Cybersecurity glossary: SOC and security terms explained
The terms you need to understand alerts, investigations and job descriptions — explained without jargon.
Updated October 2026 · 48 terms
Plain-English definitions of the cybersecurity and Security Operations Center terms you will meet in courses, job descriptions, interviews and on your first shift.
A
Alert
A notification from a security tool that something matches a rule or looks suspicious. Alerts are the starting point for most SOC investigations, and many turn out to be false positives.
Attack surface
All the points where an attacker could try to get into an organization: devices, accounts, applications, cloud services and people.
B
Brute-force attack
Repeatedly guessing passwords until one works. Shows up in logs as many failed sign-ins against one or more accounts.
Business email compromise (BEC)
A scam in which an attacker uses a compromised or spoofed email account to trick staff into sending money or sensitive data.
C
C2 (command and control)
The channel an attacker uses to send instructions to compromised systems and receive data back.
CIA triad
Confidentiality, integrity and availability — the three core goals of information security.
Containment
Limiting the damage of an incident, for example by disabling a compromised account or isolating an infected device.
Credential stuffing
Trying usernames and passwords leaked from one breach against other services, relying on people reusing passwords.
CVE
Common Vulnerabilities and Exposures: a public identifier for a specific, known vulnerability, such as CVE-2021-44228.
CVSS
Common Vulnerability Scoring System: a standard way to rate how severe a vulnerability is, on a scale from 0 to 10.
D
Defense in depth
Using several layers of security controls so that if one fails, others still protect the organization.
E
EDR
Endpoint Detection and Response: software on laptops and servers that records activity, detects threats and lets analysts investigate and isolate devices.
Escalation
Passing an incident to a more senior analyst or another team because it needs more expertise, authority or time.
Event ID 4624 / 4625
Windows Security log events for a successful logon (4624) and a failed logon (4625). Key evidence in many identity investigations.
Exfiltration
The unauthorized transfer of data out of an organization.
F
False negative
A real threat that security tools failed to detect. Often more dangerous than a false positive, because nobody investigates it.
False positive
An alert that looks suspicious but turns out to be harmless. Recognizing and closing false positives confidently is a core SOC skill.
Firewall
A control that allows or blocks network traffic based on rules about addresses, ports and protocols.
I
IDS / IPS
Intrusion Detection System / Intrusion Prevention System: tools that inspect network traffic for malicious patterns. An IDS alerts; an IPS can also block.
Impossible travel
Sign-ins to the same account from locations too far apart to reach in the time between them — a common sign of account compromise, though VPNs can cause false positives.
Incident
A confirmed or suspected event that threatens the confidentiality, integrity or availability of systems or data.
Incident response
The structured process of preparing for, detecting, containing, eradicating and recovering from security incidents, then learning from them.
Indicator of compromise (IOC)
Evidence that a system may have been compromised, such as a malicious IP address, domain, file hash or email sender.
L
Lateral movement
Techniques an attacker uses to move from one compromised system to others within the same network.
Least privilege
Giving users and systems only the access they need to do their job, and nothing more.
Living off the land
Attacks that abuse legitimate built-in tools such as PowerShell, so malicious activity blends in with normal administration.
M
Malware
Malicious software, including viruses, trojans, worms, spyware and ransomware.
MFA
Multi-factor authentication: requiring a second proof of identity, such as an app prompt or security key, in addition to a password.
MFA fatigue
An attack where the attacker, who already has a password, sends repeated MFA prompts hoping the user approves one to make them stop.
MITRE ATT&CK
A public knowledge base of attacker tactics and techniques, used as a common language for describing and detecting attacks.
P
Phishing
Fraudulent messages designed to trick people into revealing credentials, opening malicious attachments or making payments.
Playbook
A documented, step-by-step procedure for handling a specific type of alert or incident.
Privilege escalation
Gaining higher permissions than an account is supposed to have, for example moving from a standard user to an administrator.
R
Ransomware
Malware that encrypts or steals data and demands payment to restore access or prevent publication.
S
Severity
How serious an alert or incident is, based on its impact and scope. Severity determines how quickly it must be handled.
SIEM
Security Information and Event Management: a platform that collects logs from across an organization so analysts can search, correlate and alert on them.
SOAR
Security Orchestration, Automation and Response: tools that automate repetitive SOC tasks and connect security products together.
SOC
Security Operations Center: the team, processes and tools responsible for monitoring and responding to security threats.
Spear phishing
A targeted phishing attack aimed at a specific person or group, often using personal or company details to appear legitimate.
T
Threat hunting
Proactively searching for attackers who have evaded existing detections, usually starting from a hypothesis.
Threat intelligence
Information about attackers, their infrastructure and their techniques, used to detect and prioritize threats.
Triage
Quickly assessing an alert to decide whether it is real, how serious it is and what should happen next.
True positive
An alert that correctly identified malicious or unwanted activity.
TTPs
Tactics, techniques and procedures: how a particular attacker or group typically operates.
V
Vulnerability
A weakness in software, hardware, configuration or process that could be exploited by an attacker.
X
XDR
Extended Detection and Response: tools that combine data from endpoints, email, identity, network and cloud into a single detection and investigation view.
Z
Zero trust
A security model that never assumes trust based on network location and verifies every user, device and request.
Zero-day
A vulnerability that is being exploited before the vendor has released a fix.
Keep learning
Definitions are the first step. To see these concepts in action, follow the SOC analyst roadmap or investigate a realistic incident in the SOC Analyst simulator.
See the terms in action
Learn the vocabulary by doing the work.
Investigate realistic alerts and see how these concepts show up in real evidence.