Abuse.ch
Community-driven malware infrastructure tracking; free public feeds for malicious IPs, domains, and hashes. Strong on ransomware family tracking.
Cybersecurity Applications & Tools.
The vendor and platform vocabulary an analyst meets in the SOC. Each tool is defined by what it does: threat-intel feed, EDR, SIEM, SOAR, IAM, forensics, network security. The name on the slide maps back to a category an analyst can reason about.
Sources of curated indicators, campaign reports, and analyst-grade intelligence.
Vocabulary for: Uncover
Community-driven malware infrastructure tracking; free public feeds for malicious IPs, domains, and hashes. Strong on ransomware family tracking.
Collaborative threat-intel exchange aggregating IOCs from a global community, with SIEM/automated integrations.
Collects, analyzes, and prioritizes threat data with enrichment and risk scoring; integrates with existing security stacks.
U.S. Cybersecurity and Infrastructure Security Agency advisories on vulnerabilities and active threats, with mitigation guidance.
Electricity sector ISAC; threat intel, IR support, and risk analysis tailored to grid operators.
Rapid high-priority notifications about imminent cyber threats targeting public and private partners.
Global financial-sector ISAC providing real-time alerts, incident coordination, and member collaboration.
Filters internet background-scan noise so SOCs focus on targeted attacks. IP context with malicious vs. benign classification.
Healthcare-sector ISAC; threat intelligence, incident response coordination, and best practices for clinical environments.
Commercial deep/dark-web monitoring with adversary infrastructure, TTP, and threat-actor behavior intelligence.
Global knowledge base of adversary tactics, techniques, and procedures. The shared vocabulary of modern SOCs.
Multi-State ISAC for U.S. state, local, tribal, and territorial governments; alerts, IR, and risk management resources.
UK National Cyber Security Centre; guidance, threat intelligence, and IR services across public and private sectors.
Successor to RiskIQ PassiveTotal (acquired by Microsoft, 2021). Aggregates passive DNS, WHOIS, SSL, and infrastructure data for attribution and threat hunting.
Community-validated database of phishing URLs; supplies security tools and browsers with up-to-date intelligence.
Threat-intelligence platform combining machine learning with human analysis across open, dark, and technical sources.
External Attack Surface Management, the renamed RiskIQ Illuminate (acquired by Microsoft, 2021). Discovers and monitors internet-facing assets, third-party services, and shadow IT.
Training, certification, and research; publishes critical threat research and runs the Internet Storm Center.
Free analysis of files and URLs across many AV engines; community sharing and reputation data.
Protocol and database of domain registration data; used to investigate suspicious domains and attribution.
Records and logs API activity within an AWS account, the audit trail for security and forensic work.
Monitoring and observability for AWS resources and applications; metrics, logs, alarms, automation hooks.
Microsoft’s cloud identity and access management; SSO, MFA, conditional access, and integration with SaaS apps.
Cloudflare’s threat-research team and intelligence service; produces actionable indicators, campaign tracking, and disruption support against active adversaries.
DLP, cloud security, and insider-threat behavior analytics across endpoints, networks, and cloud applications.
Cloud-native security analytics platform from Google Cloud; high-speed search and threat detection at petabyte scale. Chronicle was folded into the Google Security Operations (Google SecOps) brand in 2024.
Cloud-native SIEM/SOAR (formerly Azure Sentinel); AI-driven analytics across on-prem, cloud, and hybrid with rich connector library, plus a built-in UEBA module for user and entity behavior analytics.
Agentless cloud security; full-stack visibility, vulnerability management, and risk prioritization across cloud workloads.
Cloud-native security platform from Palo Alto Networks; workload protection, IaC scanning, compliance, runtime defense.
Cloud-native security focused on container runtime, Kubernetes monitoring, and cloud workload protection.
Agentless cloud risk visibility; correlates infra/config/workload data to map attack paths and prioritize risk.
Where the logs go to be aggregated, normalized, and queried. The SOC’s primary lens.
Vocabulary for: Alert
Long-standing SIEM with strong correlation engine for compliance reporting and forensic analysis.
Data routing and processing for observability pipelines; filter, enrich, and reduce log data before forwarding.
Unified security on the Elastic Stack; endpoint protection, prebuilt detections, and customizable monitoring.
Next-gen SIEM with built-in UEBA; user-behavior timelines and automated investigation workflows.
Open-source data collector that unifies log collection and processing across distributed systems via plugins.
Enterprise SIEM with real-time correlation, ML-assisted prioritization, and broad ecosystem integration.
Server-side pipeline that ingests, transforms, and forwards data; central to the Elastic Stack.
Aggregation and correlation of security event data for centralized detection, compliance, and IR.
Open, vendor-neutral detection-rule format: write a detection once in YAML, convert it to the query language of whatever SIEM is in use. The de facto standard for sharing detection logic between teams and tools.
Source: SigmaHQPremium SIEM on the Splunk platform; correlation searches, ML, prebuilt content for SOC workflows.
Windows service that produces rich endpoint telemetry, process creation, network connections, file events, for SIEM ingestion.
EDR with behavior analysis, anti-exploit, root-cause analysis, and policy-based remediation.
Cloud-native EDR with a lightweight agent; combines behavioral analytics, threat intel, and ML.
EDR/XDR focused on endpoint visibility, malware detection, IR, and deep process-tree forensics.
Self-learning AI; builds behavioral baselines, detects anomalies, autonomously responds via its RESPOND module (formerly Antigena).
DLP and endpoint security with context-aware policies for data usage across endpoints, networks, cloud.
Managed threat-hunting service on top of CrowdStrike Falcon; 24/7 human-led analysis to validate stealthy intrusions.
Deception-based identity-threat detection. Plants fake credentials and decoy paths to surface attacker lateral movement. Illusive Networks acquired by Proofpoint, 2022.
Attack-chain visualization, IOC search, sandboxing, and threat-intel integration with centralized management. U.S. sales were prohibited by a June 2024 Commerce Department determination; still widely deployed elsewhere.
Lightweight EDR with strong remediation; ransomware rollback and post-infection recovery.
Antivirus, endpoint protection, EDR (Defender for Endpoint), and XDR ties to Sentinel and Entra ID.
Unified EPP/EDR with behavioral AI, autonomous response, rollback on Windows, and threat-hunting telemetry.
Next-gen AV plus EDR with deep learning and exploit prevention; strong investigation tools for SMB and enterprise.
Endpoint protection, email security, DLP, and EDR; global sensor network feeding detection and response.
Part of the broader Trellix XDR; detection, investigation, and response with behavioral analytics and forensic timelines.
XDR correlating telemetry across email, endpoint, server, and cloud workloads.
Extended detection and response: correlates telemetry across endpoint, identity, email, network, and cloud into unified detections and response actions, extending EDR beyond the single host.
The kit that turns a disk image, a memory dump, or a phone into a defensible report.
Vocabulary for: Uncover · Escalation
Open-source forensics platform on The Sleuth Kit; timeline analysis, keyword search, file carving, media analysis.
DFIR tool focused on memory, disk, mobile, and cloud forensics; parses encrypted containers and RAM dumps.
Industry standard for mobile-device extraction and analysis; UFED covers a wide range of devices.
Long-standing digital-investigation suite; acquisition, indexing, analysis, and court-admissible reporting.
Kroll Artifact Parser and Extractor; free triage tool that collects and parses forensic artifacts from a live system in minutes. A staple for fast evidence capture before (or instead of) full disk imaging.
Source: KrollForensics across computers, mobile, cloud, IoT; powerful artifact parsing and cross-source correlation.
Mobile forensics for law enforcement; XRY for extraction, XAMN for evidence visualization, XEC for lab management.
Mobile, cloud, drone, and IoT forensics with deep parsing of app data including secure messengers.
Open-source engine behind log2timeline; parses disk images and artifacts from many sources into a single super-timeline. The standard tooling for timeline-based forensic analysis.
Source: plaso docsOpen-source endpoint-visibility and DFIR platform (stewarded by Rapid7); hunts for and collects artifacts across entire fleets using its VQL query language.
Source: Velociraptor docsOpen-source memory-forensics framework; extracts processes, network connections, injected code, and credentials from RAM captures. Volatility 3 is the current generation.
Source: Volatility FoundationLightweight, fast forensic suite with strong scripting and hex-level analysis for deep investigations.
Who you are, what you can touch, and how the SOC proves it.
Vocabulary for: Subject
Privileged access management; just-in-time access, password vaulting, session monitoring, endpoint privilege management.
Market leader in PAM; credential rotation, secret management, session monitoring, secure remote access.
MFA, device trust, and contextual access; widely used for remote access and SaaS protection.
Identity platform with SSO, MFA, lifecycle management, and federation across thousands of apps.
IGA with lifecycle, RBAC, privileged access governance; unifies AD, Azure AD, and cloud platform identity.
Cloud-first identity for SSO, MFA, and customer IAM; strong hybrid and multi-cloud support. Absorbed ForgeRock (acquired by Thoma Bravo, 2023) and now ships its enterprise IAM lifecycle and governance products under the Ping brand.
Identity governance with least-privilege enforcement, access reviews, and ML-driven anomaly detection.
Cloud-delivered DNS-layer security; blocks malicious domains at resolution time, secures outbound web traffic.
IT asset discovery and inventory; CMDB foundations and continuous visibility into devices, software, and users.
Cisco-developed protocol for flow-based monitoring and anomaly detection; metadata about traffic sessions.
Vulnerability management with dynamic scans and exploitability-based prioritization; pairs with Metasploit.
Vulnerability scanner with authenticated/unauthenticated scans and compliance framework support.
Network intrusion detection: inspects traffic for signatures, protocol anomalies, and behavioral indicators.
Open-source NIDS with deep packet inspection and a large community rule set maintained by Cisco Talos.
Open-source NIDS/IPS with multi-threaded inspection, file extraction, TLS inspection, and JSON output.
File-integrity monitoring and change detection; enforces baselines and supports compliance.
Open-source packet analyzer; deep protocol decoding for investigation and forensics.
Behavior-focused network monitoring producing structured session logs for SIEM-friendly analytics.
Where playbooks live, alerts get enriched, and analysts get back their afternoons.
Vocabulary for: Escalation · Documentation
XDR with autonomous investigation and remediation playbooks aimed at small-to-mid SOCs.
Open-source forensic-artifact collector from ANSSI (the French national cyber agency). Runs on Windows endpoints to gather a broad, configurable set of artifacts for offline post-compromise analysis. Not a case-management platform.
SOAR with advanced playbooks, threat-intel enrichment, KPI tracking, and human-in-the-loop decisions. DFLabs acquired by Sumo Logic, 2021.
Comprehensive SOAR with case management, threat intel, playbook-driven automation, and hundreds of integrations.
ITSM and security workflow with ticketing, change management, CMDB integration, and security automation.
SOAR with case management, playbooks, and analyst dashboards; integrated with Google SecOps (Chronicle) telemetry. Siemplify acquired by Google, 2022; fully integrated into Google SecOps.
Security orchestration, automation, and response: define, automate, and orchestrate IR workflows at scale.
SOAR with Python-based playbooks, 300+ integrations, and deep Splunk analytics ties. Phantom acquired by Splunk in 2018 and renamed Splunk SOAR in 2021; Splunk itself acquired by Cisco, 2024.
Low-code SOAR for SOC analysts to build automation workflows without deep programming expertise.
IR platform with collaborative case management; integrates with Cortex for automated analysis. TheHive 5 is a commercial product from StrangeBee; the open-source TheHive 4 reached end of life in December 2022.
No-code automation built for security teams; modular “stories” for alert ingestion, enrichment, and response.
Sandboxes for malware, honeypots for attackers, and frameworks for stress-testing defenses.
Vocabulary for: Uncover
Interactive malware sandbox with behavioral and network analysis for collaborative investigation.
Deception platform deploying low-interaction honeypots that produce high-fidelity alerts on attacker interaction.
Open-source automated malware analysis running suspect files in VMs and capturing behavior. The original project’s final release was 2.0.7 (2019) and it is no longer maintained; community successors (CAPEv2, Cuckoo3) carry the approach forward.
Deception platform with realistic traps and decoys to misdirect attackers and surface intrusion attempts.
Breach-and-attack simulation validating security controls against real-world TTPs. Verodin acquired by FireEye, 2019; renamed 2020; Mandiant acquired by Google Cloud, 2022.
Breach-and-attack simulation continuously testing defenses across the kill chain.
Deception with decoys and lures mimicking real IT; alerts on engagement and provides attacker-TTP insight. Smokescreen acquired by Zscaler, 2021.
Threat-intel platform with playbooks for attack simulation, response automation, and intel-driven workflows.
Cloud sandbox combining behavior analysis with threat intelligence for advanced-malware investigation.
Deception and threat detection with decoys across endpoints, networks, and cloud. TrapX Security acquired by Commvault, 2022; rebranded as ThreatWise.
Open-source pattern-matching engine for identifying and classifying malware: rules describe strings, byte sequences, and conditions that a file or memory region must satisfy. The lingua franca for sharing malware signatures.
Source: YARA docsThreat research and malware sandboxing powering Zscaler’s cloud security services.
Scanners, fuzzers, and surface-discovery tools that find the holes before adversaries do.
Vocabulary for: Risk
Automated web vulnerability scanner for SQLi, XSS, misconfig, and modern-web/SPA technologies.
Industry-leading web app security tooling: intercepting proxy, scanning, manual pentest tools, and extensions.
Internet-wide asset discovery via continuous scanning; SSL/TLS, services, and attack-surface monitoring.
Open-source web-server scanner for dangerous files, outdated components, and known issues.
Network discovery and security auditing with rich NSE scripting for service detection.
Free, open-source web app security testing with automated and manual capabilities.
Cloud-based vulnerability management, policy compliance, and web app scanning across enterprise estates.
Search engine for internet-connected devices; identifies exposed services, outdated software, ICS, IoT.
Vulnerability management platform; Nessus-based scanning with on-prem, cloud, and hybrid coverage.
Open-source web app scanner combining automated checks with a manual testing framework.
Open-source command-line web vulnerability scanner; crawls and injects payloads for common flaws.
What you actually need before ransomware shows up, backups, immutability, and recovery posture.
Vocabulary for: Risk
Backup with integrated anti-malware; blockchain-based notarization and broad workload coverage.
Unified data protection with replication, HA, and ransomware-resistant immutable storage.
Cloud-based backup and DR for SMBs; encrypted transmission, hybrid backup, ransomware features.
Cloud-native endpoint data protection focused on insider risk and self-service restore. Code42 acquired by Mimecast, July 2024; Incydr folded into the Mimecast platform.
Unified data management; backup, archive, governance, and SaaS-app protection with AI analytics.
Cloud-native, agentless data protection for endpoints, data center, and cloud workloads.
Cloud-native data management; instant recovery, immutable backups, and ransomware detection.
Backup and recovery across virtual, physical, and cloud workloads with cloud-mobility options.
Enterprise-grade backup with broad workload coverage and centralized hybrid-cloud management.
The languages, frameworks, and editors that the rest of security operations runs on top of.
Vocabulary for: Uncover
Open-source automation for config management, deployment, and orchestration via YAML playbooks.
Cross-platform desktop app framework using web technologies; powers Cursor, VS Code, Slack, and more.
Open-source CI/CD automation server; builds, tests, and deploys with a vast plugin ecosystem.
Event-driven JavaScript runtime on V8; backend services, APIs, automation scripts, and tooling.
Task automation and configuration shell built on .NET; cross-platform via PowerShell Core.
High-level language ubiquitous in security tooling, automation, data analysis, and ML.
Lightweight, extensible code editor from Microsoft; rich ecosystem of extensions for development and security.
Tools that keep the fleet patched, the baselines enforced, and the auditors quiet.
Vocabulary for: Risk
Web-based interface for Ansible automation; RBAC, scheduling, visual dashboards, workflow orchestration.
Endpoint management platform automating patching, compliance, and security configuration at scale. Originally an IBM product; acquired by HCL in 2019.
Infrastructure-as-code platform enforcing security configurations via recipes and cookbooks.
Formerly System Center Configuration Manager (SCCM). Patching, software distribution, and compliance for Windows ecosystems; now part of the Microsoft Intune family alongside cloud-only endpoint management.
Free Microsoft tool for centrally approving and distributing Windows updates within an organization.
Automates installation and updates of popular third-party software across many endpoints.
Config management automating patching and continuous compliance through code-defined policies.
Cloud-based patching tied to vulnerability management; prioritizes patches by risk exposure.
Centralized patching for Windows and third-party apps; integrates with WSUS and Microsoft Configuration Manager (MECM/SCCM).
Patch management, software distribution, and configuration enforcement across enterprise endpoints.
Cameras, badge readers, intrusion detection, and the tools that bridge physical and cyber. In triage this data surfaces almost exclusively in insider cases: badge and camera records corroborate, or contradict, where an account’s owner physically was when the account acted.
Vocabulary for: Subject
HD surveillance, video analytics, and access control with AI-powered anomaly detection.
Pioneer of network video surveillance; broad IP-camera portfolio with edge analytics.
Surveillance, intrusion detection, access, and fire across enterprise and critical-infrastructure deployments.
Converged networking-plus-security platform unifying surveillance, access, and IoT device management.
Unified Security Center for video surveillance, access control, and license plate recognition.
Integrated physical security: surveillance, access, intrusion detection, alarms across critical infrastructure.
Physical security with OpenBlue platform; security plus building automation, with cybersecurity built in.
OnGuard access control, video, and alarm management for enterprise environments.
Open-platform IP video management with broad camera support and rich analytics.
Surveillance cameras, recorders, and VideoXpert management; rugged builds for outdoor and industrial use.
End-to-end surveillance with the Valerus VMS platform; open architecture and flexible deployment.
Three questions on the tool categories. The name on the slide should map to a category you can reason about.
Perimeter logs show constant scanning from the internet, and you need to know which sources are targeting you specifically versus scanning everyone. Which tool answers that?
GreyNoise exists for exactly this cut: it classifies internet-wide background-scan noise so the SOC can subtract it and focus on activity aimed at them specifically. VirusTotal is multi-engine file and URL analysis, PhishTank is a community-validated phishing-URL database, and WHOIS is domain registration data useful for attribution. None of the other three tells you whether a scanner is hitting everyone or just you.
Strip away the vendor names: what is the SIEM category, as a concept?
The SIEM is the aggregation and correlation layer: telemetry from endpoints, network, identity, and cloud lands in one place where correlation rules, search, and reporting run across all of it. The distractors are its neighbors: EDR is the endpoint agent that feeds it, SOAR is the automation layer that acts on what it finds, and vulnerability scanning is a separate discipline. Vendor suites blur these lines constantly, which is why the category behind the product name is the useful thing to hold onto.
An investigation needs to know exactly which AWS API calls a principal made last Tuesday. Which source holds that record?
CloudTrail records API activity within the account: who called what, when, from where. That makes it the audit trail for cloud security and forensic work, and the first pull in a cloud-anchored investigation. CloudWatch is the operations layer (metrics, logs, alarms), and a detection service like GuardDuty raises findings from telemetry but is not itself the audit record.