Blue Team Reference

The SOC Analyst
Glossary

500+ cybersecurity terms explained for practitioners — DFIR, SOC, Threat Hunting, Malware Analysis, and beyond.

A–Z
401-450 of 466 terms
S
34 terms
SaaS Security
Cloud Forensics
SaaS security is the set of policies, controls, and monitoring that protect the data, identities, and configurations inside software-as-a-service applications your organization uses but does not host or operate.
SaaS Security Posture Management (SSPM)
Detection EngineeringCloud Forensics
SaaS security posture management (SSPM) is the continuous process and tooling that finds and fixes misconfigurations, excessive permissions, and compliance gaps across SaaS applications.
Security Architecture
Detection Engineering
Security architecture is the structured design of the security controls, policies, and technologies that protect an organization's systems, data, and operations.
Security Automation
Detection Engineering
Security automation is the practice of having technology carry out security tasks such as identifying threats, triaging and enriching alerts, and responding to incidents automatically, without a human performing each step.
Security Awareness Training
Detection Engineering
Security awareness training is a structured, ongoing program that teaches everyone in an organization to recognize, resist, and report the attacks aimed at them, mainly phishing, social engineering, and the everyday mistakes that give attackers a way in.
Security Fabric
Detection Engineering
A security fabric is an integrated cybersecurity architecture in which separate security tools share a common data and control plane so they operate as one coordinated system.
Security Information and Event Management (SIEM)
Threat IntelligenceNetwork ForensicsDetection EngineeringThreat HuntingCloud ForensicsEndpoint Forensics
SIEM (Security Information and Event Management) is a security platform that collects log and event data from across an organization's infrastructure, normalizes it into a common format, and correlates it against detection rules to detect threats and support investigation and compliance.
Security Mesh
Detection Engineering
A security mesh, or cybersecurity mesh architecture (CSMA), is a security model that gives each asset its own identity-anchored perimeter and coordinates them through shared layers for analytics, identity, and policy.
Security Operation Center (SOC)
Malware AnalysisThreat IntelligenceNetwork ForensicsDetection EngineeringThreat HuntingCloud ForensicsEndpoint Forensics
A Security Operations Center (SOC) is the centralized team, process, and technology function that monitors an organization's systems around the clock, triages security alerts, and detects, investigates, and responds to cyber threats.
Security Operations (SecOps)
Detection EngineeringThreat Hunting
A vulnerability scanner flags a critical CVE on a production database server Monday morning. The security team files a ticket and moves on. The IT operations team, measured on uptime and bonused on it, sees that patching means downtime and a maintenance window they have to fight for.
Security Orchestration, Automation, and Response (SOAR)
Detection Engineering
A user reports a phishing email. An analyst opens it, copies the sender, pastes it into a reputation tool, extracts the URL, checks it against a sandbox, pulls the attachment hash, searches the mail logs for everyone else who got the same message, deletes the copies, blocks the domain, and opens a ticket. Twelve steps, eight minutes, zero judgment required.
Security Posture Management
Detection EngineeringCloud Forensics
Security posture management is the continuous practice of measuring an organization's current exposure to attack and reducing it: inventory the assets, measure each against a secure baseline, prioritize the gaps by risk, and remediate them on a loop.
Security Service Edge (SSE)
Cloud Forensics
Security Service Edge (SSE) is a cloud-delivered set of security services (SWG, CASB, and ZTNA) that secures access to the web, cloud services, and private applications from one platform, regardless of where the user or the resource sits.
Security Token Service (STS)
Cloud Forensics
A security token service (STS) is a component that issues, validates, and exchanges signed, time-bound security tokens so one system can trust an identity authenticated by another without handling the original password.
Sensitive Data Discovery
Detection EngineeringCloud Forensics
Sensitive data discovery is the practice of scanning an environment to find and identify where sensitive data lives, what type it is, and how it is exposed.
Service Account Security
Detection Engineering
Service account security is the practice of identifying, securing, and governing the non-human accounts that run applications, services, and automated tasks across their full lifecycle.
Service Provider Access Risk
Detection Engineering
Service provider access risk is the security exposure created when external organizations such as MSPs, SaaS vendors, and contractors hold access to systems you own.
Shadow IT
Detection EngineeringCloud Forensics
Shadow IT is any hardware, software, device, or cloud and SaaS service used inside an organization without the knowledge or approval of the IT and security department.
Shift-Left Security
Detection EngineeringThreat Hunting
Shift-left security is the practice of moving security testing and review earlier in the software development lifecycle, toward design and coding, instead of running them as a late gate before or after release, so a flaw is found and fixed close to where it is introduced.
Smishing
Threat IntelligenceDetection Engineering
Smishing is a form of social engineering in which an attacker sends a fraudulent text message designed to trick a person into revealing sensitive information, handing over credentials, installing a malicious app, or sending money.
SOC analyst
Detection EngineeringThreat Hunting
A SOC analyst is a security professional who monitors an organization's systems for signs of compromise, investigates the alerts that detection tools raise, and responds to or escalates confirmed threats.
Social Engineering
Threat IntelligenceDetection Engineering
Social engineering is the use of psychological manipulation to trick people into taking actions or revealing information that compromises security.
Software as a Service (SaaS)
Cloud Forensics
Software as a service (SaaS) is a cloud-based software delivery model where users access a complete application over the internet on a subscription, while the vendor runs the code, hosting, updates, and platform security.
Software Bill of Materials (SBOM)
Detection EngineeringThreat Hunting
A Software Bill of Materials (SBOM) is a structured, machine-readable inventory of the components and dependencies that make up a software product, recording each component's name, version, supplier, and relationship to the others.
Software Composition Analysis (SCA)
Detection EngineeringCloud Forensics
Software composition analysis is an automated method that identifies the open-source and third-party components inside an application and assesses the risk each one carries, matching every dependency version against known vulnerabilities, license terms, and end-of-life status.
Spam
Threat IntelligenceDetection Engineering
Spam is unsolicited, bulk-sent electronic messaging that the recipient did not ask for and that was sent indiscriminately to a large number of people at once, ranging from junk advertising to malicious scams and malware delivery.
Spear Phishing
Threat Intelligence
Spear phishing is a targeted phishing attack aimed at a specific individual or organization, using researched, personalized content to trick the target into giving up credentials, approving a payment, or running malware.
SQL Injection
Detection Engineering
SQL injection is a web vulnerability in which an attacker supplies input that an application splices into a database query as code, letting the attacker read, change, or delete data and sometimes run commands on the database host.
Sqlmap
Detection Engineering
Sqlmap is an open-source penetration testing tool that automates detecting and exploiting SQL injection flaws and taking over database servers.
Static Application Security Testing (SAST)
Detection Engineering
Static application security testing (SAST) is a white-box method that analyzes an application's source code, bytecode, or binaries for security vulnerabilities without executing the program.
Supply Chain Attack
Threat IntelligenceDetection Engineering
A software supply chain attack compromises software by targeting a weaker link upstream of the victim (a vendor, a build pipeline, an open-source dependency, or an update mechanism) and lets the normal distribution process carry the payload downstream.
Supply Chain Security
Detection EngineeringThreat Hunting
Supply chain security is the practice of identifying, assessing, and reducing the risk an organization inherits from the third parties, software, hardware, and services it depends on.
Supply Chain Visibility
Threat Intelligence
Supply chain visibility is the ability to see and track every external component, vendor, and dependency your software and infrastructure rely on, along with the access each one holds in your environment.
Suspicious Process Name
Detection EngineeringThreat Hunting
A suspicious process name is a running process whose name, file path, parent process, or digital signature does not line up with what the legitimate binary of that name should look like.
T
13 terms
Threat Actors
Threat Intelligence
A threat actor is any person, group, or organization that intentionally causes harm in the digital sphere, defined by intent rather than the tools they use.
Threat Hunting
Threat Hunting
Threat hunting is the proactive search for attackers already inside an environment, in which a human analyst forms a hypothesis about intruder behavior and searches the data for evidence of it rather than waiting for an alert.
Threat Intelligence Platform (TIP)
Threat Intelligence
A threat intelligence platform (TIP) is a system that aggregates threat data from many sources, normalizes and deduplicates it, enriches and scores it, and distributes the resulting intelligence to security controls and analysts.
Threat Landscape
Threat Intelligence
The threat landscape is the total set of cyber threats facing an organization, sector, or region at a point in time: the active threat actors, the tactics they use, the vulnerabilities they exploit, and the assets they target.
Threat Modeling
Detection EngineeringThreat Hunting
Threat modeling is a structured analysis of a system's design to identify what could go wrong and decide what to do about each threat, before the system ships.
Threat Monitoring
Detection Engineering
Threat monitoring is the ongoing process of collecting and analyzing security telemetry to identify potential threats and suspicious activity across an environment in as close to real time as possible.
Threat Prioritization
Threat IntelligenceDetection Engineering
Threat prioritization is the process of ranking threats, vulnerabilities, and alerts by the actual risk they pose, so finite remediation and response effort goes to what is most likely to cause real harm.
Tokenization
Detection Engineering
Tokenization is the process of substituting a sensitive data value with a non-sensitive token that has no exploitable value on its own, while the original is held in a separate, protected system and retrieved only through an authorized lookup.
Tokens in Cybersecurity
Detection EngineeringThreat Hunting
A token in cybersecurity is data a trusted system issues after verifying an identity, which the holder presents on later requests to prove it instead of authenticating again.
Trojans
Malware Analysis
A Trojan is malware disguised as legitimate software that a user is tricked into running; unlike a virus or worm it does not self-replicate, and its hidden payload can do anything the logged-in user can do once executed.
Trusted Partner Network (TPN) Audit
Threat Intelligence
A Trusted Partner Network (TPN) audit is a content security assessment of a media and entertainment vendor, measured against the Motion Picture Association Content Security Best Practices.
Two-Factor Authentication (2FA)
Detection Engineering
Two-factor authentication is an access control method that requires two distinct proofs of identity, drawn from two different categories (something you know, something you have, something you are), before granting access.
Typosquatting
Threat Intelligence
Typosquatting is the practice of registering names that closely resemble a legitimate, well-known name, exploiting common typing errors and visual confusion to redirect traffic, harvest credentials, or deliver malware.