First SOC Shift — Glossary
Complete glossary of SOC terminology with simple, practical definitions and context from the story.
This glossary is not meant to be memorized. It exists to help you recognize and feel comfortable with the language used in a real Security Operations Center.
This will open your print dialog. Print as usual, or select "Save as PDF" to download.
First SOC Shift — Glossary
First SOC Shift Companion Guide
SOC & Workflow
Security Operations Center (SOC)
A SOC is a team responsible for monitoring systems, investigating suspicious activity, and coordinating responses to security issues. It operates continuously and relies on people, processes, and judgment as much as technology.
Alert
An alert is a signal that something might require attention. It does not automatically mean something is wrong, only that someone should look closer.
Event
An event is a recorded action or occurrence, such as a login attempt. Most events are normal and never become security issues.
Alert Queue
The alert queue is the list of alerts waiting to be reviewed by analysts. It reflects both workload and pressure in the SOC.
Triage
Triage is the process of prioritizing what needs attention first based on urgency and potential impact. It is about decision-making, not fixing everything at once.
Ticket / Case
A ticket or case is the written record of a potential security issue, including observations, decisions, and actions taken.
Incident
An incident is a confirmed security issue that requires coordinated response. Not every alert becomes an incident.
Escalation
Escalation means involving additional people or taking stronger action as risk increases. It reflects responsibility, not failure.
Shift Change / Shift Handover
Shift handover is the structured transfer of responsibility and context between teams. It ensures continuity across time.
On-Call
On-call staff are available to respond outside normal hours if issues escalate.
Monitoring & SIEM
Monitoring
Monitoring is the continuous observation of systems and activity to maintain awareness. It focuses on visibility rather than reaction.
SIEM
A SIEM (Security Information and Event Management) is a tool that collects and analyzes logs from many sources to detect suspicious patterns.
Log
A log is a recorded entry of system activity, such as logins, file access, or errors.
Correlation
Correlation is connecting related events across systems or time to identify patterns that single alerts might miss.
Threats & Attacks
Phishing
Phishing is an attempt to trick users into revealing credentials or installing malware through fake emails or websites.
Malware
Malware is malicious software designed to harm or exploit systems.
Password Spraying
Password spraying is an attack where common passwords are tried across many accounts to avoid lockouts.
Lateral Movement
Lateral movement is when an attacker moves between systems inside the network after initial access.
False Positive
A false positive is an alert that appears suspicious but turns out to be harmless.
True Positive
A true positive is an alert that correctly identifies real malicious activity.
Response & Investigation
Containment
Containment limits the spread or impact of an incident without fully removing the threat.
Eradication
Eradication removes the root cause of an incident after containment stabilizes the situation.
DFIR (Digital Forensics and Incident Response)
DFIR teams investigate incidents deeply, preserve evidence, and support legal or compliance needs.
Chain of Custody
Chain of custody is the documented handling of evidence to ensure it remains untampered.
IOC (Indicator of Compromise)
An IOC is evidence that an attack may have occurred, such as a malicious IP or file hash.
Post-Incident & Improvement
Post-Incident Review
A post-incident review is a structured discussion after an incident to identify lessons learned.
Playbook / SOP
A playbook or SOP (Standard Operating Procedure) documents how to respond to specific scenarios.
Detection Gap
A detection gap is a blind spot where malicious activity might go unnoticed.