Back to Companion Guides
    Reference Material

    First SOC Shift — Glossary

    Complete glossary of SOC terminology with simple, practical definitions and context from the story.

    This glossary is not meant to be memorized. It exists to help you recognize and feel comfortable with the language used in a real Security Operations Center.

    This will open your print dialog. Print as usual, or select "Save as PDF" to download.

    SOC & Workflow

    Security Operations Center (SOC)

    A SOC is a team responsible for monitoring systems, investigating suspicious activity, and coordinating responses to security issues. It operates continuously and relies on people, processes, and judgment as much as technology.

    In the Story: The SOC is the primary setting where the intern learns how security work actually happens.
    Chapters: 1–8

    Alert

    An alert is a signal that something might require attention. It does not automatically mean something is wrong, only that someone should look closer.

    In the Story: Alerts appear constantly and force the team to decide what matters.
    Chapters: 1–5

    Event

    An event is a recorded action or occurrence, such as a login attempt. Most events are normal and never become security issues.

    In the Story: Events are often mentioned when explaining why some activity does not need escalation.
    Chapters: 1–2

    Alert Queue

    The alert queue is the list of alerts waiting to be reviewed by analysts. It reflects both workload and pressure in the SOC.

    In the Story: The intern learns to read the alert queue as a signal of pace and risk.
    Chapters: 1–2

    Triage

    Triage is the process of prioritizing what needs attention first based on urgency and potential impact. It is about decision-making, not fixing everything at once.

    In the Story: A senior analyst explains triage while continuing work, reinforcing that it is continuous, not formal.
    Chapters: 1–2

    Ticket / Case

    A ticket or case is the written record of a potential security issue, including observations, decisions, and actions taken.

    In the Story: The intern learns that documentation is as important as investigation.
    Chapters: 1–4

    Incident

    An incident is a confirmed security issue that requires coordinated response. Not every alert becomes an incident.

    In the Story: The team uses the term carefully, emphasizing restraint.
    Chapters: 1–5

    Escalation

    Escalation means involving additional people or taking stronger action as risk increases. It reflects responsibility, not failure.

    In the Story: Escalation decisions create tension when evidence is incomplete.
    Chapters: 1–3, 7–8

    Shift Change / Shift Handover

    Shift handover is the structured transfer of responsibility and context between teams. It ensures continuity across time.

    In the Story: The intern grows from observing handovers to leading parts of them.
    Chapters: 1, 8

    On-Call

    On-call staff are available to respond outside normal hours if issues escalate.

    In the Story: Being on-call reinforces that security work does not stop.
    Chapters: 1, 8

    Monitoring & SIEM

    Monitoring

    Monitoring is the continuous observation of systems and activity to maintain awareness. It focuses on visibility rather than reaction.

    In the Story: Monitoring is always present, even when nothing appears wrong.
    Chapters: 1–8

    SIEM

    A SIEM (Security Information and Event Management) is a tool that collects and analyzes logs from many sources to detect suspicious patterns.

    In the Story: The intern learns to navigate the SIEM as a core investigation tool.
    Chapters: 1–4

    Log

    A log is a recorded entry of system activity, such as logins, file access, or errors.

    In the Story: Logs are referenced frequently during investigations.
    Chapters: 1–6

    Correlation

    Correlation is connecting related events across systems or time to identify patterns that single alerts might miss.

    In the Story: Correlation helps detect password spraying and lateral movement.
    Chapters: 2–5

    Threats & Attacks

    Phishing

    Phishing is an attempt to trick users into revealing credentials or installing malware through fake emails or websites.

    In the Story: A phishing email leads to the first multi-day investigation.
    Chapters: 3–4

    Malware

    Malware is malicious software designed to harm or exploit systems.

    In the Story: Malware follows phishing when a user clicks a bad link.
    Chapters: 3

    Password Spraying

    Password spraying is an attack where common passwords are tried across many accounts to avoid lockouts.

    In the Story: The intern helps detect password spraying through pattern recognition.
    Chapters: 2

    Lateral Movement

    Lateral movement is when an attacker moves between systems inside the network after initial access.

    In the Story: Internal traffic anomalies raise lateral movement concerns.
    Chapters: 5

    False Positive

    A false positive is an alert that appears suspicious but turns out to be harmless.

    In the Story: The team manages alert fatigue by recognizing false positives.
    Chapters: 1–3

    True Positive

    A true positive is an alert that correctly identifies real malicious activity.

    In the Story: True positives require response and escalation.
    Chapters: 3–5

    Response & Investigation

    Containment

    Containment limits the spread or impact of an incident without fully removing the threat.

    In the Story: Isolating a host is an example of containment.
    Chapters: 3, 5

    Eradication

    Eradication removes the root cause of an incident after containment stabilizes the situation.

    In the Story: Eradication happens after the team understands scope.
    Chapters: 3, 6

    DFIR (Digital Forensics and Incident Response)

    DFIR teams investigate incidents deeply, preserve evidence, and support legal or compliance needs.

    In the Story: The SOC supports DFIR by maintaining evidence integrity.
    Chapters: 6

    Chain of Custody

    Chain of custody is the documented handling of evidence to ensure it remains untampered.

    In the Story: The intern learns to avoid actions that break chain of custody.
    Chapters: 6

    IOC (Indicator of Compromise)

    An IOC is evidence that an attack may have occurred, such as a malicious IP or file hash.

    In the Story: IOCs are used to search for related activity.
    Chapters: 3–5

    Post-Incident & Improvement

    Post-Incident Review

    A post-incident review is a structured discussion after an incident to identify lessons learned.

    In the Story: The team conducts a review to improve detection.
    Chapters: 7

    Playbook / SOP

    A playbook or SOP (Standard Operating Procedure) documents how to respond to specific scenarios.

    In the Story: Playbook updates follow lessons learned.
    Chapters: 7

    Detection Gap

    A detection gap is a blind spot where malicious activity might go unnoticed.

    In the Story: Reviews focus on closing detection gaps.
    Chapters: 7