Skip to main content

Cybersecurity Glossary

Master the Language of Security Operations

77+ essential definitions for SOC analysts and security professionals. Every term maps to real SOC training scenarios you can practice free.

77+Terms Defined
5Categories
3Tools Covered

What Is a Cybersecurity Glossary?

A cybersecurity glossary is a curated reference of terms, acronyms, and concepts used across Security Operations Centers (SOCs), incident response teams, and threat intelligence programs. For analysts starting their careers, mastering this vocabulary is the fastest way to decode alerts, communicate with senior staff, and navigate security tools with confidence.

This glossary focuses on operational terms: the tools you will use daily (SIEM, XDR, EDR), the threats you will triage (phishing, ransomware, lateral movement), and the frameworks that structure your work (MITRE ATT&CK®, NIST, defense in depth). Each definition includes real SOC context so you understand not just what a term means, but how it shapes your workflow.

SOC Glossary
A structured reference of cybersecurity terminology organized by category, with each term including a definition, extended explanation, SOC operational relevance, and links to related concepts. Designed for SOC analysts who need to understand the language of their tools, threats, and processes.

Browse by Category

Tools(15)

SIEMTools

Security Information and Event Management (SIEM) is a platform that aggregates, normalizes, and correlates log data from

XDRTools

Extended Detection and Response (XDR) is a security platform that unifies telemetry from endpoints, networks, cloud work

EDRTools

Endpoint Detection and Response (EDR) is a security technology that continuously monitors endpoint activity, recording p

SOARTools

Security Orchestration, Automation, and Response (SOAR) is a platform that integrates security tools, automates repetiti

IDSTools

An Intrusion Detection System (IDS) monitors network traffic or host activity for signs of malicious behavior, policy vi

IPSTools

An Intrusion Prevention System (IPS) is an active network security control deployed inline that inspects traffic in real

WAFTools

A Web Application Firewall (WAF) is a security control between clients and web applications that inspects HTTP/HTTPS tra

NGFWTools

A Next-Generation Firewall (NGFW) combines traditional stateful packet inspection with deep packet inspection, applicati

FirewallTools

A firewall is a network security control that inspects traffic crossing a boundary and permits or denies it against a co

DLPTools

Data Loss Prevention (DLP) is a set of technologies and policies that detect and prevent unauthorized transmission, stor

NDRTools

Network Detection and Response (NDR) is a security platform that passively monitors network traffic, using machine learn

MDRTools

Managed Detection and Response (MDR) is a service in which a third-party security provider delivers continuous threat mo

UEBATools

User and Entity Behavior Analytics (UEBA) applies machine learning and statistical modeling to establish behavioral base

HoneypotTools

A honeypot is a decoy system, service, or credential deliberately deployed to look like a legitimate target so that any

CASBTools

A Cloud Access Security Broker (CASB) is a security control point positioned between an organization's users and the clo

Concepts(20)

IOCConcepts

An Indicator of Compromise (IOC) is an observable artifact, such as a file hash, IP address, domain name, URL, registry

IOAConcepts

An Indicator of Attack (IOA) is a behavioral signal that identifies adversary intent and technique as it happens, such a

TTPsConcepts

Tactics, Techniques, and Procedures (TTPs) describe the behavioral patterns, methods, and operational processes threat a

False PositiveConcepts

A false positive is a security alert that fires on legitimate, benign activity, incorrectly classifying safe behavior as

True PositiveConcepts

A true positive is a security alert that correctly identifies genuine malicious activity or a real policy violation. It

Alert TriageConcepts

Alert triage is the structured process of reviewing, prioritizing, and investigating security alerts to determine their

Threat IntelligenceConcepts

Threat intelligence is analyzed, contextualized information about current and emerging cyber threats, including threat a

Kill ChainConcepts

The Cyber Kill Chain is a framework developed by Lockheed Martin, adapted from military targeting doctrine, that describ

Defense in DepthConcepts

Defense in depth layers multiple independent defensive controls across the network, endpoint, application, and identity

Zero TrustConcepts

Zero Trust is a security architecture philosophy based on "never trust, always verify," requiring continuous authenticat

Least PrivilegeConcepts

The principle of least privilege states that users, processes, and systems should hold only the minimum access rights re

Attack SurfaceConcepts

An organization's attack surface is the total set of points where an adversary could attempt unauthorized access: networ

MFAConcepts

Multi-Factor Authentication (MFA) requires a user to prove their identity with two or more independent factors, somethin

MTTD (Mean Time to Detect)Concepts

Mean Time to Detect is the average elapsed time between when a security incident begins and when the SOC first identifie

MTTR (Mean Time to Respond)Concepts

Mean Time to Respond (MTTR) is the average elapsed time between when a security incident is detected and when the analys

Blue TeamConcepts

The blue team is the defensive side of an organization's security function: the analysts, engineers, and responders who

SandboxingConcepts

Sandboxing is the practice of executing an untrusted file, URL, or piece of code inside an isolated environment, separat

Zero-DayConcepts

A zero-day is a software vulnerability that is unknown to the vendor at the time attackers begin exploiting it, meaning

ZTNAConcepts

Zero Trust Network Access (ZTNA) is an access model that grants users connectivity to specific applications only after v

SASEConcepts

Secure Access Service Edge (SASE) is a cloud-delivered architecture that converges networking and security functions, SD

Threats(19)

PhishingThreats

Phishing is a social engineering attack delivered via email, SMS, voice calls, or other channels that deceives recipient

Brute Force AttackThreats

A brute force attack systematically tries large numbers of username and password combinations, or decryption keys, until

Lateral MovementThreats

Lateral movement is the attack phase where adversaries expand access from an initial foothold to additional systems, usi

Privilege EscalationThreats

Privilege escalation is the set of techniques an attacker uses to gain higher access rights than they initially obtained

PersistenceThreats

Persistence is the set of techniques an adversary uses to keep access to a compromised system after whatever gave them t

Command and ControlThreats

Command and Control (C2) refers to the infrastructure and communication channels adversaries use to remotely direct malw

ExfiltrationThreats

Data exfiltration is the unauthorized transfer of sensitive data out of a victim environment to attacker-controlled infr

RansomwareThreats

Ransomware is malware that encrypts victim data or systems and demands payment, typically cryptocurrency, for the decryp

APTThreats

An Advanced Persistent Threat (APT) is a sophisticated, often nation-state-sponsored threat actor conducting long-durati

Insider ThreatThreats

An insider threat is a security risk originating from current or former employees, contractors, or business partners who

Supply Chain AttackThreats

A supply chain attack compromises a trusted third-party vendor, software build process, open-source component, or hardwa

Social EngineeringThreats

Social engineering is the psychological manipulation of individuals into performing actions or revealing information tha

Threat ActorThreats

A threat actor is any individual, group, or organization that conducts or sponsors malicious cyber activity, spanning na

Fileless MalwareThreats

Fileless malware is malicious activity that executes entirely in memory or through legitimate, pre-installed system tool

Living-off-the-Land (LOTL)Threats

Living-off-the-land (LOTL) is an attack technique where an adversary carries out reconnaissance, lateral movement, or ex

Credential StuffingThreats

Credential stuffing is an automated attack in which an adversary takes large lists of username-and-password pairs leaked

Password SprayingThreats

Password spraying is an attack technique in which an adversary tries one, or a small handful, of commonly used passwords

DDoS (Distributed Denial of Service)Threats

A Distributed Denial of Service (DDoS) attack floods a target network, service, or application with traffic or requests

BotnetThreats

A botnet is a network of internet-connected devices, PCs, servers, routers, IoT cameras, that have been compromised with

Frameworks(7)

Processes(16)

Incident ResponseProcesses

Incident response (IR) is the structured, repeatable process an organization follows before, during, and after a securit

Threat HuntingProcesses

Threat hunting is the proactive, human-led process of searching through security telemetry to find hidden threats that e

Digital ForensicsProcesses

Digital forensics is the scientific process of collecting, preserving, analyzing, and presenting digital evidence from c

Vulnerability ManagementProcesses

Vulnerability management is the continuous process of discovering, assessing, prioritizing, remediating, and verifying s

Patch ManagementProcesses

Patch management is the systematic process of acquiring, testing, approving, and deploying software updates and security

Log ManagementProcesses

Log management is the process of collecting, normalizing, storing, retaining, and analyzing log data from across the IT

Alert CorrelationProcesses

Alert correlation combines multiple related security events from different sources into a unified, higher-fidelity alert

EscalationProcesses

Escalation is the formal process of transferring an alert or incident to a higher-tier analyst, a specialized team, or m

ContainmentProcesses

Containment is the incident response phase focused on limiting the spread and impact of a confirmed security incident: i

EradicationProcesses

Eradication is the incident response phase where all threat components are permanently removed: malware, backdoors, pers

RecoveryProcesses

Recovery is the final phase of the incident response lifecycle, where affected systems are restored to normal, validated

Penetration TestingProcesses

Penetration testing is an authorized, scoped simulated attack against an organization's systems, networks, or applicatio

SOC AnalystProcesses

A SOC analyst is a cybersecurity professional who monitors, triages, investigates, and responds to security alerts and i

Red TeamProcesses

A red team is a group of security professionals who simulate a determined, sustained adversary against an organization's

SLAProcesses

A Service Level Agreement (SLA) in SOC contexts defines contractual or operational targets for alert handling: maximum t

Purple TeamProcesses

Purple teaming is a collaborative security exercise model in which offensive (red team) and defensive (blue team) practi

Frequently Asked Questions

What terms should SOC analysts know first?
Start with the core tools: SIEM, XDR, EDR, and Firewall. Then learn the processes: alert triage, incident response, escalation, and threat hunting. These terms map directly to daily SOC workflows and appear in every analyst job description.
How is this glossary organized?
Terms are grouped into five categories: Tools (SIEM, XDR, EDR, etc.), Concepts (defense in depth, zero trust, etc.), Threats (phishing, ransomware, APT, etc.), Frameworks (MITRE ATT&CK®, NIST, etc.), and Processes (incident response, alert triage, etc.). Each term includes a definition, extended explanation, SOC relevance context, and links to related terms.
How often is the glossary updated?
We review and update the glossary monthly to reflect new threats, evolving tools, and changes in industry frameworks. New terms are added as the cybersecurity landscape evolves.
Can I practice these concepts hands-on?
Yes. SOCSimulator provides free SOC analyst training with realistic SIEM, XDR, and Firewall interfaces. Every glossary term maps to a concept you will encounter during hands-on training scenarios. Start free.
What is the difference between SIEM, XDR, and EDR?
SIEM aggregates and correlates logs from across your environment for threat detection and compliance. EDR monitors individual endpoints (process execution, file changes, network connections). XDR extends EDR by unifying endpoint, network, cloud, and identity telemetry into a single detection and response platform. Most mature SOCs use all three together.
Free

Put These Concepts Into Practice

SOCSimulator puts you in the analyst seat with real alerts, real tools, and real pressure. Investigate MITRE ATT&CK®-mapped scenarios across SIEM, XDR, and Firewall consoles. Start free.