26 terms

AAlert triage

The first assessment of an alert: true or false positive, how critical, which systems and accounts are affected. Good triage says more about a SOC's quality than its number of rules.

BBSI IT-Grundschutz

The methodology of the German Federal Office for Information Security, with modules and requirements for an appropriate security level — common in public sector and regulated industries.

CCompromise assessment

A time-boxed investigation into whether an environment is already compromised. Useful on suspicion, after acquisitions or before building continuous monitoring.

Compromise assessment

CContainment

Limiting an incident so the adversary cannot spread further — for example host isolation, disabling accounts or blocking connections. Containment buys time for analysis and recovery.

Incident response

EEDR

Endpoint Detection and Response: an agent on servers and clients that records process behaviour, detects suspicious activity and enables response actions such as isolation or process termination. Detection without operations has no effect.

EDR management

IIncident response

Structured reaction to a security incident: confirm, contain, preserve evidence, eradicate the root cause, restore operations and capture lessons learned.

Incident response

IIOC / IOA

An indicator of compromise describes traces of an attack (hash, domain, file path); an indicator of attack describes behaviour such as process chains. Behavioural indicators survive an adversary changing tools.

IISO/IEC 27001

The international standard for information security management systems. CyStrat operates an ISMS certified to ISO/IEC 27001, so security processes are audited and evidenced.

About us

IIT forensics

Court-proof examination of systems, storage media and malicious software to evidence the course, scope and entry point of an attack — including malware analysis of PE and ELF samples.

IT forensics

KKRITIS

Critical infrastructure such as energy, water, health or finance, subject to heightened legal requirements for availability, detection and reporting duties.

LLog source

A system that supplies security-relevant events: domain controllers, firewalls, proxies, EDR, cloud audit logs, VPN. Every missing source is a blind spot in detection.

MMDR

Managed Detection and Response: outsourced detection and response including analyst work. Unlike plain monitoring, MDR does not stop at the alert but performs triage, assessment and agreed countermeasures.

MDR & managed capacity

MMITRE ATT&CK

A public framework cataloguing adversary tactics and techniques. It provides a shared language to measure detection coverage, expose gaps and classify alerts.

Use-case development

NNIS2

An EU directive making requirements for risk management, reporting and evidence binding for many organisations. In practice it demands demonstrable detection, response and governance.

Consulting

PPenetration test

A time-boxed, authorised attack on defined systems to evidence exploitable weaknesses. It tests technology at a point in time, not detection capability in operations.

Red teaming

PPhishing

Deception via e-mail, chat or phone to obtain credentials, MFA codes or payments. Technical filters alone are not enough — awareness and reporting paths belong to it.

Security awareness

RRansomware

An attack that encrypts data and often exfiltrates it as well for double extortion. Critical factors are detection before encryption, verified backups and a rehearsed escalation.

Incident response

RRed teaming

A realistic, objective-driven attack simulation over a longer period that tests technology, processes and detection together. Unlike a penetration test it evaluates whether an attack is noticed and stopped.

Red teaming

SSIEM

Security Information and Event Management: a platform that collects, normalises and correlates logs from IT and security systems centrally and raises alerts through detection rules. A SIEM only detects what is onboarded as a log source and described in a use case.

SIEM monitoring

SSOAR

Security Orchestration, Automation and Response: automation of recurring analysis and response steps through playbooks. Automation handles enrichment and preparation; the decision on intrusive measures stays with the analyst.

SOAR

SSOC

Security Operations Center: the team, processes and technology that detect, assess and contain attacks around the clock. A SOC can be in-house, outsourced (managed SOC) or jointly operated (co-managed).

Managed SOC

TThreat intelligence

Structured information on adversaries, tooling and indicators. Threat intelligence becomes useful once it feeds detection rules, prioritisation and alert enrichment.

Threat intelligence

UUse case

A documented detection scenario: risk, required log sources, rule logic, thresholds, false-positive handling and response instructions. Use cases are why a SIEM delivers insight instead of merely storing data.

SIEM consulting

VVulnerability management

The continuous process of discovering, rating, prioritising and evidencing remediation of vulnerabilities — using exploitability and business criticality as the yardstick, not the CVSS score alone.

Vulnerability management

XXDR

Extended Detection and Response: extends the EDR approach to further telemetry such as identity, e-mail, network and cloud. What matters in practice is not the acronym but who actually analyses the signals.

ZZero-day

A vulnerability with no patch available at the time of exploitation. What matters then is fast inventory, temporary mitigations and targeted detection of exploitation attempts.

Case story: Log4j

Frequently asked questions

Common questions about security operations terminology.

What is the difference between SIEM and MDR?
A SIEM is the technology that collects logs and raises alerts. MDR is the service that has analysts assess and answer those alerts. A SIEM without operations produces alerts nobody reads.
What is the difference between EDR and antivirus?
Traditional antivirus blocks known malware. EDR records behaviour, detects attack patterns without a signature and enables response actions such as isolation.
Is a penetration test the same as red teaming?
No. A penetration test checks defined systems for weaknesses. Red teaming simulates a real attack over a longer period and also tests whether it is detected and stopped.
Do I need a SOC for NIS2?
NIS2 does not mandate a SOC, but it demands demonstrable detection, response and reporting capability. A managed or co-managed SOC is the most practical way to evidence this.
What does agentic AI mean in security operations?
Automated enrichment, pre-assessment and preparation of measures by AI components. The decision on intrusive measures is always made by an analyst.

Your question is not listed? Ask us