AAlert triage
The first assessment of an alert: true or false positive, how critical, which systems and accounts are affected. Good triage says more about a SOC's quality than its number of rules.
The vocabulary of security operations, explained concisely — with clear distinctions instead of buzzword bingo.
26 terms
No term found.
The first assessment of an alert: true or false positive, how critical, which systems and accounts are affected. Good triage says more about a SOC's quality than its number of rules.
The methodology of the German Federal Office for Information Security, with modules and requirements for an appropriate security level — common in public sector and regulated industries.
A time-boxed investigation into whether an environment is already compromised. Useful on suspicion, after acquisitions or before building continuous monitoring.
Limiting an incident so the adversary cannot spread further — for example host isolation, disabling accounts or blocking connections. Containment buys time for analysis and recovery.
Endpoint Detection and Response: an agent on servers and clients that records process behaviour, detects suspicious activity and enables response actions such as isolation or process termination. Detection without operations has no effect.
Structured reaction to a security incident: confirm, contain, preserve evidence, eradicate the root cause, restore operations and capture lessons learned.
An indicator of compromise describes traces of an attack (hash, domain, file path); an indicator of attack describes behaviour such as process chains. Behavioural indicators survive an adversary changing tools.
The international standard for information security management systems. CyStrat operates an ISMS certified to ISO/IEC 27001, so security processes are audited and evidenced.
Court-proof examination of systems, storage media and malicious software to evidence the course, scope and entry point of an attack — including malware analysis of PE and ELF samples.
Critical infrastructure such as energy, water, health or finance, subject to heightened legal requirements for availability, detection and reporting duties.
A system that supplies security-relevant events: domain controllers, firewalls, proxies, EDR, cloud audit logs, VPN. Every missing source is a blind spot in detection.
Managed Detection and Response: outsourced detection and response including analyst work. Unlike plain monitoring, MDR does not stop at the alert but performs triage, assessment and agreed countermeasures.
A public framework cataloguing adversary tactics and techniques. It provides a shared language to measure detection coverage, expose gaps and classify alerts.
An EU directive making requirements for risk management, reporting and evidence binding for many organisations. In practice it demands demonstrable detection, response and governance.
A time-boxed, authorised attack on defined systems to evidence exploitable weaknesses. It tests technology at a point in time, not detection capability in operations.
Deception via e-mail, chat or phone to obtain credentials, MFA codes or payments. Technical filters alone are not enough — awareness and reporting paths belong to it.
An attack that encrypts data and often exfiltrates it as well for double extortion. Critical factors are detection before encryption, verified backups and a rehearsed escalation.
A realistic, objective-driven attack simulation over a longer period that tests technology, processes and detection together. Unlike a penetration test it evaluates whether an attack is noticed and stopped.
Security Information and Event Management: a platform that collects, normalises and correlates logs from IT and security systems centrally and raises alerts through detection rules. A SIEM only detects what is onboarded as a log source and described in a use case.
Security Orchestration, Automation and Response: automation of recurring analysis and response steps through playbooks. Automation handles enrichment and preparation; the decision on intrusive measures stays with the analyst.
Security Operations Center: the team, processes and technology that detect, assess and contain attacks around the clock. A SOC can be in-house, outsourced (managed SOC) or jointly operated (co-managed).
Structured information on adversaries, tooling and indicators. Threat intelligence becomes useful once it feeds detection rules, prioritisation and alert enrichment.
A documented detection scenario: risk, required log sources, rule logic, thresholds, false-positive handling and response instructions. Use cases are why a SIEM delivers insight instead of merely storing data.
The continuous process of discovering, rating, prioritising and evidencing remediation of vulnerabilities — using exploitability and business criticality as the yardstick, not the CVSS score alone.
Extended Detection and Response: extends the EDR approach to further telemetry such as identity, e-mail, network and cloud. What matters in practice is not the acronym but who actually analyses the signals.
A vulnerability with no patch available at the time of exploitation. What matters then is fast inventory, temporary mitigations and targeted detection of exploitation attempts.
Common questions about security operations terminology.
Your question is not listed? Ask us