SOAR
Security Orchestration, Automation, and Response (SOAR) automates incident-response workflows and playbooks to speed detection and containment. CBROPS contrasts SOAR with SIEM in the monitoring toolset.
Security Orchestration, Automation, and Response (SOAR) automates incident-response workflows and playbooks to speed detection and containment. CBROPS contrasts SOAR with SIEM in the monitoring toolset.
The CIA triad is confidentiality, integrity, and availability — the three goals that security controls exist to protect.
Defense in Depth layers multiple independent controls so the failure of one does not expose the asset.
A Security Information and Event Management (SIEM) system aggregates and correlates logs from across the environment to detect and investigate threats.
Security Orchestration, Automation, and Response (SOAR) automates incident-response workflows and playbooks to speed detection and containment.
The Common Vulnerability Scoring System (CVSS) rates vulnerability severity using metrics like attack vector, complexity, and scope.
The 5-tuple is the set of source IP, destination IP, source port, destination port, and protocol that uniquely identifies a network conversation.
Threat Intelligence is curated information about adversaries, indicators, and techniques used to inform detection and response.
Threat Hunting is the proactive search for undetected threats in an environment using hypotheses and data analysis.
Runbook Automation (RBA) executes predefined operational and response procedures automatically to reduce manual effort and errors.
Deep Packet Inspection (DPI) examines packet payloads, not just headers, to identify applications and threats.
NetFlow records metadata about network conversations — addresses, ports, bytes, and timing — for visibility and analysis.
A PCAP (packet capture) is a stored record of raw network traffic that analysts examine with tools like Wireshark.
Chain of Custody is the documented, unbroken record of who handled evidence and when, preserving its integrity for investigations.
A Disk Image is a bit-for-bit copy of storage used in forensic analysis so the original evidence is preserved.
Incident Response is the structured process of detecting, containing, eradicating, and recovering from security incidents, guided by frameworks like NIST.