Are you a Security Analyst, SOC Engineer, or Cybersecurity Auditor looking to strengthen
your technical vocabulary and sharpen your response skills?
Download our free SOC Terminology eBook – your go-to guide to understanding the
most critical terms, tools, and techniques used in modern Security Operations Centres
(SOC).
What is in it for me?
• Clear definitions of 100+ essential SOC and cybersecurity terms
• Enhanced understanding of SIEM, SOAR, UEBA, and incident response tools
• Better audit preparation and effective communication with SOC teams
• Boost in confidence for interviews, compliance assessments, and certifications
• Ideal reference for SOC analysts, cybersecurity auditors, risk teams, and
students
Table of Contents
1. SOC (Security Operations Center)................................................................... 5
2. SIEM (Security Information and Event Management) ........................................ 5
3. Incident Response ......................................................................................... 5
4. Threat Intelligence ......................................................................................... 6
5. EDR (Endpoint Detection and Response) ......................................................... 6
6. Indicators of Compromise (IoCs) .................................................................... 6
7. Firewall ......................................................................................................... 7
8. IDS/IPS (Intrusion Detection/Prevention System) ............................................. 7
[Link] +919604647000 centermanager@[Link]
9. SOAR (Security Orchestration, Automation, and Response) .............................. 7
10. Phishing ...................................................................................................... 8
11. Log Management ......................................................................................... 8
12. Playbook ..................................................................................................... 8
13. False Positive .............................................................................................. 9
14. Security Monitoring ...................................................................................... 9
15. Vulnerability Assessment ........................................................................... 10
16. UEBA (User and Entity Behavior Analytics) ................................................... 10
17. Threat Hunting ........................................................................................... 10
18. MDR (Managed Detection and Response) .................................................... 10
19. XDR (Extended Detection and Response) .................................................... 11
20. SOC Analyst .............................................................................................. 11
21. Risk Assessment ....................................................................................... 11
22. Asset Inventory .......................................................................................... 12
23. Data Loss Prevention (DLP)......................................................................... 12
24. Compromise Assessment .......................................................................... 13
25. Incident Ticket ........................................................................................... 13
26. Alert Fatigue .............................................................................................. 13
27. DNS Sinkhole ............................................................................................ 14
28. Whitelisting ............................................................................................... 14
29. Blacklisting ............................................................................................... 14
30. Triage ........................................................................................................ 15
31. Network Forensics ..................................................................................... 15
32. Patch Management .................................................................................... 15
33. Security Baseline ....................................................................................... 15
34. DDoS (Distributed Denial of Service) ........................................................... 16
35. Red Team .................................................................................................. 16
36. Blue Team ................................................................................................. 16
37. Purple Team .............................................................................................. 17
38. Insider Threat ............................................................................................ 17
39. Security Policy ........................................................................................... 17
40. Compliance Reporting ............................................................................... 18
[Link] +919604647000 centermanager@[Link]
41. Business Continuity ................................................................................... 18
42. Penetration Testing .................................................................................... 18
43. SOC Manager ............................................................................................ 18
44. Asset Discovery Tool .................................................................................. 19
45. Malware Sandbox ...................................................................................... 19
46. Zero-Day ................................................................................................... 19
47. Attack Surface ........................................................................................... 20
48. Incident Containment ................................................................................ 20
49. IOC (Indicator of Compromise) Feed ........................................................... 20
50. Security Awareness Training ....................................................................... 21
51. Kill Chain .................................................................................................. 21
52. Lateral Movement ...................................................................................... 22
53. Privilege Escalation .................................................................................... 22
54. Threat Actor .............................................................................................. 22
55. TTP (Tactics, Techniques, and Procedures) .................................................. 23
56. Security Orchestration ............................................................................... 23
57. Behavioral Analytics................................................................................... 23
58. Command and Control (C2 or C&C) ............................................................ 23
59. Cyber Kill Chain Framework ........................................................................ 24
60. False Negative ........................................................................................... 24
61. Honeypot .................................................................................................. 24
62. IOC (Indicator of Compromise) ................................................................... 25
63. Kill Chain Disruption .................................................................................. 25
64. Behavioral Indicators ................................................................................. 26
65. Cyber Threat Hunting ................................................................................. 26
66. Zero Trust .................................................................................................. 26
67. Multifactor Authentication (MFA) ................................................................ 26
68. Encryption ................................................................................................ 27
69. Data Exfiltration ......................................................................................... 27
70. Network Segmentation............................................................................... 27
71. Incident Escalation .................................................................................... 28
72. YARA Rules ................................................................................................ 28
[Link] +919604647000 centermanager@[Link]
73. Cyber Threat Intelligence Platform (CTIP) ..................................................... 28
74. Security Information and Event Management (SIEM) Rules ........................... 28
75. Endpoint Protection Platform (EPP) ............................................................. 29
76. Cybersecurity Framework ........................................................................... 29
77. MITRE ATT&CK Framework .......................................................................... 29
78. SOC Automation........................................................................................ 29
79. Key Performance Indicators (KPIs)............................................................... 30
80. Incident Recovery ...................................................................................... 30
81. Threat Modeling ......................................................................................... 30
82. Kill Chain Analysis ..................................................................................... 30
83. Endpoint Forensics .................................................................................... 31
84. User Behavior Analytics (UBA) .................................................................... 31
85. SIEM Correlation........................................................................................ 31
86. Threat Landscape ...................................................................................... 32
87. Sandbox Evasion ....................................................................................... 32
88. Cybersecurity Playbook .............................................................................. 32
89. Security Orchestration ............................................................................... 32
90. Tactical Intelligence ................................................................................... 33
91. Strategic Intelligence ................................................................................. 33
92. Vulnerability Management .......................................................................... 33
93. Attack Vector ............................................................................................. 34
94. Threat Feed ............................................................................................... 34
95. Anomaly Detection .................................................................................... 34
96. Data Breach .............................................................................................. 34
97. Red Teaming Exercises ............................................................................... 35
98. Behavioral Indicators ................................................................................. 35
99. Incident Playbook ...................................................................................... 35
100. False Positive Rate ................................................................................... 36
[Link] +919604647000 centermanager@[Link]
1. SOC (Security Operations Center)
Definition:
A centralized team or facility responsible for continuous monitoring, detecting,
analysing, and responding to cybersecurity incidents within an organization. The SOC
uses advanced tools, defined processes, and skilled analysts to protect digital assets
and maintain situational awareness.
Examples:
• SOC staff receive real-time alerts from SIEM and triage events for investigation.
• The SOC orchestrates response efforts when ransomware is detected in the
network.
• Each day, the SOC prepares summary reports of attempted intrusions for
executives.
2. SIEM (Security Information and Event Management)
Definition:
A technology platform or suite combining security information management (SIM) and
security event management (SEM), collecting and analysing logs from various sources
for threat detection, incident tracking, and compliance requirements.
Examples:
• SIEM correlates firewall and endpoint logs to spot lateral movement by
attackers.
• SOC analysts use SIEM dashboards to visualize trends in failed login attempts.
• During audit season, SIEM makes it easy to retrieve historical event data.
3. Incident Response
Definition:
A coordinated approach to prepare for, detect, contain, eradicate, and recover from
cybersecurity incidents, with roles, playbooks, and communications defined for the
team.
Examples:
• Analysts use playbooks for immediate actions when new malware is detected.
• Incident response involves contacting legal and compliance for data breach
reporting.
• Lessons learned meetings follow major incidents to refine future response steps.
[Link] +919604647000 centermanager@[Link]
4. Threat Intelligence
Definition:
Timely knowledge about existing or emerging cyber threats—including attacker
techniques, indicators, and vulnerabilities—that supports proactive security measures
and decision-making.
Examples:
• The SOC consumes threat feeds to block connections to known C2 servers.
• Threat intelligence enables early warning about zero-day attacks in the wild.
• Analysts adjust detection rules in response to reports about a new ransomware
family.
5. EDR (Endpoint Detection and Response)
Definition:
Solutions that monitor endpoint devices (laptops, desktops, servers) for suspicious
activities, providing alerting, evidence collection, and rapid containment/respond
capabilities.
Examples:
• EDR isolates an endpoint after scanning detects fileless malware.
• SOC uses EDR to retrieve process trees and command-line history for forensic
analysis.
• Automated EDR workflows roll back unauthorized registry changes.
Certainly! Here are the next 20 common Security Operations Center (SOC) terms
with elaborative definitions and 3 real-world examples for each. The format is ready for
you to copy and paste into a Word file.
6. Indicators of Compromise (IoCs)
Definition:
Artifacts that suggest a system may have been breached by a threat actor, including file
hashes, domain names, IP addresses, or patterns of suspicious behavior.
Examples:
• A known malicious MD5 hash is found during a scan of a company laptop.
• The SIEM detects communication from an internal server to an IoC-listed
command-and-control IP.
[Link] +919604647000 centermanager@[Link]
• Phishing emails received by staff link to suspicious URLs flagged in threat
intelligence feeds.
7. Firewall
Definition:
A hardware or software solution that filters network traffic based on predefined security
rules, designed to block unauthorized access while permitting legitimate
communication.
Examples:
• The firewall blocks inbound connections on unapproved ports from the public
internet.
• Outbound traffic to foreign countries is restricted by firewall policies for
compliance.
• Security engineers update firewall rules after discovering open access to an
admin interface.
8. IDS/IPS (Intrusion Detection/Prevention System)
Definition:
IDS monitors network or system activities for malicious actions; IPS can actively block
or prevent detected attacks in real time.
Examples:
• IDS alerts when it notices multiple failed login attempts, indicating a brute-force
attack.
• IPS automatically blocks a shellcode payload transmitted via HTTP.
• Analysts review IDS logs for unusual patterns that might represent a slow,
stealthy attack.
9. SOAR (Security Orchestration, Automation, and Response)
Definition:
A platform that integrates security tools and automates incident response workflows to
accelerate investigations and reduce manual intervention.
Examples:
• SOAR solution auto-collects logs and quarantines affected hosts upon detecting
malware.
• Automated playbooks launch in SOAR to reset passwords after credential
compromise.
[Link] +919604647000 centermanager@[Link]
• SOAR integrates threat intelligence feed actions directly into alert triage.
10. Phishing
Definition:
A cyberattack using fraudulent emails, messages, or websites to trick individuals into
revealing sensitive information or installing malware.
Examples:
• Employees receive emails appearing to come from their manager asking for login
credentials.
• SOC investigates a reported link in a mass email that leads to a fake payment
page.
• Attackers send text messages (smishing) to staff, posing as IT support.
11. Log Management
Definition:
Collecting, storing, analyzing, and maintaining log data generated by network devices,
servers, and applications to detect threats and provide audit trails.
Examples:
• The SOC reviews aggregated logs to trace suspicious administrative activity in
cloud accounts.
• Long-term log storage supports forensic investigations of past incidents.
• Log analysis reveals regular failed logins to a neglected admin interface.
12. Playbook
Definition:
A documented, step-by-step set of procedures for responding to specific security
scenarios, supporting consistency and speed.
Examples:
• SOC uses a playbook to guide isolation, containment, and eradication steps for
ransomware attacks.
• Playbooks define communication and escalation paths during a data breach.
• A phishing playbook details steps for email analysis and user notification.
[Link] +919604647000 centermanager@[Link]
13. False Positive
Definition:
A security alert that incorrectly flags legitimate activity as a threat, potentially increasing
analyst workload and decreasing alert effectiveness.
Examples:
• Automated scans flag routine software update traffic as an attack.
• A user logging in from a new location triggers a geo-velocity alarm, but it was a
planned business trip.
• Antivirus mistakenly blocks a signed, safe application as malware.
14. Security Monitoring
Definition:
Continuous surveillance and analysis of information systems to identify threats,
vulnerabilities, or policy violations in real-time or near-real-time.
Examples:
• Round-the-clock monitoring ensures the SOC detects after-hours attacks.
• Dashboards visualize network anomalies for immediate review by analysts.
• Security monitoring tools alert on suspicious lateral movement between servers.
[Link] +919604647000 centermanager@[Link]
15. Vulnerability Assessment
Definition:
The process of identifying, quantifying, and prioritizing weaknesses in systems,
applications, and networks to guide remediation efforts.
Examples:
• Regular scans reveal unpatched software vulnerabilities on legacy servers.
• Vulnerability assessments highlight third-party components with known flaws.
• A web application scan uncovers injection flaws before go-live.
16. UEBA (User and Entity Behavior Analytics)
Definition:
Advanced analytics that baseline normal activity for users and entities, detecting
deviations indicative of threats such as insider attacks or compromised accounts.
Examples:
• UEBA flags an account downloading large amounts of sensitive data at unusual
hours.
• An employee suddenly accessing sensitive HR data triggers an alert.
• UEBA detects a service account performing anomalous actions in production
systems.
17. Threat Hunting
Definition:
A proactive approach whereby analysts manually or semi-automatically search for
evidence of threats missed by traditional security tools.
Examples:
• Threat hunters search endpoint logs for signs of advanced persistent threats.
• Structured hunts look for known indicators of fileless malware in memory.
• Analysts pivot through SIEM data to uncover unusual remote desktop
connections.
18. MDR (Managed Detection and Response)
Definition:
Outsourced security services providing threat monitoring, detection, and response,
often including threat intelligence, incident analysis, and remediation.
Examples:
[Link] +919604647000 centermanager@[Link]
• MDR provider alerts clients to a new phishing campaign targeting their
executives.
• Managed service investigates endpoint alerts and provides a full post-mortem.
• MDR team coordinates with internal IT to contain a cloud credential
compromise.
19. XDR (Extended Detection and Response)
Definition:
A unified security solution that correlates data and security analytics across endpoints,
networks, cloud, and applications for comprehensive threat detection and response.
Examples:
• XDR links suspicious DNS activity with an endpoint alert to reveal lateral
movement.
• Alerts from cloud IAM, firewall, and endpoint tools are unified in the XDR
dashboard.
• XDR incident investigation tracks an attacker from initial compromise to data
access.
20. SOC Analyst
Definition:
A cybersecurity professional responsible for monitoring, analyzing, and responding to
alerts and incidents as part of the SOC team.
Examples:
• Level 1 analyst triages SIEM alerts for severity and potential escalation.
• A SOC analyst investigates root cause and impact following a malware
detection.
• Analysts collaborate with IT teams to remediate vulnerabilities found during
threat hunting.
21. Risk Assessment
Definition:
A systematic process to identify, evaluate, and prioritize cybersecurity risks to an
organization's assets, defining mitigation and response strategies.
Examples:
• The SOC conducts risk assessments before onboarding new cloud services.
[Link] +919604647000 centermanager@[Link]
• High-risk systems handling sensitive data receive prioritized patching.
• Risk assessment findings guide changes in security policy after technology
upgrades.
22. Asset Inventory
Definition:
A comprehensive and regularly updated list of all hardware, software, and data assets
within the organization, used to improve visibility and prioritize protection.
Examples:
• Regular asset inventory reviews uncover unauthorized devices connected to the
network.
• Discovery tools map cloud resources missing from earlier asset lists.
• SOC updates asset inventory after deploying new servers in the data center.
23. Data Loss Prevention (DLP)
Definition:
Technologies and policies designed to prevent unauthorized sharing, transmission, or
theft of sensitive data, both inside and outside the organization.
Examples:
• DLP blocks the upload of confidential HR files to public cloud storage.
• Email DLP policies prevent credit card numbers from being emailed externally.
[Link] +919604647000 centermanager@[Link]
• DLP alerts when users try to copy sensitive data onto removable USB media.
24. Compromise Assessment
Definition:
An in-depth analysis to determine if an environment has been breached in the past,
often after a suspected incident, to find evidence of compromise and recommend next
steps.
Examples:
• SOC performs compromise assessment on servers after suspicious activity is
detected.
• External consultants conduct a compromise check after a ransomware
infection.
• Compromise assessment discovers remnants of an old malware infection that
was never remediated.
25. Incident Ticket
Definition:
A trackable, documented record of a detected security incident, from initial
identification through investigation, response, and closure.
Examples:
• Every phishing alert is logged and tracked in the SOC’s incident management
system.
• Managers review incident tickets weekly to track SOC performance and trends.
• Incident tickets include all key details, response steps, and post-incident
analysis.
Thank you for confirming. Here are the next 20 Security Operations Center (SOC)
terms (terms 26–45), each with elaborative definitions and three real-world examples
for each. You can copy and paste these directly into your Word file in the same
structured format.
26. Alert Fatigue
Definition:
A condition where analysts become desensitized to security alerts due to frequent false
positives or sheer alert volume, leading to slower responses and potential oversight of
true threats.
Examples:
[Link] +919604647000 centermanager@[Link]
• Analysts overlook a genuine malware alert after hours of processing low-priority
noise.
• The SOC deploys stricter SIEM correlation rules to reduce alert fatigue.
• Alert fatigue leads to delayed response during a targeted phishing campaign.
27. DNS Sinkhole
Definition:
A DNS server or configuration that redirects requests for malicious domains to safe,
controlled addresses—often for blocking or analysis—helping identify or prevent
infections.
Examples:
• Malware communications to a command-and-control domain are diverted to an
internal sinkhole.
• Analysts monitor sinkhole logs to identify infected endpoints attempting to reach
blacklisted domains.
• IT redirects known phishing domains using DNS sinkholes to prevent staff from
reaching them.
28. Whitelisting
Definition:
A security approach that allows only explicitly approved software, websites, or
processes to run or communicate, blocking everything else by default.
Examples:
• Only pre-approved business applications can run on point-of-sale terminals.
• Company firewalls whitelist trusted domains for outbound internet access.
• Email systems reject all external messages except from whitelisted partners.
29. Blacklisting
Definition:
Blocking entities (such as IPs, applications, domains, or users) identified as malicious,
untrusted, or unwanted, to prevent access or execution in the environment.
Examples:
• Firewall blocks inbound connections from a known botnet IP blacklist.
• Email security products drop messages from blacklisted phishing domains.
• Application controls prevent installation of software from blacklisted vendors.
[Link] +919604647000 centermanager@[Link]
30. Triage
Definition:
A process for quickly assessing, prioritizing, and assigning security alerts or incidents
based on severity, credibility, and potential impact.
Examples:
• L1 SOC analysts triage hundreds of SIEM alerts to escalate the most critical
ones.
• Automated triage assigns top priority to incidents involving crown-jewel assets.
• During an outbreak, triage rules focus on rapid evaluation of ransomware
detections.
31. Network Forensics
Definition:
The use of capture and analysis of network traffic to investigate, reconstruct, and
understand cyber incidents or breaches.
Examples:
• Analysts review full packet captures to trace lateral movement during a breach.
• Network forensics identifies data exfiltration attempts over suspicious encrypted
tunnels.
• After an incident, the SOC reconstructs attacker command sequences from
PCAP files.
32. Patch Management
Definition:
A structured process of identifying, acquiring, testing, and deploying patches or
updates to software and systems to mitigate security vulnerabilities.
Examples:
• Emergency patching of VPN software after a high-profile zero-day exploit is
announced.
• The SOC coordinates monthly patch windows with IT for critical vulnerabilities.
• Patch management tools report on systems with missed security updates.
33. Security Baseline
Definition:
A defined, approved configuration of systems, applications, and controls representing
[Link] +919604647000 centermanager@[Link]
the minimum required security settings, serving as a benchmark for compliance and
hardening.
Examples:
• Servers are checked weekly for adherence to the enterprise security baseline.
• SOC audits baselines to catch unauthorized software installations.
• Changes from the baseline trigger alerts for possible misconfigurations.
34. DDoS (Distributed Denial of Service)
Definition:
An attack that uses a flood of traffic from multiple sources to overwhelm and disable
the target service, network, or infrastructure.
Examples:
• External attackers launch a massive DDoS, making the corporate website
unavailable.
• SOC partners with ISPs to implement upstream DDoS filtering during an attack.
• Traffic analysis tools identify anomalous spikes in inbound packets consistent
with DDoS.
35. Red Team
Definition:
A group of security professionals authorized to simulate real-world attacks using
adversarial techniques, aiming to test and improve the organization’s defenses.
Examples:
• The Red Team successfully bypasses physical security to plant rogue network
devices.
• Red Teamers use spear-phishing to compromise privileged user accounts during
exercises.
• Findings from Red Team engagements directly update and improve SOC
playbooks.
36. Blue Team
Definition:
Defensive security group responsible for monitoring, detecting, and responding to
incidents, running day-to-day security operations within the SOC.
Examples:
[Link] +919604647000 centermanager@[Link]
• Blue Team investigates Red Team activity during a planned “assume breach”
drill.
• Daily, Blue Team analysts watch for anomalous logins and malware alerts.
• Blue Team quickly contains and eradicates a simulated ransomware infection.
37. Purple Team
Definition:
A collaborative model in which Red and Blue Teams work together to maximize security
improvements through sharing, feedback, and joint exercises.
Examples:
• Purple Team debriefs after exercises produce new detection signatures.
• Red and Blue conduct “tabletop” events to discuss responses to new attack
techniques.
• Post-mortem meetings allow both teams to iterate on controls and detections.
38. Insider Threat
Definition:
A security risk originating from people within the organization, such as employees,
contractors, or partners, who abuse their legitimate access to cause harm.
Examples:
• SOC flags a user exporting large quantities of sensitive data before resignation.
• Disgruntled employee intentionally downloads and shares confidential pricing
lists.
• Contractors bypass internal controls to access customer PII.
39. Security Policy
Definition:
A formalized, written document specifying an organization’s security principles, rules,
expectations, and enforcement procedures, guiding decisions and behaviors.
Examples:
• Company security policy mandates multi-factor authentication for remote
access.
• The policy requires annual security awareness training for all staff.
• USB storage device use is prohibited by official security policy.
[Link] +919604647000 centermanager@[Link]
40. Compliance Reporting
Definition:
Producing evidence, metrics, and documentation to demonstrate conformity to
regulatory requirements, security standards, and internal policies.
Examples:
• Automated tools generate PCI DSS compliance reports for auditors.
• SOC prepares monthly logs attesting to GDPR incident management processes.
• Compliance reporting highlights completed and overdue vulnerability
remediations.
41. Business Continuity
Definition:
The institution of processes and plans ensuring the organization can carry out critical
operations during or following a disruption caused by cyber incidents or disasters.
Examples:
• The company conducts tabletop exercises to test cyberattack recovery plans.
• Business continuity plan calls for rapid fail-over to disaster recovery datacenters.
• The SOC verifies daily backups to support business continuity after ransomware
outbreaks.
42. Penetration Testing
Definition:
An authorized and systematic attempt to exploit systems, applications, or physical
security to identify and report vulnerabilities before criminal actors do.
Examples:
• External consultants run regular penetration tests and deliver detailed findings to
the SOC.
• Web application pentesters discover SQL injection flaws missed by automated
scans.
• The SOC remediates weaknesses found by internal penetration testers.
43. SOC Manager
Definition:
A senior leader responsible for overseeing SOC operations, managing staff, budgeting
for tools, establishing processes, and ensuring effective threat detection and response.
[Link] +919604647000 centermanager@[Link]
Examples:
• The SOC Manager approves new analyst training programs.
• They coordinate with IT and business leads during major incidents.
• SOC Manager presents monthly risk posture updates to executive leadership.
44. Asset Discovery Tool
Definition:
Automated technology for detecting, cataloging, and tracking all hardware and software
present in a network environment, enhancing visibility and reducing blind spots.
Examples:
• New IoT devices are automatically added to inventory by asset discovery scans.
• Unauthorized laptops plugged into meeting rooms trigger instant asset discovery
alerts.
• The SOC compares asset lists from discovery tools against baseline inventories.
45. Malware Sandbox
Definition:
An isolated virtual or physical environment in which suspicious files, URLs, or
applications are safely executed and analyzed without risking production networks.
Examples:
• SOC analysts detonate suspicious email attachments in a malware sandbox to
observe behavior.
• Malware sandboxes automatically extract indicators of compromise for further
investigation.
• The sandbox environment logs callback attempts to C2 infrastructure.
46. Zero-Day
Definition:
A security vulnerability that is unknown to the software vendor or security community at
the time of discovery, for which no patch or fix is available. Zero-days are highly valued
by attackers because they can exploit systems before defenses are developed.
Examples:
• Attackers use a zero-day vulnerability in a popular web browser to compromise
users before a patch is released.
[Link] +919604647000 centermanager@[Link]
• The SOC rapidly deploys virtual patches and compensating controls after
discovering a zero-day exploit targeting their environment.
• Security researchers publish a zero-day alert prompting immediate incident
responses across affected sectors.
47. Attack Surface
Definition:
The total sum of all points (attack vectors) where an unauthorized user can try to enter
or extract data from an environment. Reducing the attack surface is essential to
lowering security risk.
Examples:
• Migration to cloud services expands the company’s attack surface by adding new
interfaces.
• The SOC identifies unnecessary open ports on servers that increase the attack
surface.
• Hardening endpoints by disabling unused services helps shrink the attack
surface.
48. Incident Containment
Definition:
Focused actions taken during an active security incident to limit the extent, spread, or
damage caused by the attack, often by isolating systems or blocking attacker
communications.
Examples:
• Disconnecting an infected workstation from the network to stop ransomware
propagation.
• Blocking malicious IP addresses at the firewall to contain an ongoing intrusion.
• Temporarily disabling compromised user accounts to halt insider data leaks.
49. IOC (Indicator of Compromise) Feed
Definition:
A continuously updated source or stream of known Indicators of Compromise, such as
IP addresses, hashes, or domain names, shared by threat intelligence providers and
integrated into security platforms for real-time detection.
Examples:
[Link] +919604647000 centermanager@[Link]
• The SIEM ingests IOC feeds to automatically flag traffic to blacklisted command-
and-control servers.
• Endpoint agents block files matching hashes found in IOC feeds.
• Regular IOC feed updates help SOC analysts prioritize investigation of
suspicious alerts.
50. Security Awareness Training
Definition:
Programs designed to educate employees and users about cybersecurity risks, policies,
and behaviors to reduce the likelihood of human error-related incidents like phishing.
Examples:
• Quarterly phishing simulation campaigns test and improve employee response
to social engineering.
• Training materials include videos and quizzes on recognizing malicious emails.
• SOC tracks training completion rates and correlates with incident reports.
51. Kill Chain
Definition:
A model describing the sequential stages of a cyberattack, from reconnaissance
through exploitation to objective execution, helping defenders to detect and disrupt
attacks at multiple points.
Examples:
[Link] +919604647000 centermanager@[Link]
• The SOC uses the kill chain framework to identify and block attacks during
reconnaissance stages.
• Analysts map malware behavior to kill chain phases to prioritize response
actions.
• Incident post-mortems reference kill chain phases to highlight defense gaps.
52. Lateral Movement
Definition:
Tactics used by attackers to progressively move deeper into a network after initial
compromise, often by exploiting trust relationships or stolen credentials.
Examples:
• Attackers use stolen admin credentials to access multiple servers laterally.
• The SOC detects unusual SMB traffic indicative of lateral movement attempts.
• Network segmentation policies mitigate the impact of lateral movement.
53. Privilege Escalation
Definition:
A process where attackers gain higher levels of access or permissions than initially
granted, enabling greater control or theft of sensitive data.
Examples:
• Exploiting a flaw in Windows to escalate privileges from user to admin.
• SOC detects a process spawning a new shell with elevated permissions.
• Incident response involves revoking escalated privileges and remediation.
54. Threat Actor
Definition:
An individual, group, or entity responsible for carrying out malicious cyber activities.
Examples include hackers, nation-states, hacktivists, or insider threats.
Examples:
• A financially motivated threat actor launches a ransomware campaign targeting
healthcare.
• Nation-state sponsored APT groups are identified by the SOC through unique
TTPs (tactics, techniques, and procedures).
• Insider threat actors successfully exfiltrate sensitive IP data.
[Link] +919604647000 centermanager@[Link]
55. TTP (Tactics, Techniques, and Procedures)
Definition:
The behavior, methods, and tools an attacker uses when conducting cyber operations,
which analysts study to detect and attribute attacks.
Examples:
• SOC builds detection rules based on known TTPs of ransomware groups.
• Analysts map observed attack behaviors to MITRE ATT&CK TTPs during
investigations.
• Threat intelligence reports detail new TTPs used in supply chain attacks.
56. Security Orchestration
Definition:
Automating and coordinating security tools and processes across different platforms
and teams to improve response efficiency and reduce manual effort.
Examples:
• Automated ticket creation after alerts are triaged reduces SOC analyst workload.
• Orchestration triggers immediate IP blocking in firewalls after malware
detection.
• Integration between SIEM, SOAR, and EDR platforms improves workflow.
57. Behavioral Analytics
Definition:
The use of machine learning and statistical analysis to identify anomalous user or
system behaviors that deviate from established baselines, potentially indicating
threats.
Examples:
• Behavioral analytics detect a user downloading large amounts of data overnight.
• Unexpected system service changes are flagged by behavior baselining tools.
• UEBA solutions surface insider threat indicators through behavioral anomalies.
58. Command and Control (C2 or C&C)
Definition:
Servers or infrastructure used by attackers to maintain communication and control over
compromised systems within a victim network.
Examples:
[Link] +919604647000 centermanager@[Link]
• SOC blocks outbound traffic to known C2 domains based on threat intelligence.
• Analysts monitor network logs for periodic beaconing to C2 IPs.
• Malware sandboxing reveals attempted connections to C2 servers during
analysis.
59. Cyber Kill Chain Framework
Definition:
A cybersecurity model developed by Lockheed Martin outlining the steps adversaries
take in executing an attack, used to develop detection and defense strategies.
Examples:
• SOC uses the kill chain to design layered defenses against different attack
phases.
• Incident reports reference phases of the kill chain to describe attacker activity.
• Red Team exercises simulate attacks mapped to kill chain phases to test
readiness.
60. False Negative
Definition:
A failure to detect or alert on an actual malicious event, allowing threats to operate
undetected within the environment.
Examples:
• A sophisticated malware sample bypasses antivirus detection, causing a false
negative.
• The SIEM misses lateral movement due to incomplete logging, producing a false
negative.
• False negatives delay the SOC response, increasing attack dwell time.
61. Honeypot
Definition:
A decoy system or network designed to attract attackers to study their behaviors,
collect intelligence, or divert attacks from real assets.
Examples:
• The SOC deploys honeypots that mimic vulnerable servers to trap malware.
• Attackers spend hours exploring honeypot file shares, yielding investigation data.
• Honeypots alert analysts to scanning activity and potential new threats.
[Link] +919604647000 centermanager@[Link]
62. IOC (Indicator of Compromise)
Definition:
Specific artifacts or evidence—such as IPs, hashes, filenames—collected during threat
investigations that signal potential intrusion or infection.
Examples:
• File hash linked to known ransomware found on an endpoint.
• IP address associated with a botnet command-and-control server logs inbound
connection attempts.
• Suspicious domain names identified through network traffic analysis.
63. Kill Chain Disruption
Definition:
Security measures focusing on interrupting one or more phases of the attacker’s kill
chain to prevent full attack execution.
Examples:
• Blocking phishing emails halts the reconnaissance or delivery phase.
• Network segmentation disrupts lateral movement.
• Rapid patching of vulnerabilities prevents exploitation.
[Link] +919604647000 centermanager@[Link]
64. Behavioral Indicators
Definition:
Patterns or signs of behavior that hint at malicious intent or activity, especially
deviations from normal user, system, or network operations.
Examples:
• A user logging in from an unusual geographic location.
• Systems executing new processes that are not part of normal operations.
• Repeated failed logins followed by a successful login late at night.
65. Cyber Threat Hunting
Definition:
The proactive and iterative search through networks and datasets to detect and isolate
advanced threats undetected by automated tools.
Examples:
• Analysts query logs for unusual file execution and registry changes.
• Searching for known APT tool signatures in internal network traffic.
• Hunting for anomalies in PowerShell usage patterns on endpoints.
66. Zero Trust
Definition:
A security model that assumes no implicit trust within or outside the network perimeter;
every access request is verified, authenticated, and authorized before granting access.
Examples:
• Implementing micro-segmentation to verify every access request between
applications.
• Continuous authentication methods applied to user sessions accessing critical
systems.
• Enforcing least-privilege access to limit damage from compromised credentials.
67. Multifactor Authentication (MFA)
Definition:
A security measure requiring users to provide two or more types of authentication
factors (something they know, have, or are) before granting access.
[Link] +919604647000 centermanager@[Link]
Examples:
• Requiring a password plus a time-based one-time code for VPN access.
• Using biometric factors in addition to passwords for highly sensitive systems.
• MFA preventing attackers from simply using stolen credentials to gain entry.
68. Encryption
Definition:
The process of converting data into a coded format to prevent unauthorized access,
ensuring confidentiality during storage or transmission.
Examples:
• Full disk encryption on laptops protects data if devices are lost or stolen.
• TLS encryption secures web traffic between users and company applications.
• Email messages containing sensitive information are encrypted before delivery.
69. Data Exfiltration
Definition:
The unauthorized transfer of data from an organization’s network to an external
location, often a key goal of attackers after infiltration.
Examples:
• Detecting large outbound data transfers during abnormal hours.
• Using DLP tools to block transfers of sensitive files to USB storage.
• Network forensics identifies encrypted tunnels used to exfiltrate data.
70. Network Segmentation
Definition:
Dividing a computer network into smaller, isolated segments to improve security and
reduce the lateral movement of threat actors.
Examples:
• Separating the finance network segment from general user networks.
• Using VLANs and firewalls to isolate sensitive systems.
• Implementing segmentation to contain outbreaks of malware.
[Link] +919604647000 centermanager@[Link]
71. Incident Escalation
Definition:
The process of advancing incident handling to higher levels of expertise or management
based on severity or complexity.
Examples:
• Escalating phishing incidents from L1 to L2 analysts for detailed analysis.
• Alerting senior management about data breaches as per the incident response
plan.
• Involving legal and PR teams for incidents involving sensitive data leaks.
72. YARA Rules
Definition:
Customizable rules written to identify and classify malware and suspicious files based
on textual or binary patterns.
Examples:
• Using YARA to scan malware samples in a sandbox environment.
• Integration of YARA rules in EDR platforms to detect known threat signatures.
• Analysts write new YARA rules to detect emerging malware variants.
73. Cyber Threat Intelligence Platform (CTIP)
Definition:
A system that aggregates, correlates, and analyzes threat intelligence data from
multiple sources to support proactive defense and decision-making.
Examples:
• Feeding CTIP data into SIEM for advanced alerting capabilities.
• Sharing intelligence reports with partners via CTIP collaboration features.
• Using CTIP dashboards to monitor targeted threat campaigns.
74. Security Information and Event Management (SIEM) Rules
Definition:
Predefined and customizable logic within a SIEM that triggers alerts based on
correlating and analyzing security events.
Examples:
• Writing new SIEM rules to detect brute-force attacks.
[Link] +919604647000 centermanager@[Link]
• Tuning SIEM rules to reduce false positives while maintaining effectiveness.
• SIEM alerts based on rules detecting privilege escalation attempts.
75. Endpoint Protection Platform (EPP)
Definition:
A suite of security tools deployed at endpoints to prevent malware infections and detect
threats, usually including antivirus, firewall, and device control.
Examples:
• Blocking execution of known malicious files at endpoint devices.
• Using EPP to enforce USB device access policies.
• Integrated EPP components blocking phishing link payloads.
76. Cybersecurity Framework
Definition:
A formal set of standards, best practices, and guidelines for managing cybersecurity
risks, such as NIST CSF or ISO/IEC 27001.
Examples:
• Aligning SOC processes with the NIST Cybersecurity Framework categories.
• Using ISO 27001 controls to establish security policies and procedures.
• Reporting SOC maturity based on framework compliance audits.
77. MITRE ATT&CK Framework
Definition:
A globally-accessible knowledge base of adversary tactics, techniques, and procedures
(TTPs) used as a foundation for threat detection and response.
Examples:
• Mapping incidents to ATT&CK techniques to improve detection rules.
• Using ATT&CK to guide threat hunting hypotheses.
• SOC trains analysts on MITRE ATT&CK to better interpret attacker behavior.
78. SOC Automation
Definition:
The use of automated tools and scripts to reduce manual tasks in SOC workflows such
as alert triage, data collection, and remediation.
Examples:
[Link] +919604647000 centermanager@[Link]
• Automatically enriching alerts with threat intelligence data upon SIEM trigger.
• Automating user account lockouts after suspicious login attempts.
• Generating incident reports automatically for compliance documentation.
79. Key Performance Indicators (KPIs)
Definition:
Quantifiable metrics used to evaluate SOC performance and effectiveness in areas
such as incident response time, alert volume, and false positive rates.
Examples:
• Tracking average time to detect and respond to incidents monthly.
• Measuring reduction in false positives after SIEM rule tuning.
• Reporting number of incidents successfully contained without data loss.
80. Incident Recovery
Definition:
The process of restoring affected systems and services to normal operation after
containment and eradication of a security incident.
Examples:
• Restoring data from clean backups post-malware removal.
• Reimaging compromised servers to ensure no persistent threats remain.
• Verifying system integrity before returning to production load.
81. Threat Modeling
Definition:
A structured approach to identifying, enumerating, and prioritizing potential threats and
vulnerabilities in a system or environment to design mitigations proactively.
Examples:
• Modeling web application components to identify injection attack vectors.
• Creating attacker profiles to simulate potential breach scenarios.
• Using threat modeling outputs to drive security control implementation.
82. Kill Chain Analysis
Definition:
A detailed examination of an attack by dissecting it into discrete stages following the
cyber kill chain model to identify where defenses failed or succeeded.
[Link] +919604647000 centermanager@[Link]
Examples:
• Post-incident review showing attacker activities at delivery and exploitation
phases.
• Using kill chain analysis to update detection rules and close gaps.
• Educating SOC staff on the kill chain stages through real incident case studies.
83. Endpoint Forensics
Definition:
The collection and analysis of data from endpoint devices to investigate incidents, trace
attacker actions, and gather evidence.
Examples:
• Examining file system artifacts to determine malware origin.
• Analyzing registry changes and process histories during investigations.
• Extracting volatile memory for advanced malware analysis.
84. User Behavior Analytics (UBA)
Definition:
A subset of UEBA focusing specifically on identifying unusual or anomalous behavior
patterns of individual users that may indicate compromise or insider threats.
Examples:
• Detecting a user downloading large volumes of data after hours.
• Flagging unusual login times inconsistent with normal patterns.
• Identifying privilege escalation through unexpected access requests.
85. SIEM Correlation
Definition:
The process by which a SIEM system relates different security events from various
sources to reveal patterns indicative of potential security incidents.
Examples:
• Correlating multiple failed login attempts with suspicious file download to detect
brute force plus malware attack.
• Linking firewall block events with endpoint alerts to identify targeted attacks.
• Aggregating alerts across departments to spot coordinated attacks.
[Link] +919604647000 centermanager@[Link]
86. Threat Landscape
Definition:
The overall environment of current and evolving cyber threats targeting organizations,
including attacker groups, malware types, vulnerabilities, and attack methods.
Examples:
• Monitoring shifts in the threat landscape to adapt SOC detection capabilities.
• Adjusting defenses based on new ransomware variants dominating the threat
landscape.
• Incorporating intelligence on emerging nation-state threats to prioritize critical
asset protection.
87. Sandbox Evasion
Definition:
Techniques used by malware to detect and avoid analysis in malware sandbox
environments, making detection more challenging.
Examples:
• Malware delays execution when it detects indicators of a virtualized sandbox.
• Sophisticated threats check for keyboard or mouse inputs before activating
payloads.
• Analysts develop sandbox enhancements to counter evasion tactics.
88. Cybersecurity Playbook
Definition:
A formal, detailed collection of procedures and workflows that guide SOC analysts and
responders through specific incident types or threat scenarios.
Examples:
• A ransomware playbook details containment, eradication, and recovery steps.
• SOC executes the DDoS playbook when signs of volumetric attack appear.
• Playbooks are regularly updated based on lessons learned from past incidents.
89. Security Orchestration
Definition:
The process of integrating multiple security tools and automating workflows to improve
efficiency and speed in threat detection and incident response.
Examples:
[Link] +919604647000 centermanager@[Link]
• Automatically quarantining an endpoint detected with malware through
orchestration.
• Security orchestration triggers multi-step workflows for phishing investigations.
• Integrating SIEM, EDR, and ticketing systems for seamless incident tracking.
90. Tactical Intelligence
Definition:
Actionable and time-sensitive threat intelligence focused on immediate operational
needs such as current IoCs or attack signatures.
Examples:
• Receiving tactical intelligence feeds with IP addresses linked to active attacks.
• Using tactical intelligence to block malicious domains in real time.
• Distributing updated IoCs from tactical intelligence to SOC tools promptly.
91. Strategic Intelligence
Definition:
Long-term, broader threat intelligence designed to inform security strategy, risk
management, and policy development.
Examples:
• Executive briefings on geopolitical risks impacting cybersecurity posture.
• Analysis of emerging attacker trends to inform budget and staffing decisions.
• Using strategic intelligence to shape long-term security architecture.
92. Vulnerability Management
Definition:
A continuous cycle of identifying, classifying, remediating, and mitigating vulnerabilities
in systems and applications.
Examples:
• Scheduling regular vulnerability scans and patch cycles.
• Prioritizing remediation efforts based on risk and exploitability.
• Coordinating with IT teams to deploy patches for high-risk vulnerabilities
promptly.
[Link] +919604647000 centermanager@[Link]
93. Attack Vector
Definition:
The method or pathway through which an attacker gains unauthorized access to a
network or system.
Examples:
• Phishing emails serve as an attack vector delivering malware payloads.
• Exploiting unpatched software vulnerabilities as attack vectors for initial
compromise.
• Using stolen credentials to access network resources via VPN.
94. Threat Feed
Definition:
Automated streams of cyber threat data, such as malicious IPs, file hashes, domains, or
URLs, used to enhance detection and prevention capabilities.
Examples:
• Integrating open-source threat feeds into SIEM correlation rules.
• Consuming commercial threat feeds for enriched contextual alerting.
• Updating firewall blacklists based on threat feed indicators.
95. Anomaly Detection
Definition:
The identification of patterns in data that do not conform to expected behavior,
potentially indicating a security incident or threat.
Examples:
• Detecting an unusual spike in data uploads by a user outside normal hours.
• Alerting when an endpoint executes an unrecognized process executable.
• Network monitoring tools flagging deviations in traffic protocols or volumes.
96. Data Breach
Definition:
An incident where sensitive, protected, or confidential data is accessed, disclosed, or
exfiltrated without authorization.
Examples:
• Personal customer information stolen via SQL injection attack.
[Link] +919604647000 centermanager@[Link]
• Employee credentials leaked in a phishing attack leading to access to internal
systems.
• Cloud storage misconfiguration exposing private corporate documents.
97. Red Teaming Exercises
Definition:
Simulated attack campaigns conducted by internal or external teams to test an
organization’s defenses, detection, and response capabilities.
Examples:
• Red Team attempts social engineering and phishing to test human security
awareness.
• Launching simulated lateral movement to test detection of internal threats.
• Testing incident response by introducing benign malware variants in a controlled
manner.
98. Behavioral Indicators
Definition:
Signs derived from observing deviations in typical user or system activities that may
signal malicious or unauthorized behavior.
Examples:
• Unusual login times from a user suggest possible compromised credentials.
• Unexpected data access patterns inconsistent with job roles.
• Devices connecting to suspicious external domains outside of normal business
hours.
99. Incident Playbook
Definition:
A set of predefined, detailed instructions covering the lifecycle of specific incident
response actions crafted to standardize and expedite SOC reactions.
Examples:
• Playbooks for malware incidents include containment, eradication, and recovery
steps.
• Handling phishing incidents following prescribed email analysis and user
notifications.
• Playbooks updated with best practices from recent threat intelligence.
[Link] +919604647000 centermanager@[Link]
100. False Positive Rate
Definition:
The frequency at which security tools incorrectly flag benign activity as malicious,
impacting SOC efficiency.
Examples:
• Excessive false positives cause delays in investigating genuine threats.
• SIEM tuning reduces the false positive rate by refining detection logic.
• Automated tools implement risk scoring to lower false positive alerts.
[Link] +919604647000 centermanager@[Link]