreign.

Global

Settings that apply to every machine of a product in your account, set on the Filters page. A machine's own setting overrides the global one; see Scope.

Impact tag

A short colored tag on an event, such as sqli or xss, naming the kind of attack the finding could allow; the color is that tag's severity. You can filter the events list by tag; see Filtering.

Install command

The one-line command the dashboard gives you to run on a computer, which installs the agent and links it to that machine. It works once and expires; see Install.

Label

A name and color you create and attach to events to sort them, such as "fixed" or "needs review". Labels work across all your events lists; see Labels.

Machine

One place where an EyalSec product runs and reports to your account, registered on the dashboard: usually a computer, server or container, and for some products a service, project or browser PC. Events are recorded per machine; see Machines.

Machine limit

How many machines your plan lets you have for each product. See Machine limit.

Map

A layout of the es-python events list that draws your events as a graph from sources through files to sinks, instead of a table. See Events map.

Masking

Replacing values that look like secrets (passwords, tokens, keys, URL passwords) with [masked] before an event is sent. See Masking.

Mode

What a rule does with the events it matches: Show or Hide (only change what you see), Don't send (drop) or Raise (block). See Rules.

N to R

The terms from N to R.

No plan yet

The state of a newly registered account before EyalSec sets up a plan: you can sign in, but you cannot add machines or see events. Contact sales to get set up; see No plan yet.

Note

Text you write and attach to one event, for example what you found when you looked into it. See Notes.

Old copy running

A warning on a machine meaning a program from an earlier install of that machine is still running. It can no longer send events; restart it under the current install. See Machine badges.

Origin

Where the untrusted data in an event came from, in more detail than the source: for example which connection or file it was read from. It appears in the event's detail; see Origin.

Plan

What your account includes: which products, how many machines, how many events per month, and whether Raise is allowed. Plans are set up by EyalSec sales; see Plans.

Product

One of the two EyalSec agents: es-python, which watches Python programs, and es-chromium, the EyalSec browser. Each product is enabled per account and has its own events list; see Products.

Public ID

A machine's shareable identifier, used by the dashboard and the API to refer to it. It reveals nothing secret, unlike the machine's token. See Machines.

Quota

The number of events (rows) each events list shows per calendar month on your plan. Repeats of an event already shown do not use it. Events past the quota are still recorded but stay hidden unless the quota is raised, and each new month starts with fresh room; see Event quota.

Raise

Blocking: instead of only reporting, the agent stops the risky operation, in es-python by raising a RuntimeError at that spot. It is a rule mode and must be enabled on your plan; see Report and Raise.

Report

The default behavior: the agent records the event and lets your program carry on unchanged. See Report.

Repr

The untrusted value itself, as text, as it looked when it reached the sink. It is shown in the event's Value column and detail, and the whitelist and blacklist filters match against it; see Event detail.

Row menu

The menu you open by right-clicking an event, or with its ⋮ button, to label it, add a note, or block similar events. See Row menu.

Rule

A setting that decides what happens to events matching a pattern: show them, hide them, stop them being sent, or block the action. Rules can be global or per machine; see Rules.

Rule template

A saved set of rules you can apply to a machine or your global settings in one step. EyalSec provides some and you can make your own; see Rule templates.

Run

One start of a program, from launch to exit. es-python tags each event with its run, so you can pick a run on the events page and see only what that invocation did; see Runs.

S to Z

The terms from S to Z.

Sanitized

Data that your program made safe before using it, for example by escaping it. EyalSec checks this for each event and says what it found in the Sanitization block; a value proven safe is suppressed. See Suppressed events.

A set of events filters you saved under a name so you can load it again later. See Saved searches.

Severity

How serious an event is: critical, high, medium, low or info. EyalSec works it out from what the event shows, and you can filter by it; see Severity.

Sink

A risky operation that untrusted data could misuse, such as running a shell command, building a database query or opening a file path. The event's name (its sink label) says which operation it was; see How it works.

Socket-only

A badge on some older es-python machines that can watch only network data. New machines are never socket-only; see Machine badges.

Source

Where untrusted data enters your program, such as the network (socket), files (file) or standard input (stdin). Every source is off until you switch it on; see How it works and Taint sources.

Stack trace

The chain of function calls that led to the risky operation, so you can find the line in your code. See Stack trace.

Status

Where a machine is in its setup: created (registered, not installed), pending (install started), installed (working) or failed. See Status.

Suppressed

An event hidden from the normal list because EyalSec found the data was made safe before it was used. Suppressed events are still stored; the Show control on the events page reveals them. See Suppressed events.

Taint

EyalSec's word for untrusted data: data that came from outside your program, such as network input or a file someone else can write. EyalSec follows it through your program to see where it ends up; see How it works.

Token

A machine's private credential, which its agent uses to prove which machine it is. It is never shown in the dashboard. Treat it like a password.

Two-factor authentication

A second step at sign-in, where you type a code from an authenticator app (or an emailed code, or a backup code) after your password. See Two-factor authentication.

Unique event

The setting that decides when a new detection is "the same" as an earlier one and only raises its count, and when it opens a new row. See Unique event.

Unset

A source or setting left without an explicit choice on a machine, so it follows the global setting (or the agent's own default). See Unset.

Something unclear or missing on this page? Email support@eyalsec.com.

EyalSec Pricing Docs Security Contact Login Book a live demo