Learn · Glossary

The vocabulary of a modern SOC.

101 terms across SOC, detection, threat, identity, cloud, compliance and AI, defined by practitioners. Each term has its own dedicated page with an extended explanation.

SOC18Detection15Threat22Identity15Cloud12Compliance11AI8

ABAC

Attribute-Based Access Control (ABAC) makes access decisions based on user, resource, and environmental attributes.
Identity

Attribute-Based Access Control (ABAC) makes access decisions based on specific attributes. It considers properties of the user, the resource, the action, and the environment. How it works: Each access request is checked against rules that c…

Read more →

Anomaly Detection

Anomaly detection identifies deviations from the usual behaviour of accounts, devices, or network traffic and reports them for review.
Detection

Anomaly detection identifies deviations from the normal behaviour of a system, account, or network. It finds unusual activities for which no fixed detection rule exists yet. How it works: A system first learns what normal behaviour is over…

Read more →

APT

An Advanced Persistent Threat (APT) is an attacker group with significant time, money, and clear objectives.
Threat

An Advanced Persistent Threat (APT) is an attacker group with significant time, money, and clear objectives. These attacks are often state-sponsored and can last for several months. How it works: APT groups carefully select their targets. T…

Read more →

BEC

Business Email Compromise is a type of corporate fraud where attackers trick staff into making payments to accounts controlled by the attackers.
Threat

Business Email Compromise (BEC) is fraud carried out via business email. Attackers impersonate a senior executive, supplier, or partner to request payments to their own accounts. How it works: Attackers often start by taking over a legitima…

Read more →

Blue Team

The Blue Team defends an organisation's IT, detects attacks and responds to security incidents.
SOC

The Blue Team is the team that defends an organisation against attacks. This includes monitoring, detection, incident response and system hardening. How it works: The Blue Team operates defensive tools such as SIEM, EDR and identity protect…

Read more →

BSI IT-Grundschutz

BSI IT-Grundschutz is the German BSI's methodology for information security, mainly serving as a reference in Switzerland.
Compliance

IT-Grundschutz is a standard from the German Federal Office for Information Security (BSI). It describes how organisations build and implement an information security management system using established measures. How it works: IT-Grundschut…

Read more →

CIEM

Cloud Infrastructure Entitlement Management analyses and manages permissions for identities in cloud environments.
Cloud

Cloud Infrastructure Entitlement Management (CIEM) analyses and limits permissions in cloud environments. It shows which identities have which rights and which of them are in use. How it works: In the cloud, there are many identities: peopl…

Read more →

Cloud Workload

A cloud workload is an application, service, or function that runs in a cloud environment.
Cloud

A cloud workload is any application or computing power running in a cloud environment. This includes virtual machines, containers, serverless functions, and managed databases. How it works: Workloads operate on platforms like Azure, AWS, or…

Read more →

CNAPP

A Cloud-Native Application Protection Platform (CNAPP) bundles multiple cloud security functions into one single platform.
Cloud

A Cloud-Native Application Protection Platform (CNAPP) combines several cloud security functions on one platform. It typically unites CSPM, CIEM, CWPP and the scanning of code and images. How it works: The platform collects information on c…

Read more →

Command and Control (C2)

Command and Control (C2) is the channel attackers use to remotely control compromised systems and exfiltrate data.
Threat

Command and Control (C2) is the infrastructure attackers use to remotely control compromised systems. Via the C2 channel, they send commands and receive data. How it works: After an infection, malware establishes a connection to an attacker…

Read more →

Conditional Access

Conditional Access is a form of policy-based access control for user sign-ins and sessions.
Identity

Conditional Access regulates access based on conditions like user, device, location, and risk. The term originates from Microsoft Entra ID, but other identity providers offer the same principle. How it works: During each sign-in, the IdP ev…

Read more →

Container Security

Container security protects containers throughout their entire lifecycle, from the image through to deployment and operation.
Cloud

Container security involves protecting containers throughout their entire lifecycle. This starts with creating the image and extends to monitoring during live operation. How it works: A container is based on an image containing operating sy…

Read more →

Correlation Rule

A correlation rule links events from various sources and triggers an Alert when a defined pattern is matched.
Detection

A correlation rule links several events into a single pattern before it triggers an Alert. It detects attacks composed of individual steps that appear harmless on their own. How it works: The rule observes events from one or more sources ov…

Read more →

Credential Stuffing

Credential stuffing automatically tests stolen username and password combinations across many online services.
Threat

Credential stuffing is an attack in which stolen username and password combinations are automatically tried on other services. The attack works because many people reuse their passwords across different platforms. How it works: Millions of…

Read more →

CSPM

Cloud Security Posture Management (CSPM) continuously scans cloud environments for security misconfigurations and potential risks.
Cloud

Cloud Security Posture Management (CSPM) continuously checks cloud environments for misconfigurations. It finds issues like publicly accessible storage, missing encryption, or overly permissive network rules. How it works: A CSPM reads the…

Read more →

CTI

Cyber Threat Intelligence (CTI) provides processed information about attackers, their tools, and their objectives.
Threat

Cyber Threat Intelligence (CTI) is processed information about attackers, their tools, and their objectives. It helps a SOC to correctly classify Alerts and expand its detection capabilities. How it works: CTI exists on four levels. Technic…

Read more →

CVE

CVE is the global directory of publicly known security vulnerabilities where each vulnerability receives its own identifier.
Threat

Common Vulnerabilities and Exposures (CVE) is a global directory of publicly known security vulnerabilities. Each vulnerability receives its own identifier, such as CVE-2024-3400. How it works: The CVE programme is operated by MITRE and fun…

Read more →

CWPP

A Cloud Workload Protection Platform (CWPP) protects the workloads running within a cloud environment.
Cloud

A Cloud Workload Protection Platform (CWPP) protects the workloads within the cloud itself. This includes virtual machines, containers, and serverless functions. How it works: A CWPP monitors what is running on the workloads. It detects sus…

Read more →

Data Exfiltration

Data exfiltration is the unauthorised removal of data from an organisation, often for extortion purposes.
Threat

Data exfiltration is the unauthorised transfer of data from an organisation. Attackers use the stolen information for extortion, espionage or resale. How it works: Attackers first gather valuable data like contracts, customer details or per…

Read more →

Data Loss Prevention (DLP)

Data Loss Prevention (DLP) detects and prevents confidential data from leaving an organisation without authorisation.
Threat

Data Loss Prevention (DLP) detects and prevents the unwanted exfiltration of confidential data. It monitors where sensitive information is stored, used and transferred. How it works: DLP solutions identify sensitive data using patterns, key…

Read more →

DDoS

A DDoS attack overloads an online service with a flood of requests from many sources until it becomes unavailable.
Threat

A Distributed Denial of Service (DDoS) attack overwhelms a service with requests from many sources. The goal is to make websites, online services, or network connections unavailable. How it works: Attackers use botnets of thousands of compr…

Read more →

Deception Technology

Deception technology distributes decoys like fake credentials and files across the network to detect attackers early.
Detection

Deception technology places specific decoys in the IT environment to deceive and detect attackers. These include fake credentials, files, accounts and even entire systems. How it works: A honeypot is a single decoy system. Deception technol…

Read more →

Detection as Code

Detection as Code manages detection rules like software: versioned, tested, reviewed and deployed automatically.
Detection

Detection as Code means that detection rules are developed, versioned, tested, and deployed like software. The rules reside in a repository and follow a defined process. How it works: Each rule is a file, for example in Sigma format or the…

Read more →

Digital Forensics

Digital forensics secures and investigates digital traces so an incident can be reconstructed and used as evidence.
SOC

Digital forensics is the legally sound preservation and analysis of digital evidence. After an incident, it clarifies what happened, how the attacker operated and which data was affected. How it works: First, evidence is secured: memory, ha…

Read more →

DORA

The Digital Operational Resilience Act (DORA) is an EU regulation for the digital resilience of the financial sector.
Compliance

The Digital Operational Resilience Act (DORA) is an EU regulation for the digital resilience of the financial sector. It has applied since 17 January 2025 to banks, insurance companies, investment firms, and many other financial entities in…

Read more →

EDR

Endpoint Detection and Response (EDR) monitors activities on devices like laptops and servers, enabling intervention during attacks.
Detection

Endpoint Detection and Response (EDR) monitors activity on laptops, servers and virtual machines, intervening during attacks. It continuously records processes, file access and network connections. How it works: An agent on each device send…

Read more →

Evaluation harness

An evaluation harness is an automated test suite that measures the performance of an AI agent against predefined tasks.
AI

An evaluation harness is a test environment for repeatedly measuring an AI system's quality. It assesses the system using a fixed collection of tasks with known correct answers. How it works: First, a test set is created from real, anonymis…

Read more →

Exploit

An exploit is code or a method that deliberately exploits a security vulnerability to compromise a system or gain higher privileges.
Threat

An exploit is code or a method used to specifically take advantage of a vulnerability. It turns a theoretical flaw into a real attack. How it works: An exploit takes advantage of a flaw in software, configuration, or a protocol. The result…

Read more →

FINMA

The Swiss Financial Market Supervisory Authority (FINMA) supervises financial institutions and sets their cybersecurity requirements.
Compliance

The Swiss Financial Market Supervisory Authority (FINMA) supervises banks, insurance companies, stock exchanges and other financial institutions in Switzerland. It also sets requirements for cybersecurity and operational resilience. How it…

Read more →

GDPR

The EU's General Data Protection Regulation governs how organisations process the personal data of individuals inside the EU.
Compliance

The General Data Protection Regulation (GDPR) has governed the handling of personal data within the EU since May 2018. It also applies to companies outside the EU offering goods or services to people in the EU or monitoring their behaviour…

Read more →

Guardrail

Guardrails are technical boundaries that define what an AI agent is permitted to do.
AI

A guardrail is a technical boundary that specifies what an AI system may and may not do. Guardrails prevent harmful outputs, unauthorised actions, and the leakage of confidential data. How it works: Guardrails operate at multiple stages. Be…

Read more →

HIPAA

HIPAA is a US law protecting health data that can also affect Swiss firms with US clients.
Compliance

The Health Insurance Portability and Accountability Act (HIPAA) is a US law for protecting health information. It applies to healthcare providers, health insurers, and clearinghouses in the USA, as well as their service providers, including…

Read more →

Honeypot

A honeypot is a decoy system with no productive purpose, so its use almost always indicates an attacker.
Detection

A honeypot is a decoy system that looks realistic but has no productive purpose. Any access to it is suspicious and therefore provides a very clear signal. How it works: A honeypot can be a server, a service, or an entire environment. It is…

Read more →

Human-in-the-loop

Human-in-the-loop means that a person makes the most critical decisions within an automated process.
AI

Human-in-the-loop means a person makes decisions or gives approvals at defined points in an automated process. The system prepares the action, while the human reviews it and takes responsibility for the outcome. How it works: An automated w…

Read more →

Hyper Automation

Hyper Automation is the consistent, end-to-end automation of all recurring tasks in a Security Operations Center.
SOC

Hyper Automation in the SOC refers to the consistent automation of all recurring steps. This includes enrichment, correlation, prioritisation, and pre-approved response actions. How it works: Every Alert first passes through an automated ch…

Read more →

IaC Security

IaC Security checks Infrastructure as Code for misconfigurations and vulnerabilities before infrastructure is deployed.
Cloud

IaC Security checks Infrastructure as Code for security flaws before the infrastructure is created. This finds errors within the code, not in the live environment. How it works: Infrastructure as Code describes infrastructure in files using…

Read more →

IAM

Identity and Access Management (IAM) controls who can access specific systems and data within an organisation.
Identity

Identity and Access Management (IAM) governs who can access which systems and data. It covers accounts, roles, permissions, and the processes for joiners, movers, and leavers. How it works: Each person and every technical account receives a…

Read more →

IdP

An Identity Provider (IdP) is the system that authenticates users and confirms their identity to applications.
Identity

An Identity Provider (IdP) is the system that logs people in and confirms their identity to applications. Well-known examples include Microsoft Entra ID, Okta, and Google Workspace. How it works: A person logs in once to the IdP with a pass…

Read more →

Incident Response

Incident Response is the structured process of containing, eradicating, and recovering from a security incident.
SOC

Incident Response covers all steps an organisation takes to detect, contain, eradicate, and learn from a security incident. The goal is to minimise damage and keep recovery times short. How it works: A phased approach following the classic…

Read more →

Insider Threat

An insider threat comes from individuals with legitimate access who misuse it, either intentionally or negligently.
Threat

An insider threat originates from people with legitimate access to an organisation. These can be employees, former employees, service providers, or partners. How it works: A distinction is made between malicious and unintentional insiders.…

Read more →

IOC

An Indicator of Compromise (IOC) is a technical characteristic that indicates a potential security breach.
Threat

An Indicator of Compromise (IOC) is a technical characteristic that points towards a cyber attack. Typical examples include IP addresses, domains, file hashes or specific registry entries. How it works: After an incident, analysts document…

Read more →

ISO 27001

ISO 27001 is the international standard for information security management systems. Certification confirms that risks are managed systematically.
Compliance

ISO/IEC 27001 is the international standard for information security management systems (ISMS). Certification confirms that an organisation systematically manages risks and regularly reviews its security measures. How it works: The standard…

Read more →

ITDR

Identity Threat Detection and Response (ITDR) detects and stops attacks on accounts, tokens, sessions and identity providers.
Identity

Identity Threat Detection and Response (ITDR) is the discipline that detects and stops attacks on identities. These include accounts, tokens, sessions, permissions and identity providers. It complements EDR and SIEM with signals that only a…

Read more →

Just-in-Time Access

Just-in-Time Access grants privileged rights only when required and for a short time, automatically revoking them afterwards.
Identity

Just-in-Time Access provides privileged rights only when needed and for a limited period. The rights are automatically revoked once this period expires. How it works: Admins do not have permanent elevated rights by default. They request the…

Read more →

Kubernetes Security

Kubernetes Security protects clusters and their applications through secure configuration, access control, and operational monitoring.
Cloud

Kubernetes Security involves protecting Kubernetes clusters and the applications running on them. This includes configuration, access, networking, images, and monitoring during operation. How it works: Kubernetes manages containers across m…

Read more →

Lateral Movement

Lateral Movement describes how attackers move from system to system and escalate privileges after initial access.
Threat

Lateral movement refers to an attacker moving from one compromised system to others on the network. The goal is to gain access to more valuable permissions and data. How it works: After initial access, an attacker is usually on a standard w…

Read more →

LLM

A Large Language Model (LLM) is an AI model trained on vast amounts of text to understand and generate language.
AI

A Large Language Model (LLM) is an AI model trained on very large amounts of text. It understands and generates language and can summarise, translate and classify texts and write code. How it works: An LLM predicts the most likely continuat…

Read more →

LLM Jailbreak

An LLM jailbreak bypasses a language model's safety mechanisms, making it provide content it should refuse.
AI

An LLM jailbreak is an attempt to bypass a language model's safety guidelines. The goal is to make the model do or reveal things it should refuse. How it works: Providers and developers define what a model must not do. This includes harmful…

Read more →

Log Source

A log source is any system that provides security-relevant events to a SIEM or the SOC.
Detection

A log source is a system that delivers log data to the SIEM or the SOC platform. Examples include firewalls, servers, identity providers, email services and cloud consoles. How it works: Every log source generates events in its own format.…

Read more →

Malware

Malware is the umbrella term for malicious software such as ransomware, Trojans or infostealers that damage systems or steal data.
Threat

Malware is software developed with malicious intent. It steals data, gives attackers access, encrypts files or disrupts systems. How it works: Malware includes various types: viruses, worms, Trojans, ransomware, spyware and infostealers. It…

Read more →

MDR

Managed Detection and Response (MDR) is a service that detects threats and actively contains them.
SOC

Managed Detection and Response (MDR) is a service that detects and actively contains threats. The focus is on endpoints and identities, often based on a specific EDR product. How it works: The MDR provider monitors EDR telemetry around the…

Read more →

MFA

Multi-Factor Authentication requires a second form of verification in addition to a password during login.
Identity

Multi-Factor Authentication (MFA) requires a second proof of identity in addition to a password for login. This can be an app confirmation, a code, a security key, or a biometric characteristic. How it works: MFA combines at least two facto…

Read more →

MITRE ATT&CK

MITRE ATT&CK is a publicly accessible knowledge base of adversarial tactics and techniques based on real-world observations.
Threat

MITRE ATT&CK is a public knowledge base about the behaviour of attackers. It classifies real-world attack techniques by tactics and assigns each a fixed identifier, like T1566 for phishing. How it works: The US organisation MITRE maintains…

Read more →

Model Poisoning

Model poisoning manipulates the training or knowledge data of an AI model to alter its behaviour in a targeted way.
AI

Model poisoning is the manipulation of an AI model through its training data or parameters. The model subsequently behaves incorrectly or according to the attacker's intentions in certain situations. How it works: An attacker introduces man…

Read more →

MSSP

A Managed Security Service Provider (MSSP) operates specific security services for its clients, such as firewalls or monitoring.
SOC

A Managed Security Service Provider (MSSP) operates security services for its clients, like firewalls, monitoring or vulnerability scans. Its focus is usually on operating technology rather than on investigating attacks. How it works: An MS…

Read more →

MTTD

Mean Time to Detect (MTTD) is the average time from the start of an attack to its detection.
SOC

Mean Time to Detect (MTTD) is the average time from an attack's start to its detection. It shows how long an attacker can operate unnoticed within an environment. How it works: For each confirmed incident, the first malicious activity's tim…

Read more →

MTTR

Mean Time to Respond (MTTR) is the average time from when an incident is detected until it is contained.
SOC

Mean Time to Respond (MTTR) is the average time from detecting an incident to its containment. It shows how quickly a Security Operations Center stops an attack. How it works: For each Case, the time is measured between detection and an eff…

Read more →

NDR

Network Detection and Response (NDR) analyses network traffic to detect attacks, without needing an agent on the systems.
Detection

Network Detection and Response (NDR) analyses network traffic to spot attacks that are invisible on devices. It evaluates connections and metadata without needing an agent on the systems. How it works: Sensors read traffic at central networ…

Read more →

NIS2

NIS2 is a European Union directive setting minimum cybersecurity requirements for important and essential entities.
Compliance

NIS2 is an EU directive that sets minimum cybersecurity requirements for essential and important entities. Member states had to transpose it into national law by October 2024, and it significantly expands the previous NIS directive. How it…

Read more →

OAuth 2.0

OAuth 2.0 is a standard that allows an application to access data on a person's behalf without knowing their password.
Identity

OAuth 2.0 is a standard allowing an application to access a user's resources without knowing their password. This access is granted using time-limited tokens. How it works: An application requests access to a person's mailbox or calendar. T…

Read more →

PAM

Privileged Access Management (PAM) protects and controls accounts that have extensive system rights.
Identity

Privileged Access Management (PAM) protects and controls accounts with extensive rights. These include domain admins, root accounts, cloud administrators, and highly privileged service accounts. How it works: PAM stores the credentials of p…

Read more →

Passkeys

Passkeys replace passwords with cryptographic key pairs, effectively protecting logins against phishing.
Identity

Passkeys are credentials that replace a password with a cryptographic key pair. They are bound to the respective website and are therefore resistant to phishing. How it works: When setting up a passkey, the device generates a key pair. The…

Read more →

PCI DSS

PCI DSS is the security standard from the card organisations for anyone who stores, processes, or transmits card data.
Compliance

The Payment Card Industry Data Security Standard (PCI DSS) defines security requirements for everyone who stores, processes, or transmits card data. It is published by the PCI Security Standards Council, which includes the major card organi…

Read more →

Phishing

Phishing is an attack that uses fake emails and messages to trick people into taking an action.
Threat

Phishing is an attempt to trick people with fake messages into clicking, entering data, or making a payment. It is one of the most common entry points for attacks on organisations. How it works: Attackers impersonate known senders like Micr…

Read more →

Playbook

A playbook is a predefined procedure describing how a SOC responds to a specific type of security incident.
SOC

A playbook describes how a Security Operations Center reacts to a specific type of incident. It defines the steps, decision points, responsibilities, and permitted actions to be taken. How it works: Playbooks exist for common scenarios like…

Read more →

Privilege Escalation

Privilege escalation describes the process of gaining higher permissions than an account or process is assigned.
Threat

Privilege escalation refers to gaining higher permissions than an account or process is assigned. Attackers use it to change from a normal user to an administrator. How it works: There are two main types of escalation. Vertical escalation i…

Read more →

Prompt Injection

Prompt injection inserts hidden instructions into a language model's input, causing it to perform unintended actions.
AI

Prompt injection is an attack on applications that use language models. The attacker inserts instructions that make the model deviate from its original directives. How it works: A language model does not reliably distinguish between develop…

Read more →

Purple Team

A Purple Team combines a Red Team and a Blue Team, allowing insights from attacks to directly improve detection rules.
SOC

In a Purple Team, attackers (Red Team) and defenders (Blue Team) collaborate openly. The goal is to test and directly improve detection capabilities step by step. How it works: The Red Team executes an attack technique, such as reading cred…

Read more →

RAG

Retrieval-Augmented Generation connects a language model with a knowledge source, basing its answers on retrieved documents.
AI

Retrieval-Augmented Generation (RAG) connects a language model to a specific knowledge source. Before responding, the system searches for relevant documents, and the model bases its answer on this content. How it works: Documents are broken…

Read more →

Ransomware

Ransomware is malicious software that encrypts data and demands a ransom for decryption.
Threat

Ransomware is malicious software that encrypts data and demands a ransom for decryption. Today, attackers usually also steal the data and threaten to publish it. How it works: A typical attack starts with stolen credentials, a phishing emai…

Read more →

RBAC

Role-Based Access Control (RBAC) assigns access rights through roles based on functions within an organisation.
Identity

Role-Based Access Control (RBAC) assigns access rights via roles instead of to individuals. A person receives one or more roles, and each role has defined permissions. How it works: Roles are usually based on functions like 'Accounting', 'H…

Read more →

Red Team

A Red Team simulates a realistic attack to test an organisation's detection and response capabilities under real-world conditions.
SOC

A Red Team simulates a realistic attack against an organisation, as real attackers would conduct it. The goal is to test the overall detection and response, not to simply list individual vulnerabilities. How it works: The Red Team receives…

Read more →

revFADP

The revFADP is the revised Swiss Federal Act on Data Protection, which governs personal data processing.
Compliance

The revised Federal Act on Data Protection (revFADP) governs personal data processing by private persons (individuals and companies) and federal bodies in Switzerland. It came into force on 1 September 2023 and is closely aligned with the G…

Read more →

Runbook

A runbook is a detailed operational procedure outlining the technical steps for a specific task.
SOC

A runbook is a technical, step-by-step guide for a specific task. It describes the exact commands or clicks needed within a particular system. How it works: Runbooks are the tools that a playbook calls upon. For example, a playbook might st…

Read more →

SAML

SAML is an open standard that allows an Identity Provider to pass signed authentication assertions to applications, enabling Single Sign-On.
Identity

Security Assertion Markup Language (SAML) is a standard for logging in via an Identity Provider. It enables Single Sign-On between organisations and applications. How it works: A person opens an application that supports SAML. The applicati…

Read more →

SASE

SASE (Secure Access Service Edge) combines network and security functions into a single, cloud-delivered service.
Cloud

Secure Access Service Edge (SASE) combines network and security functions in a single cloud service. Sites and mobile employees use it to connect securely to the internet, cloud and internal applications. How it works: Previously, traffic r…

Read more →

Secrets Management

Secrets Management centrally manages passwords, API keys, tokens and certificates securely and with traceable access.
Cloud

Secrets Management is the secure administration of passwords, API keys, certificates and tokens needed by applications and systems. The goal is to prevent secrets from being exposed in code or files. How it works: Secrets are stored in a ce…

Read more →

Service Account

A service account is a technical account used by applications and services to access systems and data.
Identity

A service account is a technical account that is used by applications, services or scripts and does not belong to any person. It allows systems to authenticate with each other. How it works: Applications often require access to databases, f…

Read more →

Shadow IT

Shadow IT refers to software, cloud services, and devices that employees use without the IT department's approval.
Cloud

Shadow IT describes applications, devices, and cloud services used without the IT department's knowledge or approval. It often arises because employees want to work more quickly or conveniently. How it works: A team might sign up for an onl…

Read more →

SIEM

A Security Information and Event Management (SIEM) system collects logs from many sources, makes them searchable and analyses them with detection rules.
Detection

A Security Information and Event Management (SIEM) system collects logs from many sources, makes them searchable and analyses them with detection rules. It provides the core data foundation for a Security Operations Center. How it works: Th…

Read more →

Sigma Rules

Sigma rules describe detection logic for logs in an open format that can be translated for many SIEM platforms.
Detection

Sigma is an open format for writing detection rules independent of a specific SIEM. A Sigma rule can be translated into the query languages of various platforms. How it works: A Sigma rule is a text file in the YAML format. It describes the…

Read more →

SOAR

Security Orchestration, Automation and Response (SOAR) platforms help a SOC to automate procedures and connect tools together.
Detection

Security Orchestration, Automation and Response (SOAR) is a platform that helps a SOC automate processes and connect tools. It executes playbooks and documents every step. How it works: SOAR connects to SIEM, EDR, email, identity, and ticke…

Read more →

SOC

A Security Operations Center (SOC) is the team that constantly monitors an organisation's IT for attacks and intervenes during incidents.
SOC

A Security Operations Center (SOC) is the team that continuously monitors an organisation's IT for attacks and intervenes during incidents. It combines analysts, processes, and tools like SIEM and EDR into a continuous operation. How it wor…

Read more →

SOC 2

SOC 2 is a US auditing standard that assesses the security controls of service providers against the Trust Services Criteria.
Compliance

SOC 2 is an auditing standard from the US organisation AICPA for service providers that process customer data. An independent auditor assesses whether the controls for security and other criteria are suitable and effective. How it works: SO…

Read more →

SOCaaS

SOC as a Service (SOCaaS) is a SOC operated by an external provider and delivered as an ongoing service.
SOC

SOC as a Service (SOCaaS) is a SOC run by an external provider and delivered as a continuous service. The organisation receives monitoring, detection and response without building its own round-the-clock team. How it works: The provider con…

Read more →

SSO

Single Sign-On (SSO) allows users to sign in once and access multiple applications without entering another password.
Identity

Single Sign-On (SSO) allows users to sign in once and access many applications without further password entry. The authentication process is managed centrally by an Identity Provider. How it works: A user signs in to the Identity Provider (…

Read more →

Supply Chain Attack

A supply chain attack targets an organisation through a trusted supplier, software, or service provider with access.
Threat

A supply chain attack targets an organisation through a supplier, service provider, or software it trusts. The attacker exploits this established trust to reach their intended target. How it works: There are several methods. Attackers might…

Read more →

T1 / T2 / T3

T1, T2, and T3 are the classic tiered roles for analysts within a Security Operations Center.
SOC

T1, T2, and T3 refer to the three classic levels in a SOC. T1 triages alerts, T2 investigates incidents, and T3 handles complex cases, threat hunting, and detection engineering. How it works: T1 analysts work through a queue and check alert…

Read more →

Tabletop Exercise

A tabletop exercise simulates a security incident to test roles, decisions, and communication in a real emergency.
SOC

A tabletop exercise is a discussion-based session where a team talks through a simulated security incident. It tests procedures, decision-making, and communication without affecting live systems. How it works: A facilitator presents a scena…

Read more →

Telemetry Pipeline

A telemetry pipeline collects, filters, and routes logs and events before they are analysed in the SIEM or SOC.
Detection

A telemetry pipeline collects, processes, and distributes security data before it reaches the SIEM or other systems. It controls what data flows where and in what format. How it works: A pipeline ingests data from multiple log sources. It n…

Read more →

Threat Hunting

Threat Hunting is the targeted search for attackers within a network who have not yet triggered a detection.
SOC

Threat Hunting is the targeted search for attackers who have not yet triggered an Alert. Analysts start with a hypothesis and actively test it against security data. How it works: A hunt begins with an assumption, such as: 'An attacker is u…

Read more →

Tier-less SOC

A Tier-less SOC is a model that operates without the traditional T1, T2, and T3 analyst hierarchy.
SOC

A tier-less SOC forgoes the classic division into Level 1, 2, and 3 analysts. A Case remains with the same person or small team from the initial Alert until its resolution. How it works: In a traditional model, Level 1 analysts triage Alert…

Read more →

TISAX

TISAX is the assessment standard of the automotive industry for information security at suppliers and service providers.
Compliance

TISAX (Trusted Information Security Assessment Exchange) is an assessment and exchange procedure for information security in the automotive industry. The ENX Association operates it on behalf of the German Association of the Automotive Indu…

Read more →

TTP

Tactics, Techniques and Procedures (TTPs) describe how an attacker operates, from their goals to the concrete implementation.
Threat

Tactics, Techniques, and Procedures (TTPs) describe how an attacker operates. Tactics are the goals, techniques the methods, and procedures the specific implementation by a particular group. How it works: A tactic could be 'stealing credent…

Read more →

UEBA

User and Entity Behaviour Analytics (UEBA) detects unusual user and device activity by establishing a baseline of normal behaviour.
Detection

User and Entity Behaviour Analytics (UEBA) detects unusual behaviour from people, accounts, and devices. It compares current activities against a baseline of learned, normal behaviour. How it works: UEBA analyses data over several weeks to…

Read more →

Vulnerability Management

Vulnerability management is the ongoing process of finding weaknesses, assessing them by risk, and verifying their remediation.
Threat

Vulnerability management is the ongoing process of finding weaknesses, assessing them, remediating them, and verifying their remediation. It is a continuous cycle, not a one-time project. How it works: Scanners regularly check servers, work…

Read more →

XDR

Extended Detection and Response (XDR) connects security signals from endpoints, identities, email, cloud and network in one platform.
Detection

Extended Detection and Response (XDR) connects signals from endpoints, identities, email, cloud and network in one platform. The goal is to view an attack across all areas as one cohesive incident. How it works: XDR usually builds on an EDR…

Read more →

YARA Rules

YARA rules describe patterns in files and memory used to detect and classify malware.
Detection

YARA is a tool and rule format for identifying and classifying files based on patterns. It is primarily used to identify malware and its variants. How it works: A YARA rule describes a file's typical characteristics, like specific text stri…

Read more →

Zero Trust

Zero Trust is a security model in which no access is automatically considered trustworthy.
Identity

Zero Trust is a security model where no access is automatically considered trustworthy. Every request is verified based on identity, device, and context, even inside the internal network. How it works: Traditional networks trust everything…

Read more →

Zero-Day

A zero-day is a security vulnerability that is exploited before the manufacturer provides a patch.
Threat

A zero-day vulnerability is a security flaw exploited by attackers before the manufacturer provides a patch. The name comes from defenders having zero days of advance warning. How it works: Attackers discover a vulnerability themselves or b…

Read more →

ZTNA

Zero Trust Network Access (ZTNA) connects users securely to specific applications without exposing the entire network.
Cloud

Zero Trust Network Access (ZTNA) grants access to individual internal applications, not entire networks. Every connection is verified based on identity, device, and context. How it works: With a classic VPN, a device is inside the internal…

Read more →