Security Analytics terms

SIEM, detection, threat intelligence and behaviour analytics in the SOC.

Endpoint detection and response (EDR) Software that continuously records endpoint activity, applies detection logic, and lets responders investigate and contain threats. Extended detection and response (XDR) A platform that correlates telemetry across endpoints, network, identity, and cloud into a single detection and investigation view. Indicator of compromise (IOC) A piece of forensic evidence, such as a file hash or IP address, suggesting a system has been breached or contacted by an attacker. Mean time to detect (MTTD) The average time between when an incident begins and when a team becomes aware of it. MITRE ATT&CK framework A public knowledge base of adversary tactics and techniques used as a shared vocabulary for describing attacker behavior. Open-source intelligence (OSINT) Intelligence produced from publicly available information — social media, news, public records — rather than classified sources. Security operations center (SOC) The team responsible for continuously monitoring an organization's systems, triaging alerts, and coordinating incident response. SIEM (security information and event management) A platform that centralizes and correlates log and event data across an IT environment to detect and investigate security threats. SOAR (security orchestration, automation and response) A platform that automates and orchestrates the response steps a security team takes after an alert is raised. Threat intelligence Analyzed information about attacker groups, tools, and techniques used to anticipate and defend against threats, not just react to them. User and entity behavior analytics (UEBA) Analytics that baseline normal user and device behavior and flag deviations that could signal a compromise, even without a known IOC. Zero-day vulnerability A software flaw unknown to the vendor, or unpatched, at the time it is discovered or actively exploited.