The vocabulary of a modern SOC.
101 terms across SOC, detection, threat, identity, cloud, compliance and AI, defined by practitioners. Each term has its own dedicated page with an extended explanation.
ABAC
Attribute-Based Access Control (ABAC) makes access decisions based on specific attributes. It considers properties of the user, the resource, the action, and the environment. How it works: Each access request is checked against rules that c…
Anomaly Detection
Anomaly detection identifies deviations from the normal behaviour of a system, account, or network. It finds unusual activities for which no fixed detection rule exists yet. How it works: A system first learns what normal behaviour is over…
APT
An Advanced Persistent Threat (APT) is an attacker group with significant time, money, and clear objectives. These attacks are often state-sponsored and can last for several months. How it works: APT groups carefully select their targets. T…
BEC
Business Email Compromise (BEC) is fraud carried out via business email. Attackers impersonate a senior executive, supplier, or partner to request payments to their own accounts. How it works: Attackers often start by taking over a legitima…
Blue Team
The Blue Team is the team that defends an organisation against attacks. This includes monitoring, detection, incident response and system hardening. How it works: The Blue Team operates defensive tools such as SIEM, EDR and identity protect…
BSI IT-Grundschutz
IT-Grundschutz is a standard from the German Federal Office for Information Security (BSI). It describes how organisations build and implement an information security management system using established measures. How it works: IT-Grundschut…
CIEM
Cloud Infrastructure Entitlement Management (CIEM) analyses and limits permissions in cloud environments. It shows which identities have which rights and which of them are in use. How it works: In the cloud, there are many identities: peopl…
Cloud Workload
A cloud workload is any application or computing power running in a cloud environment. This includes virtual machines, containers, serverless functions, and managed databases. How it works: Workloads operate on platforms like Azure, AWS, or…
CNAPP
A Cloud-Native Application Protection Platform (CNAPP) combines several cloud security functions on one platform. It typically unites CSPM, CIEM, CWPP and the scanning of code and images. How it works: The platform collects information on c…
Command and Control (C2)
Command and Control (C2) is the infrastructure attackers use to remotely control compromised systems. Via the C2 channel, they send commands and receive data. How it works: After an infection, malware establishes a connection to an attacker…
Conditional Access
Conditional Access regulates access based on conditions like user, device, location, and risk. The term originates from Microsoft Entra ID, but other identity providers offer the same principle. How it works: During each sign-in, the IdP ev…
Container Security
Container security involves protecting containers throughout their entire lifecycle. This starts with creating the image and extends to monitoring during live operation. How it works: A container is based on an image containing operating sy…
Correlation Rule
A correlation rule links several events into a single pattern before it triggers an Alert. It detects attacks composed of individual steps that appear harmless on their own. How it works: The rule observes events from one or more sources ov…
Credential Stuffing
Credential stuffing is an attack in which stolen username and password combinations are automatically tried on other services. The attack works because many people reuse their passwords across different platforms. How it works: Millions of…
CSPM
Cloud Security Posture Management (CSPM) continuously checks cloud environments for misconfigurations. It finds issues like publicly accessible storage, missing encryption, or overly permissive network rules. How it works: A CSPM reads the…
CTI
Cyber Threat Intelligence (CTI) is processed information about attackers, their tools, and their objectives. It helps a SOC to correctly classify Alerts and expand its detection capabilities. How it works: CTI exists on four levels. Technic…
CVE
Common Vulnerabilities and Exposures (CVE) is a global directory of publicly known security vulnerabilities. Each vulnerability receives its own identifier, such as CVE-2024-3400. How it works: The CVE programme is operated by MITRE and fun…
CWPP
A Cloud Workload Protection Platform (CWPP) protects the workloads within the cloud itself. This includes virtual machines, containers, and serverless functions. How it works: A CWPP monitors what is running on the workloads. It detects sus…
Data Exfiltration
Data exfiltration is the unauthorised transfer of data from an organisation. Attackers use the stolen information for extortion, espionage or resale. How it works: Attackers first gather valuable data like contracts, customer details or per…
Data Loss Prevention (DLP)
Data Loss Prevention (DLP) detects and prevents the unwanted exfiltration of confidential data. It monitors where sensitive information is stored, used and transferred. How it works: DLP solutions identify sensitive data using patterns, key…
DDoS
A Distributed Denial of Service (DDoS) attack overwhelms a service with requests from many sources. The goal is to make websites, online services, or network connections unavailable. How it works: Attackers use botnets of thousands of compr…
Deception Technology
Deception technology places specific decoys in the IT environment to deceive and detect attackers. These include fake credentials, files, accounts and even entire systems. How it works: A honeypot is a single decoy system. Deception technol…
Detection as Code
Detection as Code means that detection rules are developed, versioned, tested, and deployed like software. The rules reside in a repository and follow a defined process. How it works: Each rule is a file, for example in Sigma format or the…
Digital Forensics
Digital forensics is the legally sound preservation and analysis of digital evidence. After an incident, it clarifies what happened, how the attacker operated and which data was affected. How it works: First, evidence is secured: memory, ha…
DORA
The Digital Operational Resilience Act (DORA) is an EU regulation for the digital resilience of the financial sector. It has applied since 17 January 2025 to banks, insurance companies, investment firms, and many other financial entities in…
EDR
Endpoint Detection and Response (EDR) monitors activity on laptops, servers and virtual machines, intervening during attacks. It continuously records processes, file access and network connections. How it works: An agent on each device send…
Evaluation harness
An evaluation harness is a test environment for repeatedly measuring an AI system's quality. It assesses the system using a fixed collection of tasks with known correct answers. How it works: First, a test set is created from real, anonymis…
Exploit
An exploit is code or a method used to specifically take advantage of a vulnerability. It turns a theoretical flaw into a real attack. How it works: An exploit takes advantage of a flaw in software, configuration, or a protocol. The result…
FINMA
The Swiss Financial Market Supervisory Authority (FINMA) supervises banks, insurance companies, stock exchanges and other financial institutions in Switzerland. It also sets requirements for cybersecurity and operational resilience. How it…
GDPR
The General Data Protection Regulation (GDPR) has governed the handling of personal data within the EU since May 2018. It also applies to companies outside the EU offering goods or services to people in the EU or monitoring their behaviour…
Guardrail
A guardrail is a technical boundary that specifies what an AI system may and may not do. Guardrails prevent harmful outputs, unauthorised actions, and the leakage of confidential data. How it works: Guardrails operate at multiple stages. Be…
HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) is a US law for protecting health information. It applies to healthcare providers, health insurers, and clearinghouses in the USA, as well as their service providers, including…
Honeypot
A honeypot is a decoy system that looks realistic but has no productive purpose. Any access to it is suspicious and therefore provides a very clear signal. How it works: A honeypot can be a server, a service, or an entire environment. It is…
Human-in-the-loop
Human-in-the-loop means a person makes decisions or gives approvals at defined points in an automated process. The system prepares the action, while the human reviews it and takes responsibility for the outcome. How it works: An automated w…
Hyper Automation
Hyper Automation in the SOC refers to the consistent automation of all recurring steps. This includes enrichment, correlation, prioritisation, and pre-approved response actions. How it works: Every Alert first passes through an automated ch…
IaC Security
IaC Security checks Infrastructure as Code for security flaws before the infrastructure is created. This finds errors within the code, not in the live environment. How it works: Infrastructure as Code describes infrastructure in files using…
IAM
Identity and Access Management (IAM) governs who can access which systems and data. It covers accounts, roles, permissions, and the processes for joiners, movers, and leavers. How it works: Each person and every technical account receives a…
IdP
An Identity Provider (IdP) is the system that logs people in and confirms their identity to applications. Well-known examples include Microsoft Entra ID, Okta, and Google Workspace. How it works: A person logs in once to the IdP with a pass…
Incident Response
Incident Response covers all steps an organisation takes to detect, contain, eradicate, and learn from a security incident. The goal is to minimise damage and keep recovery times short. How it works: A phased approach following the classic…
Insider Threat
An insider threat originates from people with legitimate access to an organisation. These can be employees, former employees, service providers, or partners. How it works: A distinction is made between malicious and unintentional insiders.…
IOC
An Indicator of Compromise (IOC) is a technical characteristic that points towards a cyber attack. Typical examples include IP addresses, domains, file hashes or specific registry entries. How it works: After an incident, analysts document…
ISO 27001
ISO/IEC 27001 is the international standard for information security management systems (ISMS). Certification confirms that an organisation systematically manages risks and regularly reviews its security measures. How it works: The standard…
ITDR
Identity Threat Detection and Response (ITDR) is the discipline that detects and stops attacks on identities. These include accounts, tokens, sessions, permissions and identity providers. It complements EDR and SIEM with signals that only a…
Just-in-Time Access
Just-in-Time Access provides privileged rights only when needed and for a limited period. The rights are automatically revoked once this period expires. How it works: Admins do not have permanent elevated rights by default. They request the…
Kubernetes Security
Kubernetes Security involves protecting Kubernetes clusters and the applications running on them. This includes configuration, access, networking, images, and monitoring during operation. How it works: Kubernetes manages containers across m…
Lateral Movement
Lateral movement refers to an attacker moving from one compromised system to others on the network. The goal is to gain access to more valuable permissions and data. How it works: After initial access, an attacker is usually on a standard w…
LLM
A Large Language Model (LLM) is an AI model trained on very large amounts of text. It understands and generates language and can summarise, translate and classify texts and write code. How it works: An LLM predicts the most likely continuat…
LLM Jailbreak
An LLM jailbreak is an attempt to bypass a language model's safety guidelines. The goal is to make the model do or reveal things it should refuse. How it works: Providers and developers define what a model must not do. This includes harmful…
Log Source
A log source is a system that delivers log data to the SIEM or the SOC platform. Examples include firewalls, servers, identity providers, email services and cloud consoles. How it works: Every log source generates events in its own format.…
Malware
Malware is software developed with malicious intent. It steals data, gives attackers access, encrypts files or disrupts systems. How it works: Malware includes various types: viruses, worms, Trojans, ransomware, spyware and infostealers. It…
MDR
Managed Detection and Response (MDR) is a service that detects and actively contains threats. The focus is on endpoints and identities, often based on a specific EDR product. How it works: The MDR provider monitors EDR telemetry around the…
MFA
Multi-Factor Authentication (MFA) requires a second proof of identity in addition to a password for login. This can be an app confirmation, a code, a security key, or a biometric characteristic. How it works: MFA combines at least two facto…
MITRE ATT&CK
MITRE ATT&CK is a public knowledge base about the behaviour of attackers. It classifies real-world attack techniques by tactics and assigns each a fixed identifier, like T1566 for phishing. How it works: The US organisation MITRE maintains…
Model Poisoning
Model poisoning is the manipulation of an AI model through its training data or parameters. The model subsequently behaves incorrectly or according to the attacker's intentions in certain situations. How it works: An attacker introduces man…
MSSP
A Managed Security Service Provider (MSSP) operates security services for its clients, like firewalls, monitoring or vulnerability scans. Its focus is usually on operating technology rather than on investigating attacks. How it works: An MS…
MTTD
Mean Time to Detect (MTTD) is the average time from an attack's start to its detection. It shows how long an attacker can operate unnoticed within an environment. How it works: For each confirmed incident, the first malicious activity's tim…
MTTR
Mean Time to Respond (MTTR) is the average time from detecting an incident to its containment. It shows how quickly a Security Operations Center stops an attack. How it works: For each Case, the time is measured between detection and an eff…
NDR
Network Detection and Response (NDR) analyses network traffic to spot attacks that are invisible on devices. It evaluates connections and metadata without needing an agent on the systems. How it works: Sensors read traffic at central networ…
NIS2
NIS2 is an EU directive that sets minimum cybersecurity requirements for essential and important entities. Member states had to transpose it into national law by October 2024, and it significantly expands the previous NIS directive. How it…
OAuth 2.0
OAuth 2.0 is a standard allowing an application to access a user's resources without knowing their password. This access is granted using time-limited tokens. How it works: An application requests access to a person's mailbox or calendar. T…
PAM
Privileged Access Management (PAM) protects and controls accounts with extensive rights. These include domain admins, root accounts, cloud administrators, and highly privileged service accounts. How it works: PAM stores the credentials of p…
Passkeys
Passkeys are credentials that replace a password with a cryptographic key pair. They are bound to the respective website and are therefore resistant to phishing. How it works: When setting up a passkey, the device generates a key pair. The…
PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) defines security requirements for everyone who stores, processes, or transmits card data. It is published by the PCI Security Standards Council, which includes the major card organi…
Phishing
Phishing is an attempt to trick people with fake messages into clicking, entering data, or making a payment. It is one of the most common entry points for attacks on organisations. How it works: Attackers impersonate known senders like Micr…
Playbook
A playbook describes how a Security Operations Center reacts to a specific type of incident. It defines the steps, decision points, responsibilities, and permitted actions to be taken. How it works: Playbooks exist for common scenarios like…
Privilege Escalation
Privilege escalation refers to gaining higher permissions than an account or process is assigned. Attackers use it to change from a normal user to an administrator. How it works: There are two main types of escalation. Vertical escalation i…
Prompt Injection
Prompt injection is an attack on applications that use language models. The attacker inserts instructions that make the model deviate from its original directives. How it works: A language model does not reliably distinguish between develop…
Purple Team
In a Purple Team, attackers (Red Team) and defenders (Blue Team) collaborate openly. The goal is to test and directly improve detection capabilities step by step. How it works: The Red Team executes an attack technique, such as reading cred…
RAG
Retrieval-Augmented Generation (RAG) connects a language model to a specific knowledge source. Before responding, the system searches for relevant documents, and the model bases its answer on this content. How it works: Documents are broken…
Ransomware
Ransomware is malicious software that encrypts data and demands a ransom for decryption. Today, attackers usually also steal the data and threaten to publish it. How it works: A typical attack starts with stolen credentials, a phishing emai…
RBAC
Role-Based Access Control (RBAC) assigns access rights via roles instead of to individuals. A person receives one or more roles, and each role has defined permissions. How it works: Roles are usually based on functions like 'Accounting', 'H…
Red Team
A Red Team simulates a realistic attack against an organisation, as real attackers would conduct it. The goal is to test the overall detection and response, not to simply list individual vulnerabilities. How it works: The Red Team receives…
revFADP
The revised Federal Act on Data Protection (revFADP) governs personal data processing by private persons (individuals and companies) and federal bodies in Switzerland. It came into force on 1 September 2023 and is closely aligned with the G…
Runbook
A runbook is a technical, step-by-step guide for a specific task. It describes the exact commands or clicks needed within a particular system. How it works: Runbooks are the tools that a playbook calls upon. For example, a playbook might st…
SAML
Security Assertion Markup Language (SAML) is a standard for logging in via an Identity Provider. It enables Single Sign-On between organisations and applications. How it works: A person opens an application that supports SAML. The applicati…
SASE
Secure Access Service Edge (SASE) combines network and security functions in a single cloud service. Sites and mobile employees use it to connect securely to the internet, cloud and internal applications. How it works: Previously, traffic r…
Secrets Management
Secrets Management is the secure administration of passwords, API keys, certificates and tokens needed by applications and systems. The goal is to prevent secrets from being exposed in code or files. How it works: Secrets are stored in a ce…
Service Account
A service account is a technical account that is used by applications, services or scripts and does not belong to any person. It allows systems to authenticate with each other. How it works: Applications often require access to databases, f…
Shadow IT
Shadow IT describes applications, devices, and cloud services used without the IT department's knowledge or approval. It often arises because employees want to work more quickly or conveniently. How it works: A team might sign up for an onl…
SIEM
A Security Information and Event Management (SIEM) system collects logs from many sources, makes them searchable and analyses them with detection rules. It provides the core data foundation for a Security Operations Center. How it works: Th…
Sigma Rules
Sigma is an open format for writing detection rules independent of a specific SIEM. A Sigma rule can be translated into the query languages of various platforms. How it works: A Sigma rule is a text file in the YAML format. It describes the…
SOAR
Security Orchestration, Automation and Response (SOAR) is a platform that helps a SOC automate processes and connect tools. It executes playbooks and documents every step. How it works: SOAR connects to SIEM, EDR, email, identity, and ticke…
SOC
A Security Operations Center (SOC) is the team that continuously monitors an organisation's IT for attacks and intervenes during incidents. It combines analysts, processes, and tools like SIEM and EDR into a continuous operation. How it wor…
SOC 2
SOC 2 is an auditing standard from the US organisation AICPA for service providers that process customer data. An independent auditor assesses whether the controls for security and other criteria are suitable and effective. How it works: SO…
SOCaaS
SOC as a Service (SOCaaS) is a SOC run by an external provider and delivered as a continuous service. The organisation receives monitoring, detection and response without building its own round-the-clock team. How it works: The provider con…
SSO
Single Sign-On (SSO) allows users to sign in once and access many applications without further password entry. The authentication process is managed centrally by an Identity Provider. How it works: A user signs in to the Identity Provider (…
Supply Chain Attack
A supply chain attack targets an organisation through a supplier, service provider, or software it trusts. The attacker exploits this established trust to reach their intended target. How it works: There are several methods. Attackers might…
T1 / T2 / T3
T1, T2, and T3 refer to the three classic levels in a SOC. T1 triages alerts, T2 investigates incidents, and T3 handles complex cases, threat hunting, and detection engineering. How it works: T1 analysts work through a queue and check alert…
Tabletop Exercise
A tabletop exercise is a discussion-based session where a team talks through a simulated security incident. It tests procedures, decision-making, and communication without affecting live systems. How it works: A facilitator presents a scena…
Telemetry Pipeline
A telemetry pipeline collects, processes, and distributes security data before it reaches the SIEM or other systems. It controls what data flows where and in what format. How it works: A pipeline ingests data from multiple log sources. It n…
Threat Hunting
Threat Hunting is the targeted search for attackers who have not yet triggered an Alert. Analysts start with a hypothesis and actively test it against security data. How it works: A hunt begins with an assumption, such as: 'An attacker is u…
Tier-less SOC
A tier-less SOC forgoes the classic division into Level 1, 2, and 3 analysts. A Case remains with the same person or small team from the initial Alert until its resolution. How it works: In a traditional model, Level 1 analysts triage Alert…
TISAX
TISAX (Trusted Information Security Assessment Exchange) is an assessment and exchange procedure for information security in the automotive industry. The ENX Association operates it on behalf of the German Association of the Automotive Indu…
TTP
Tactics, Techniques, and Procedures (TTPs) describe how an attacker operates. Tactics are the goals, techniques the methods, and procedures the specific implementation by a particular group. How it works: A tactic could be 'stealing credent…
UEBA
User and Entity Behaviour Analytics (UEBA) detects unusual behaviour from people, accounts, and devices. It compares current activities against a baseline of learned, normal behaviour. How it works: UEBA analyses data over several weeks to…
Vulnerability Management
Vulnerability management is the ongoing process of finding weaknesses, assessing them, remediating them, and verifying their remediation. It is a continuous cycle, not a one-time project. How it works: Scanners regularly check servers, work…
XDR
Extended Detection and Response (XDR) connects signals from endpoints, identities, email, cloud and network in one platform. The goal is to view an attack across all areas as one cohesive incident. How it works: XDR usually builds on an EDR…
YARA Rules
YARA is a tool and rule format for identifying and classifying files based on patterns. It is primarily used to identify malware and its variants. How it works: A YARA rule describes a file's typical characteristics, like specific text stri…
Zero Trust
Zero Trust is a security model where no access is automatically considered trustworthy. Every request is verified based on identity, device, and context, even inside the internal network. How it works: Traditional networks trust everything…
Zero-Day
A zero-day vulnerability is a security flaw exploited by attackers before the manufacturer provides a patch. The name comes from defenders having zero days of advance warning. How it works: Attackers discover a vulnerability themselves or b…
ZTNA
Zero Trust Network Access (ZTNA) grants access to individual internal applications, not entire networks. Every connection is verified based on identity, device, and context. How it works: With a classic VPN, a device is inside the internal…