Blue Team Reference
The SOC Analyst
Glossary
500+ cybersecurity terms explained for practitioners — DFIR, SOC, Threat Hunting, Malware Analysis, and beyond.
A–Z
151-200 of 466 terms
C15 terms
Cyber Hygiene
Detection Engineering
Cyber hygiene is the routine, continuous maintenance of basic security controls, including patching, identity discipline, least-privilege access, tested backups, and monitoring.
Cyber Insurance
Detection Engineering
Cyber insurance is a policy that transfers an organization's financial liability for cyber events such as data breaches and ransomware to an insurer in exchange for a premium.
Cyber kill chain
Threat IntelligenceDetection EngineeringThreat Hunting
What Is the Cyber Kill Chain? 7 Stages Explained An attacker has to get every step right. You only have to catch one. That asymmetry, normally working against the defender, runs the other way once an intrusion is broken into stages.
Cyber Resilience
Threat Intelligence
Cyber resilience is an organization's ability to keep critical operations running through a cyberattack and recover quickly, assuming a serious breach will eventually get through.
Cyber Risk
Threat Intelligence
Cyber risk is the probable loss an organization faces from a cyber event, defined as the likelihood that a threat exploits a vulnerability multiplied by the impact if it does.
Cybersecurity
Malware AnalysisNetwork ForensicsDetection EngineeringThreat HuntingCloud ForensicsEndpoint Forensics
A SOC analyst opens her queue on a Monday. An endpoint agent flagged powershell.exe spawning from a Word document, then reaching out to an IP in a country the company does no business with. Within twenty minutes she has pulled the process tree, confirmed the macro, isolated the host, and pushed a detection rule so the next attempt fires an alert before anyone clicks.
Cybersecurity Advisory Services
Detection EngineeringThreat Hunting
Cybersecurity advisory services are high-level guidance and strategic planning engagements that evaluate whether a security program is comprehensive, current, and effective, then recommend how to improve it.
Cybersecurity Platform Consolidation
Detection Engineering
Cybersecurity platform consolidation is the strategic process of unifying disparate security tools onto a single platform with shared data, shared management, and one operational view.
Cybersecurity Platform Consolidation Best Practices
Detection Engineering
Cybersecurity platform consolidation best practices are the operating discipline that makes consolidation reduce risk: inventory and map tool coverage, trace redundancy and dependency, prioritize by risk, migrate detections to parity, phase the cutover, and measure coverage instead of tool count.
Cybersecurity Risk Assessment
Detection Engineering
A cybersecurity risk assessment identifies threats to an organization's assets, estimates how likely each is and how much damage it would cause, and ranks the results so the most serious risks are addressed first.
Cybersecurity Sandboxing
Malware AnalysisThreat Intelligence
Cybersecurity sandboxing is the use of an isolated, controlled environment to run or open potentially malicious code and study its behavior safely, without risking production systems.
Cybersecurity Transformation
Detection EngineeringThreat Hunting
Cybersecurity transformation is the implementation of a comprehensive security strategy across the whole program (risk management, threat intelligence, governance, incident response, and compliance), rebuilt to fit how an organization operates today.
Cybersquatting
Threat Intelligence
Cybersquatting, also called domain squatting, is the bad-faith registration and use of an internet domain that is identical or confusingly similar to a trademark, brand, or name someone else owns.
Cyber threat intelligence (CTI)
Threat IntelligenceThreat Hunting
Two reports land on a SOC analyst's desk, both about the same IP address. The first says: 198.51.100.23: malicious, block it. That is the whole report.
Cyber Vulnerabilities
Detection EngineeringThreat Hunting
A cyber vulnerability is a weakness in a system, its configuration, or its processes that an attacker can exploit to do something they should not be able to do.
D35 terms
Dark AI
Threat Intelligence
Dark AI is the use of artificial intelligence, especially generative AI, to enable, accelerate, or scale cyberattacks, defined by the absence of the safety guardrails legitimate models ship with.
Dark Web Monitoring
Threat Intelligence
Dark web monitoring is the continuous process of searching criminal forums, marketplaces, paste sites, and leak channels for an organization's exposed data such as leaked credentials, stolen records, and brand impersonation.
Database Monitoring
Detection Engineering
Database monitoring is the continuous collection and analysis of a database's activity, health, and security: who connected, what queries ran, what data was touched, what changed, and how the system performed.
Data Breach
Detection Engineering
A data breach is the unauthorized access to or acquisition of sensitive data, exposing protected information to someone without authorization.
Data Classification
Detection EngineeringCloud Forensics
Data classification is the practice of categorizing data according to predefined criteria such as its sensitivity, type, or business value, so each category can be protected according to what it is.
Data Compliance
Detection EngineeringThreat Hunting
Data compliance is the practice of organizing and managing sensitive data so it meets the legal, regulatory, and contractual rules that apply to it, and being able to prove it.
Data Encryption
Detection Engineering
Data encryption is the process of converting readable plaintext into encoded ciphertext that only a holder of the correct cryptographic key can reverse, protecting the confidentiality of data even if it is accessed.
Data Exfiltration
Detection Engineering
Data exfiltration is the unauthorized transfer of data from a device or network to a location the owner does not control, the theft stage of an attack where access to data becomes loss of data.
Data Flow Mapping
Detection EngineeringCloud Forensics
Data flow mapping is the process of visualizing and tracking the flow of data across an environment from acquisition to disposal, following data through its full lifecycle to show where sensitive data actually goes.
Data Gravity
Detection EngineeringThreat Hunting
Data gravity is the tendency of a large dataset to attract applications, services, and more data toward it, because moving the analysis to the data is cheaper than moving the data to the analysis.
Data Leakage
Detection Engineering
Data leakage is the unauthorized transmission of sensitive, confidential, or protected data from within an organization to an external destination or party.
Data Leaks vs Data Breaches
Detection Engineering
A data leak is the unintentional exposure of sensitive data through error or misconfiguration, while a data breach is the unauthorized access to or acquisition of that data, usually through a deliberate attack.
Data Logging
Detection EngineeringThreat Hunting
Data logging is the process of recording events and state changes as discrete, timestamped entries so they can be stored, searched, and analyzed after the fact.
Data Loss Prevention (DLP)
Detection EngineeringEndpoint Forensics
Data Loss Prevention (DLP) is a set of security tools, policies, and processes designed to detect, monitor, and block the unauthorized transfer, sharing, or exposure of sensitive data. DLP solutions inspect data in motion (network traffic), data at rest (stored files), and data in use (endpoint activity) to prevent accidental leaks and deliberate exfiltration before damage occurs.
Data Obfuscation
Detection EngineeringCloud Forensics
Data obfuscation is the process of disguising confidential or sensitive data to protect it from unauthorized access while keeping it usable for the systems and people that legitimately need it.
Data Onboarding
Detection EngineeringThreat Hunting
Data onboarding is the process of bringing a log source into a SIEM and making its events usable: collected, parsed into fields, normalized to a common schema, enriched, and routed to the right storage.
Data Poisoning
Threat IntelligenceDetection Engineering
Data poisoning is a cyberattack in which an adversary deliberately corrupts the data a machine-learning model trains on, so the model behaves as the attacker intends instead of as designed.
Data Portability
Detection EngineeringThreat Hunting
Data portability is the ability of users to easily transfer their personal data from one service provider to another in a structured, commonly used, machine-readable format.
Data Privacy
Detection EngineeringCloud Forensics
Data privacy is the branch of data protection that governs how personal data is collected, used, shared, retained, and disposed of, with the rights of the individual at the center.
Data Protection vs Data Security
Detection Engineering
Data security is the technical defense of data against unauthorized access, while data protection is the broader program that contains data security and adds privacy, lawful handling, and regulatory compliance across the data lifecycle.
Data Security
Detection Engineering
Data security is the practice of protecting digital data from unauthorized access, change, or destruction across its lifecycle, built on the CIA triad of confidentiality, integrity, and availability.
Data Security Posture Management (DSPM)
Detection EngineeringCloud Forensics
Data security posture management (DSPM) is the continuous process and tooling that discovers sensitive data across cloud environments, classifies it, and assesses and reduces the risk around it.
Data Theft Prevention
Detection Engineering
Data theft prevention is the combination of controls, policies, and monitoring that keeps sensitive data from being acquired by anyone not authorized to have it.
Debug Logging
Detection Engineering
Debug logging is a software development technique that records detailed diagnostic information about an application's internal runtime state (variable values, code paths, timestamps, and external data) to help identify and resolve bugs.
Decentralized Identity
Detection Engineering
Decentralized identity is a model where users hold their own identifiers and cryptographically signed credentials in a wallet and prove claims directly, with no central database storing everyone's identity.
Deepfake Attack
Threat IntelligenceDetection Engineering
A deepfake attack is the use of AI-generated synthetic media, fake voice, video, or images, to convincingly impersonate a real person and deceive a target into paying, sharing data, or granting access.
Deep Web vs Dark Web
Threat Intelligence
The deep web is any part of the internet that search engines do not index, while the dark web is a small, intentionally hidden slice of it reachable only through anonymizing software like Tor.
Defense in Depth
Network ForensicsDetection Engineering
Defense in depth is a security strategy that layers multiple, independent controls across an environment so the failure or bypass of any one control does not result in a successful breach.
Denial-of-Service (DoS) Attacks
Network ForensicsDetection Engineering
A denial-of-service attack is a cyberattack that makes a machine, service, or network unavailable to its users by overwhelming it with traffic or by sending input that causes it to crash or hang.
Detection engineering
Detection EngineeringThreat Hunting
A detection rule that alerts on powershell.exe -enc catches the lazy attacker and misses everyone else. Rename the binary, split the flag, encode it differently, and the rule goes silent while the attack runs. A rule that instead models the behavior, an encoded PowerShell command spawned by a Microsoft Office process, catches the technique no matter what the attacker renames.
DevOps
Cloud Forensics
DevOps is a set of practices, cultural philosophies, and tools that combines software development and IT operations to shorten the development lifecycle and deliver software continuously and reliably.
DevOps Monitoring
Detection EngineeringThreat Hunting
DevOps monitoring is the practice of continuously tracking the health, performance, and integrity of every stage of the software delivery lifecycle, from a developer's commit through the build pipeline to running infrastructure.
DevOps vs. DevSecOps
Detection Engineering
DevOps merges development and operations into one automated delivery pipeline, while DevSecOps takes that same pipeline and integrates security into every stage as an automated, shared responsibility rather than a late gate.
DevSecOps
Detection EngineeringThreat Hunting
DevSecOps is the practice of integrating security into every stage of the software development lifecycle, from design and coding through build, test, and deployment, so security is a continuous, shared responsibility built into the pipeline rather than a separate review at the end.
Digital forensics
Network ForensicsEndpoint Forensics
Delete a file, empty the recycle bin, and most people assume it is gone. It is not. On an NTFS volume the operating system removes the file's entry from the master file table and marks its clusters as free, but the bytes sit untouched in unallocated space until something else overwrites them, which may be minutes or months later.