IOC

An Indicator of Compromise (IOC) is an artifact — such as a hash, IP, or domain — that signals a possible intrusion. CBRCOR covers using IOCs (and behavioral indicators) in detection and hunting.

All 350-201 Terms

SOC

A Security Operations Center (SOC) is the team and facility that monitors, detects, and responds to security incidents.

SIEM

A Security Information and Event Management (SIEM) system aggregates and correlates logs and alerts to detect threats.

SOAR

Security Orchestration, Automation, and Response (SOAR) automates incident-response playbooks to accelerate detection and containment.

Playbook

A Playbook is a documented, often automated sequence of response actions for a specific incident type.

Incident Response

Incident Response is the structured process of detecting, analyzing, containing, eradicating, and recovering from security incidents.

Threat Hunting

Threat Hunting is the proactive, hypothesis-driven search for threats that have evaded automated detection.

Threat Intelligence

Threat Intelligence is curated information about adversaries, their infrastructure, and indicators used to inform detection and response.

MITRE ATT&CK

MITRE ATT&CK is a knowledge base of adversary tactics and techniques used to map, detect, and reason about attacks.

IOC

An Indicator of Compromise (IOC) is an artifact — such as a hash, IP, or domain — that signals a possible intrusion.

Forensics

Digital Forensics is the disciplined collection and analysis of evidence from hosts, networks, and memory during an investigation.

Chain of Custody

Chain of Custody is the documented, unbroken record of who handled evidence and when, preserving its integrity.

Risk Scoring

Risk Scoring quantifies the severity and priority of vulnerabilities and incidents, often using CVSS and business context.

CVSS

The Common Vulnerability Scoring System (CVSS) rates vulnerability severity using standardized metrics.

Vulnerability Management

Vulnerability Management is the ongoing process of identifying, prioritizing, and remediating security weaknesses.

API Integration

API Integration connects security tools so data and actions flow automatically across the SOC toolchain.