Blue Team Reference

The SOC Analyst
Glossary

500+ cybersecurity terms explained for practitioners — DFIR, SOC, Threat Hunting, Malware Analysis, and beyond.

A–Z
51-100 of 466 terms
B
10 terms
Backdoor Attacks
Malware AnalysisDetection Engineering
A backdoor attack is the installation and use of a hidden access method that bypasses a system's normal authentication so an attacker can return undetected.
Backporting
Detection Engineering
Backporting is taking a security fix from a newer version of a software package and applying it to an older version without upgrading the package or changing its version number.
Behavioral Analytics
Detection EngineeringThreat Hunting
Behavioral analytics models normal activity for each user and entity, then scores deviations from that baseline as potential security risk.
Blue Team
Detection EngineeringThreat Hunting
A blue team is the group responsible for an organization's defensive security: monitoring systems for threats, detecting and investigating attacks, responding to incidents, and continuously hardening defenses.
Bootkits
Malware AnalysisEndpoint Forensics
A bootkit is malware that infects the early boot process so it loads before the operating system and the security tools running on top of it.
Botnet
Malware AnalysisNetwork Forensics
A botnet is a network of compromised hosts, each running the same malware, that a single operator controls remotely through a command-and-control channel as one coordinated unit.
Bring-Your-Own-Device (BYOD)
Endpoint Forensics
BYOD is the practice of letting employees use personally owned phones, tablets, and laptops to access corporate resources, so the organization must secure its data on a device it does not own.
Browser Extensions
Detection EngineeringEndpoint Forensics
Browser extensions are programs that run inside the browser with broadly scoped, user-granted permissions, which makes legitimate, useful extensions an attack surface when their code is sold, compromised, or auto-updated into something malicious.
Brute Force Attack
Threat IntelligenceDetection EngineeringThreat Hunting
A brute force attack is a method of gaining unauthorized access to an account, system, or encrypted file by systematically trying every possible password or credential combination until the correct one is found.
Business Email Compromise (BEC)
Threat Intelligence
Business email compromise is a fraud technique in which an attacker poses as a trusted party and uses email to trick an employee into sending money or sensitive data.
C
38 terms
CDR Use Cases
Detection EngineeringCloud Forensics
CDR use cases are the concrete cloud attacks that Cloud Detection and Response detects at runtime, from credential abuse to data exfiltration, each mapped to its telemetry, detection signal, and response.
CDR vs ADR
Detection EngineeringCloud Forensics
CDR detects threats against the cloud environment (control plane, workloads, identities), while ADR detects threats inside the running application at runtime.
CDR vs Cloud Security Monitoring
Detection EngineeringCloud Forensics
Cloud security monitoring is the continuous observation of a cloud environment for configuration, compliance, and state, while CDR actively detects and responds to threats across cloud runtime, identity, and the control plane.
CDR vs CNAPP
Detection EngineeringCloud Forensics
CNAPP is the broad posture and prevention platform that shrinks cloud attack surface across the lifecycle, while CDR is the runtime discipline that detects and responds to active threats.
CDR vs XDR
Detection EngineeringCloud Forensics
CDR is deep cloud-runtime detection and response in one domain, while XDR is broad detection and response correlated across endpoint, network, identity, email, and cloud.
Centralized Logging
Network ForensicsDetection Engineering
Centralized logging is the practice of collecting log data from across an environment into a single system where it is stored, normalized, and made searchable.
CI/CD Pipeline
Detection EngineeringCloud Forensics
A CI/CD pipeline is the automated path that takes a code change from a developer's commit through build, test, and release to running in production.
CIS Benchmarks
Detection EngineeringCloud Forensics
A CIS Benchmark is a consensus-built set of secure configuration recommendations for a specific technology, published free by the Center for Internet Security (CIS).
Cloud Access Security Broker (CASB)
Detection EngineeringCloud Forensics
A Cloud Access Security Broker (CASB) is a security policy enforcement point placed between users and cloud services that applies enterprise security policy as those cloud apps are accessed.
Cloud Analytics
Detection EngineeringCloud Forensics
Cloud analytics is the set of data analytics operations (ingestion, storage, querying, analysis, visualization, and modeling) executed on cloud infrastructure instead of local hardware so compute scales to the question.
Cloud Application Detection and Response (CADR)
Detection EngineeringCloud Forensics
Cloud Application Detection and Response (CADR) correlates application runtime signals with cloud context to detect and respond to threats across the code-to-cloud path.
Cloud Application Security
Detection EngineeringCloud Forensics
Cloud application security is the practice of protecting cloud-hosted applications across their whole lifecycle, covering the code, the cloud configuration, the running workloads, and the identities that reach them.
Cloud Automation
Detection EngineeringCloud Forensics
Cloud automation is the practice of provisioning, configuring, and managing cloud resources programmatically through infrastructure as code, CI/CD pipelines, auto-scaling, and scheduled tasks.
Cloud Compliance
Detection EngineeringCloud Forensics
Cloud compliance is meeting the regulatory, standards, and contractual requirements for the data and systems you run in the cloud, and proving it continuously.
Cloud Compromise Assessment
Threat HuntingCloud Forensics
A cloud compromise assessment is a point-in-time, evidence-driven investigation of a cloud environment for signs that an unauthorized actor has accessed, persisted in, or moved through it.
Cloud Computing
Detection EngineeringCloud Forensics
Cloud computing is the on-demand delivery of computing resources (servers, storage, databases, and software) over the internet, billed by use instead of owned outright.
Cloud Data Loss Prevention (DLP)
Detection EngineeringCloud Forensics
Cloud DLP is the set of capabilities that discovers, classifies, monitors, and protects sensitive data inside cloud apps, storage, and email so it does not leak or get exfiltrated.
Cloud Data Security
Detection EngineeringCloud Forensics
Cloud data security is the set of technologies, policies, and controls that protect data in a cloud environment from loss, leakage, and unauthorized access across data at rest, in transit, and in use.
Cloud Detection
Detection EngineeringCloud Forensics
Cloud detection is the practice of finding malicious or anomalous activity in cloud environments by collecting and analyzing control-plane, identity, network, and runtime telemetry.
Cloud Detection and Response (CDR)
Detection EngineeringCloud Forensics
Cloud Detection and Response (CDR) is runtime threat detection and response across cloud workloads, identities, and the control plane.
Cloud Encryption
Detection EngineeringCloud Forensics
Cloud encryption is the use of cryptography to render data in a cloud environment unreadable without the right key, applied across data at rest, in transit, and in use.
Cloud Firewall
Detection EngineeringCloud Forensics
A cloud firewall is firewall capability delivered as a cloud service, filtering traffic to and from cloud workloads and distributed users without a physical appliance.
Cloud Forensics
Cloud Forensics
Cloud forensics is the application of forensic investigation to cloud computing environments: identifying, preserving, analyzing, and reporting on digital evidence from cloud services during or after a security incident.
Cloud Governance
Detection EngineeringCloud Forensics
Cloud governance is the set of policies, rules, and processes an organization uses to control how it provisions, secures, funds, and operates its cloud resources.
Cloud Incident Response
Detection EngineeringCloud Forensics
Cloud incident response is the structured process for detecting, investigating, containing, and recovering from a security incident in a public cloud environment such as AWS, Azure, or Google Cloud.
Cloud Infrastructure
Detection EngineeringCloud Forensics
Cloud infrastructure is the pool of compute, storage, networking, and virtualization a provider runs and rents on demand, plus the control plane used to manage it.
Cloud Infrastructure Entitlement Management (CIEM)
Detection EngineeringCloud Forensics
Cloud infrastructure entitlement management (CIEM) is a security process that analyzes and right-sizes the identities, permissions, and entitlements across cloud environments toward least privilege.
Cloud Investigation and Response Automation (CIRA)
Detection EngineeringCloud Forensics
Cloud Investigation and Response Automation (CIRA) is an emerging Gartner category that automates the forensic collection, correlation, and response for confirmed cloud security incidents.
Cloud Jacking
Detection EngineeringCloud Forensics
Cloud jacking is the hijacking of a cloud account, resource, or service by someone who is not supposed to control it, typically through stolen or leaked credentials rather than a software exploit.
Cloud Migration
Detection EngineeringCloud Forensics
Cloud migration is the process of moving applications, data, and workloads from on-premises infrastructure (or one cloud) into a cloud provider's environment.
Cloud Monitoring
Detection EngineeringCloud Forensics
Cloud monitoring is the practice of continuously measuring and evaluating cloud workloads, services, and infrastructure against defined metrics and thresholds for performance, availability, cost, and security.
Cloud-Native Application Protection Platform (CNAPP)
Detection EngineeringCloud Forensics
A cloud-native application protection platform (CNAPP) is one platform that consolidates CSPM, CWPP, and CIEM across the full cloud application lifecycle.
Cloud Native Security
Detection EngineeringCloud Forensics
Cloud native security is the practice of protecting applications built for the cloud (containers, Kubernetes, microservices, serverless, and infrastructure-as-code) across their full lifecycle from code to runtime.
Cloud Response
Detection EngineeringCloud Forensics
Cloud response is the part of incident response that contains, investigates, eradicates, and recovers from a confirmed threat in a cloud environment.
Cloud Security
Detection EngineeringCloud Forensics
Cloud security is the set of policies, technologies, controls, and practices designed to protect cloud-based systems, data, and infrastructure from cyber threats. It covers everything stored, processed, or transmitted through cloud environments, including applications, virtual machines, containers, databases, and the networks that connect them.
Cloud Security Architecture
Detection EngineeringCloud Forensics
Cloud security architecture is the deliberate arrangement of controls, components, and responsibilities that secures a cloud environment end to end, covering identity, workload protection, network controls, encryption, and logging.
Cloud Security Assessment
Detection EngineeringCloud Forensics
A cloud security assessment is a point-in-time evaluation of a cloud environment's security posture, measured against published best practices and benchmarks.
Cloud Security Best Practices
Detection Engineering
Cloud security best practices are the durable, provider-neutral controls a customer configures to protect the workloads, data, and identities they run in the cloud.