Take a tour

GET A demo

  • Solutions
  • Platform
  • Partners
  • Company
  • Resources
en
fr

Take a tour

GET A demo

en
fr
Solutions

Tailored cybersecurity built for your specific challenges and industry

By Use Case

SIEM replacement
Stack integration
Continuous threat detection
Automated incident response
Alert fatigue relief

By Vertical

Healthcare
Technology
Energy & Utilities
Government
Manufacturing
MSSP
Platform

Give your analysts their time back

UNIFIED SOC Platform

AI SOC Platform

PLATFORM IntegrationS

Integrations catalog

Products

Sekoia Defend
SIEM
Sekoia Intelligence
CTI
Sekoia Reveal
CAASM
Sekoia Elevate
AI SOC agents
See Sekoia in action

Curious about what our platform can do? Take a self-guided tour and explore the features that security teams rely on.

Take a tour

Partners

Join a powerful ecosystem of cyber experts, continuous training, and shared success

Partners

Our business partners
Why become a partner?
Partner portal

Services

Training courses
Sekoia university
Join our business partner ecosystem

Grow your business alongside Sekoia. Join a thriving network of partners and unlock new revenue opportunities in cybersecurity.

Become a partner

Why Sekoia?

Our story, our world-class team, and our latest updates

About us

About Sekoia
About TDR team
Customer reviews
Join us

Newsroom

Newsroom
Brand kit
Resources

Deepen your cyber knowledge with expert insights, reports, and real-world case studies

Blog

Blog

glossary

Cyberglossary

Resource center

Case studies
Solution briefs
Webinars
Reports
View all
Stay ahead of cyber threats

Get the latest insights on threat intelligence, SOC best practices and Sekoia product updates delivered straight to your inbox.

SUBSCRIBE

Cybersecurity glossary

Find all the terms related to Sekoia products and the world of cybersecurity.

All terms

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Index
Clear all
A
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Join our partner ecosystem

Grow your business alongside Sekoia. Join a thriving network of partners and unlock new revenue opportunities in cybersecurity.

Become a partner

2FA
Two-factor authentication is an electronic authentication method that adds an extra layer of security to online accounts by verifying a user's identity using two components, typically something they know and something they have.
read more
Advanced Persistent Threat (APT)
An Advanced Persistent Threat (APT) is a prolonged, targeted cyber attack in which an intruder gains access to a network and remains undetected for an extended period, with the goal of quietly stealing sensitive data, conducting espionage, or sabotaging critical systems. Unlike opportunistic attacks that go after easy targets, an APT is carefully planned to infiltrate a specific organization, evade its defenses, and stay hidden for weeks, months, or even years. These campaigns are usually carried out by well-funded, highly skilled teams, many of them state-sponsored.
read more
AI in cybersecurity
AI in cybersecurity refers to the use of artificial intelligence techniques, principally machine learning, deep learning, and generative AI, to strengthen how organizations detect, prevent, investigate, and respond to cyber threats. Rather than relying only on static rules and known signatures, AI analyzes vast volumes of data (network traffic, endpoint activity, logs, user behavior, and threat intelligence) to recognize patterns, flag anomalies, and predict emerging risks at a speed and scale no human team can match alone. The field has two complementary sides: AI for security, which applies AI to defend the organization, and security for AI, which protects AI systems themselves from attacks such as prompt injection and model poisoning. Increasingly, AI is becoming the operating model of modern security, powering autonomous agents that triage, investigate, and contain threats end to end.
read more
Alert Fatigue
Alert fatigue, also called alarm fatigue or notification fatigue, is the state that sets in when security analysts face so many alerts that they become desensitized and start to miss, dismiss, or under-investigate them, including the ones that matter. In a security operations center (SOC), tools such as a security information and event management (SIEM) system, endpoint detection and response (EDR), and dozens of others can generate tens of thousands of alerts a day, a large share of them false positives. When everything is flagged as urgent, nothing is, and a real intrusion can slip through in the noise. Alert fatigue is both an operational problem and a human one. Operationally, it slows detection and response and lets genuine threats go unexamined. On the human side, the endless triage of low-value alerts drives analyst burnout and turnover, which makes the problem worse. This page explains what alert fatigue is, what causes it, the damage it does, and the practical ways SOC teams reduce it.
read more
Anonymous Sudan
Anonymous Sudan is a hacktivist group that emerged in January 2023 and became known for a high-tempo campaign of distributed denial-of-service (DDoS) attacks against organizations in the United States, Europe, the Middle East, and beyond. The group presented itself as Sudanese hacktivists retaliating against perceived anti-Muslim acts, but its target selection consistently aligned with pro-Russian, anti-Western interests, and it operated closely with the pro-Russian group Killnet. Microsoft tracks the group as Storm-1359. In October 2024, the US Department of Justice unsealed an indictment against two Sudanese brothers alleged to run the operation and announced the seizure of its DDoS tooling. Anonymous Sudan stood out less for technical novelty than for scale, showmanship, and the fact that it sold its attack capacity to others as a DDoS-for-hire service. This page covers the group's origins and disputed attribution, how it operated, its notable attacks, the 2024 law-enforcement takedown, and how organizations defend against attacks of this kind.
read more
APT27 (LuckyMouse, EmissaryPanda)
APT27 is a China-nexus cyber espionage group active since at least 2010, known for long-running intrusions that steal information from government and industry targets around the world. It is widely assessed to be Chinese state-sponsored, and it is tracked under a large number of names, most commonly Emissary Panda, LuckyMouse, and Iron Tiger. MITRE ATT&CK catalogs it as G0027. Over more than a decade the group has built a broad toolset and a reputation for getting into a network and staying there, sometimes undetected for months or years. APT27 is a patient, access-focused actor rather than a smash-and-grab one. It typically breaks in through internet-facing web applications, establishes a quiet foothold, and works to expand access and collect intelligence over the long term. This page covers the group's attribution and aliases, who it targets, how it operates, its malware and notable campaigns, and how organizations defend against it, drawing in part on first-party research by Sekoia's Threat Detection & Research (TDR) team.
read more
APT28
APT28 (also known as Fancy Bear) is a Russian state-sponsored threat actor active since at least 2004. Attributed to the GRU (Russian Military Intelligence), the group specializes in cyber espionage, targeting government, military, and security organizations globally to gather strategic intelligence and influence political outcomes.
read more
APT29 aka Nobelium, Cozy Bear
APT29 is a Russian state-sponsored cyber espionage group attributed by the US, UK, and other governments to Russia's Foreign Intelligence Service (SVR). Active since at least 2008, it's one of the most capable and persistent nation-state actors tracked by the security community, defined by operational stealth, long dwell times, and a focus on intelligence collection rather than disruption or destruction. APT29 is also widely known as Cozy Bear, Midnight Blizzard (Microsoft's current designation), Nobelium, and The Dukes; MITRE ATT&CK tracks it as G0016. It's best known for the 2020 SolarWinds supply chain compromise and, more recently, for breaching Microsoft's corporate systems. Unlike noisier actors, APT29 prioritizes operational security and hard-to-detect access, and it has steadily shifted from malware-heavy intrusions toward cloud- and identity-focused tradecraft. This page covers the group's attribution and aliases, its place in the Russian threat ecosystem, its notable campaigns, how it operates today, and how organizations can defend against it.
read more
APT31
APT31 is a Chinese state-sponsored cyber espionage group that gathers intelligence in support of the interests of the People's Republic of China (PRC). Active for over a decade, it is best known for targeted spearphishing against governments, politicians, critical infrastructure, and businesses, and for stealing both political intelligence and commercial trade secrets. In March 2024, the United States and United Kingdom formally linked the group to China's Ministry of State Security (MSS), sanctioning a front company and indicting or sanctioning several individuals. The actor is tracked under several names, most commonly Zirconium, Judgment Panda, and Violet Typhoon, and MITRE ATT&CK catalogs it as G0128. APT31's targeting follows PRC strategic priorities rather than any single industry, and its tradecraft leans on legitimate services and compromised home and office routers to hide its activity. This page covers the group's attribution and aliases, who it targets, how it operates, its notable campaigns, and how organizations defend against it, drawing in part on first-party research by Sekoia's Threat Detection & Research (TDR) team.
read more
APT37 (Reaper)
APT37 is a North Korean state-sponsored cyber espionage group active since at least 2012. It is best known for stealthy, long-running intelligence collection against South Korean targets, and it has steadily widened its reach and sharpened its tradecraft over the past decade. The group is tracked under many names, most commonly Reaper and ScarCruft, and MITRE ATT&CK catalogs it as G0067. Its signature tool, a remote access trojan called ROKRAT, and its habit of hiding command-and-control traffic inside ordinary cloud services have become defining traits. Compared with North Korea's financially motivated operations, APT37 is an intelligence unit first. Its job is to gather information that supports the regime's political, military, and economic decisions, and its targeting reflects that: the people and institutions that shape or study policy toward North Korea. This page covers the group's attribution and aliases, who it targets, how it operates, its notable campaigns, and how organizations defend against an actor built for quiet, persistent access.
read more
AridViper
AridViper, also known as APT-C-23 or Desert Falcon, is a threat actor allegedly associated with Hamas, primarily focused on targeting Israeli organizations in the defense, law enforcement, and government sectors.
read more
BlackCat Ransomware
BlackCat ransomware, also known as ALPHV, is a sophisticated ransomware group that emerged in late 2021, known for its advanced cross-platform capabilities targeting Windows, Linux, and VMware ESXi systems.
read more
Bluenoroff
Bluenoroff is a North Korean state-sponsored advanced persistent threat group believed to be a subgroup of the Lazarus Group, also known as Hidden Cobra.
read more
Building an Effective SOC Team: Roles and Responsibilities
Building an effective SOC team means defining clear roles, responsibilities, and communication flows so that detection and response operations run seamlessly, since a Security Operations Center is only as strong as the people behind it.
read more
Building a SOC: Key Considerations for Security Leaders
Building a Security Operations Center is a strategic investment requiring careful planning across people, processes, and technology, with key decision points that determine whether the SOC delivers long-term value.
read more
Business Email Compromise
Business email compromise (BEC) is a form of targeted, email-based social-engineering fraud in which an attacker impersonates a trusted person, such as an executive, a colleague, or a vendor, to trick an employee into transferring money or handing over sensitive data. Unlike mass phishing, BEC is highly personalized and usually contains no malware, no malicious links, and no attachments. That's precisely what makes it so hard for traditional email security to catch. It's also known as email account compromise (EAC), and the FBI has described it as one of the most financially damaging online crimes tracked. Because BEC abuses normal business processes, an urgent request from the "CEO," a vendor's "updated" bank details, rather than exploiting a technical vulnerability, it succeeds against organizations of every size and maturity. This page explains what BEC is, how an attack unfolds, the main types the FBI recognizes, why it's so difficult to detect, its real-world scale, and how organizations can prevent and respond to it.
read more
Cactus ransomware
Cactus ransomware is ransomware that encrypts a victim's files and demands a ransom payment in exchange for restoring the stolen and encrypted data, entering victims' systems through various infection techniques.
read more
Calisto
Calisto is a Russian state-sponsored cyber espionage group active since at least 2017, best known for patient, highly targeted spearphishing aimed at stealing credentials from people who matter to Russian intelligence. In December 2023, a joint statement by the United States, United Kingdom, Canada, Australia, and New Zealand attributed the group to Russia's Federal Security Service (FSB), specifically its Centre 18. The actor is tracked under several names, most commonly Calisto (also spelled Callisto), Star Blizzard, and COLDRIVER. Unlike groups that rely on elaborate malware, Calisto's tradecraft is built around social engineering and identity theft. It studies its targets, impersonates trusted contacts, and lures them to credential-harvesting pages, then uses the stolen access to collect intelligence or to leak material in support of Russian information operations. This page covers the group's attribution and aliases, who it targets, how it operates, and how organizations defend against it, drawing in part on first-party research by Sekoia's Threat Detection & Research (TDR) team.
read more
Callback phishing
Callback phishing is a social engineering attack in which a lure, usually an email, prompts the victim to call a phone number instead of clicking a link or opening an attachment. When the victim calls, an attacker posing as a support agent for a trusted brand uses a scripted conversation to extract credentials or one-time passcodes, obtain payment, or talk the victim into installing remote access software. Because the email contains no malicious link or attachment, only a phone number, it slips past content-based email filters. That's precisely what makes the technique effective. Callback phishing is also known as Telephone-Oriented Attack Delivery (TOAD) and, in its original form, as BazarCall. What distinguishes callback phishing from ordinary phishing is the reversal of initiative: the victim makes the call, so the interaction feels voluntary and their guard is down. Ransomware crews adopted it as a reliable initial-access technique, and it now spans enterprise attacks and consumer fraud alike. This page explains how it works, where it came from, the brands and tools attackers abuse, how it differs from vishing and smishing, and how organizations can detect and defend against it.
read more
CERT (Computer Emergency Response Team)
A Computer Emergency Response Team (CERT) is a specialized group of cybersecurity experts responsible for protecting, detecting, and responding to cyber incidents within an organization or nation. They provide the technical expertise and coordination needed to mitigate threats like data breaches, ransomware, and system vulnerabilities.
read more
ClearFake
ClearFake is a malicious JavaScript framework used to deliver malware through compromised websites. It works by injecting code into legitimate sites, most often compromised WordPress sites, and then tricking visitors into installing malware through a fake prompt, originally a fake web browser update and, more recently, a fake CAPTCHA verification. First seen in July 2023, it belongs to the broader "fake updates" category of threats and has become one of the most active web-based malware delivery frameworks, evolving quickly and adopting techniques such as hiding its payloads on the blockchain. The name ClearFake comes from the fact that its injected JavaScript was written in clear, unobfuscated text in early versions, unusual for this kind of malware. This entry explains what ClearFake is, how its infection chain works, how its lures and delivery have evolved, what malware it delivers, and how organizations detect and defend against it, drawing in part on first-party research by Sekoia's Threat Detection & Research (TDR) team, which analyzed the threat from its emergence.
read more
Command & Control (C2) attack
A Command and Control (C2) attack is a technique in which an attacker establishes a covert communication channel between a compromised device and an attacker-operated server, known as the C2 server (also written C&C), to remotely issue instructions and receive stolen data. Once this channel is active, the adversary can download additional malware, move laterally across the network, exfiltrate sensitive data, or enlist the machine into a botnet. Command and control sits among the final stages of the Cyber Kill Chain, meaning that by the time C2 is established, initial defenses have already been bypassed. That's why fast C2 detection matters so much.
read more
Crypters
Crypters ("криптер" in Russian) are software programs that encrypt, obfuscate, and manipulate malware so it can bypass security detection while keeping its malicious functionality fully intact. A crypter takes a known malicious payload, such as an infostealer, remote access trojan (RAT), or ransomware. It wraps it in a layer that looks harmless to antivirus and other scanners, then decrypts and runs the original malware at execution time. The crypter itself isn't malicious code; it's a tool. But its purpose in the wrong hands is to disguise malware and enable its delivery, which is why crypters are a foundational component of the modern cybercrime supply chain. The ultimate goal is FUD status, short for Fully UnDetectable: the packaged malware evades every security vendor.
read more
CSIRT
A computer security incident response team (CSIRT) is an operational security team that an organization relies on to respond to cybersecurity incidents. When an incident is reported, the CSIRT analyzes it and carries out the actions needed to contain and resolve it. Between incidents it plays a preventive role through ongoing threat monitoring. The same function is described by several closely related terms: a computer incident response team (CIRT) and, more broadly, an incident response team all refer to the same idea, a dedicated group responsible for handling security incidents from detection through recovery. A CSIRT exists so that when something goes wrong, whether a data breach, a malware infection, or an account takeover, the organization has a prepared team with clear roles rather than improvising under pressure. This page explains what a CSIRT does, the roles it brings together, the three common types, how the term relates to CERT and SOC, and how organizations set one up or work with an external one.
read more
CustomerLoader
CustomerLoader is a malware that distributes a wide variety of payloads, including infostealers, remote access trojans, and ransomware, onto infected systems.
read more
Cybersecurity
Cybersecurity aims to protect companies' networks, systems, and sensitive data from digital attacks, through the use of IT security tools, proven methodologies, and training to prevent and contain attacks.
read more
Cyber Threat Intelligence (CTI)
Cyber Threat Intelligence (CTI) is the research, analysis, and modeling of cyber threats that turns raw data about attackers into contextualized, actionable knowledge. It describes a threat or an attack through indicators and context that both people and machines can understand, so security teams can anticipate, detect, and respond to attacks rather than simply react to them. CTI answers who is likely to attack you, how they operate, and what you can do about it before they succeed.
read more
DarkGate malware
DarkGate is a loader with remote access trojan capabilities developed in Delphi, which gained notoriety in late 2023 for its ability to operate secretly and evade detection by antivirus systems.
read more
Data Loss Prevention
Data Loss Prevention (DLP) is a set of strategies, processes, and technologies designed to stop sensitive information from being accessed, misused, or sent outside an organization without authorization. A DLP solution identifies and classifies confidential data such as customer records, financial information, and intellectual property (IP), monitors how that data is accessed, used, and shared across endpoints, networks, and cloud services, and enforces policies that block or flag risky actions. The goal is to prevent both accidental leaks, like an employee emailing a file to the wrong recipient, and deliberate data theft, whether by an outside attacker or a malicious insider, while supporting compliance with regulations such as the General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), and Payment Card Industry Data Security Standard (PCI DSS).
read more
DDoSia project
The DDoSia project is a Distributed Denial of Service attack toolkit developed and used by the pro-Russia hacktivist group NoName057(16) against countries critical of the Russian invasion of Ukraine.
read more
Doenerium
Doenerium is an infostealer malware designed to discreetly collect and steal confidential information from victims' computers, including logins, passwords, financial data, and other sensitive information.
read more
Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) is a cybersecurity technology that continuously monitors endpoint devices such as laptops, desktops, servers, and mobile devices to detect, investigate, and respond to advanced cyber threats, malicious behaviors, and fileless malware attacks that bypass traditional antivirus software.
read more
EPP
An endpoint protection platform (EPP) is an integrated suite of endpoint security technologies that work together on a device, such as a laptop, desktop, server, or mobile device, to detect and prevent security threats. Deployed through a lightweight agent and increasingly managed from the cloud, an EPP combines capabilities like next-generation antivirus (NGAV), a personal firewall, data encryption, data loss prevention (DLP), and device control into a single managed solution. Its primary purpose is prevention: stopping known and unknown threats such as file-based and fileless malware, ransomware, and malicious scripts before they can execute on the endpoint. In this sense, EPP is the modern evolution of traditional antivirus, moving beyond simple signature matching to add behavioral analysis, machine learning, and threat intelligence. It forms the foundational, preventive layer of endpoint security, and in most modern deployments it's paired with endpoint detection and response (EDR) for the threats that get through.
read more
EPT
Endpoint protection tools are security solutions designed to protect an organization's endpoints — such as laptops, desktops, servers, and mobile devices — from cyber threats.
read more
FakeBat
FakeBat is a loader malware in MSI format, sold as Malware-as-a-Service and known for its anti-detection features, widely distributed through malvertising and fake browser updates using the drive-by download technique.
read more
Firewall
A firewall is a network security device or software that monitors and filters incoming and outgoing network traffic, deciding whether to allow or block it based on a defined set of security rules. It acts as a barrier between a trusted internal network and untrusted external networks such as the internet, letting safe, legitimate traffic through while keeping unauthorized users and malicious data out. Firewalls can be delivered as hardware, software, or a cloud-based service, and they range from simple packet filters to advanced next-generation firewalls (NGFWs) that inspect traffic deeply and apply threat intelligence in real time.
read more
Frost & Sullivan Radar
The Frost & Sullivan Radar is a competitive intelligence tool that positions vendors across two dimensions, the Innovation & Growth Index and the Industry Footprint Index, to evaluate and compare companies within specific industries or market segments.
read more
Gartner Magic Quadrant
The Gartner® Magic Quadrant™ (MQ) is a visual research tool, backed by a proprietary methodology, that provides a graphical comparative positioning of technology and service providers within a specific market. Each vendor is plotted on a two-axis chart: Ability to Execute on the vertical axis and Completeness of Vision on the horizontal. That creates four quadrants: Leaders, Challengers, Visionaries, and Niche Players. Published by Gartner, a global research and advisory firm, a Magic Quadrant helps technology buyers quickly understand how the most relevant providers in a market compare, both on what they can deliver today and on how well their strategy aligns with where the market is heading. It's widely used in procurement and vendor evaluation, including across cybersecurity markets such as SIEM, endpoint protection, and email security.
read more
Generative AI
Generative AI is a type of artificial intelligence that creates new content — text, code, images, audio, or video — by learning patterns from existing data and generating new, similar data based on what it has learned.
read more
Hatvibe malware
Hatvibe is a custom loader written in VBScript, first identified in 2023 and used by the threat actor UAC-0063, suspected to be linked to APT28 based on victimology overlap.
read more
IAM
Identity and access management (IAM) is the framework of policies, processes, and technologies that makes sure the right identities have the right access to the right resources at the right time. It covers two linked jobs: confirming that a user, device, or service is who it claims to be, and granting only the level of access that identity is entitled to. An identity here is not only a person. It can be an employee, a contractor, a customer, an application, or a machine, and increasingly an AI agent, each needing its own controlled access. IAM matters for two reasons that pull in the same direction: security and productivity. It narrows the ways an attacker can misuse credentials, and it lets people reach the tools they need without friction. Because compromised identities are behind so many breaches, IAM has become a foundation of modern security rather than a back-office IT function. This page explains what IAM is, how it works, its core components, the standards behind it, and how it connects to related disciplines like privileged access management and zero trust.
read more
Intrusion Detection System (IDS)
An Intrusion Detection System (IDS) is a network security tool that monitors network traffic and system activity for known malicious activity, suspicious behavior, or security policy violations, and raises an alert when it finds something. Think of it as a watchdog: it watches, recognizes signs of an attack, and notifies security teams or a centralized tool like a Security Information and Event Management (SIEM) platform so they can investigate. Crucially, an IDS is a passive, listen-only system. It detects and reports, but it does not block threats on its own. That job belongs to an intrusion prevention system (IPS), which is why the two are so often deployed together.
read more
IoC
An indicator of compromise (IoC) is a piece of forensic evidence, an observable artifact on a network or system, that indicates with high confidence that a security breach has occurred or is underway. Common IoCs include file hashes of known malware, malicious IP addresses and domains, command-and-control (C2) infrastructure, suspicious registry keys, and anomalous login or traffic patterns. Think of IoCs as the digital fingerprints an attacker leaves behind. Security teams use them in two ways: reactively, to investigate a suspected incident, trace an attacker's path, and scope the damage; and proactively, by feeding known IoCs into detection tools so an alert fires automatically if the same artifact reappears. That second use is what makes threat intelligence feeds and IoC sharing so valuable. IoCs are a foundational element of cyber threat intelligence (CTI), detection engineering, and incident response.
read more
ISAC
An Information Sharing and Analysis Center (ISAC) is a nonprofit, member-driven organization that serves as a central, trusted hub for gathering, analyzing, and sharing cyber and physical threat information within a specific critical infrastructure sector, such as finance, healthcare, energy, or transportation. ISACs enable two-way information sharing between the private sector and government: they collect threat data from their members and from sources like CISA, enrich and analyze it, and disseminate actionable intelligence back to members through secure channels. The guiding principle is collective defense: a threat identified by one organization can protect an entire sector. First established in the United States in 1999 following Presidential Decision Directive 63 (PDD-63), ISACs now operate across dozens of sectors and increasingly around the world.
read more
Kinsing malware
Kinsing is a malware family, written in the Go programming language, that primarily targets Linux servers and cloud and container environments to mine cryptocurrency. It takes its name from the binary dropped on infected systems and is also known as H2Miner. First analyzed in early 2020, it behaves like a worm, spreading on its own by scanning for and compromising exposed or misconfigured systems, and it remains active and evolving today. Because its main goal is to hijack a server's processing power to mine cryptocurrency, it is a form of cryptojacking. The name Kinsing is used both for the malware itself and for the financially motivated activity that deploys it. This entry explains what Kinsing is, how it infects systems and what it does once inside, what it targets, how it has evolved, and how organizations detect and defend against it.
read more
Machine Learning
Machine Learning is a subset of artificial intelligence that provides systems the ability to automatically learn and improve from experience without being explicitly programmed, by accessing data and using it to learn for themselves.
read more
Mallox
Mallox (also known as TargetCompany, Fargo, and Tohnichi) is a ransomware strain and Ransomware-as-a-Service (RaaS) operation targeting Microsoft Windows systems, active since mid-2021. It's best known for a distinctive initial-access method: rather than relying primarily on phishing, Mallox operators hunt for unsecured, internet-facing Microsoft SQL (MS-SQL) servers and break in through brute-force and dictionary attacks against weak database credentials. Once inside, they deploy the Mallox payload, which encrypts files (commonly appending a .mallox extension) and follows the double extortion model: data is stolen before encryption and threatened with publication on a Tor leak site unless a ransom is paid. Operating as a RaaS with recruited affiliates, Mallox has claimed victims across many countries and industries, and remains an active, evolving threat.
read more
Malware analysis
Malware analysis is the process of examining malicious software to understand how it works, what it does, and how to detect and stop it. By dissecting a sample's code, structure, and behavior, analysts determine its purpose, capabilities, and potential impact, then extract the indicators of compromise (IOCs) needed to hunt for it and defend against it. The output turns an unknown suspicious file into actionable knowledge that feeds directly into incident response, threat intelligence, and detection engineering. Three core approaches cover most scenarios: static analysis (examining a file without running it), dynamic analysis (executing it safely in a sandbox to observe its behavior), and hybrid analysis (combining both). For the most advanced samples, reverse engineering goes deeper still.
read more
Managed detection and response (MDR)
Managed detection and response (MDR) is a cybersecurity service that combines security technology with human expertise to deliver 24/7 threat monitoring, detection, investigation, and response on an organization's behalf. Instead of only surfacing alerts, an MDR provider's analysts actively hunt for threats, separate real incidents from false positives, and guide or carry out containment across endpoints, networks, cloud, and identities. In effect, MDR gives an organization the outcomes of a mature security operations center (SOC) as an outsourced, subscription service. MDR has become one of the most common ways for organizations to close the gap between the volume of security alerts they generate and the in-house expertise available to act on them. This page explains what MDR is, how it works, what it typically includes, how it compares to related terms such as EDR, XDR, MSSP, and MXDR, and how to think about whether it fits your organization.
read more
Managed Security Operations Centers
A managed security operations center (managed SOC) is a Security Operations Center delivered as a subscription service by a third-party provider rather than built and staffed entirely in-house. The provider supplies the people, processes, and technology needed to monitor an organization's IT environment around the clock, detect threats, and drive incident response. It's commonly marketed under the labels SOC as a Service (SOCaaS) or outsourced SOC, and it often forms the operational backbone of a broader managed detection and response (MDR) engagement. For most security leaders, the real question isn't whether a SOC is necessary but how to resource one. Building continuous coverage internally demands scarce analysts, expensive tooling, and a level of operational maturity that takes years to reach. A managed SOC compresses that timeline. This page explains what it delivers, how delivery models differ, how it compares to adjacent services like MSSP and MDR, and how to choose a provider.
read more
MDAV
Microsoft Defender Antivirus is a built-in antivirus component of the Windows operating system that provides protection against malware and other threats.
read more
MFA
Multi-factor authentication (MFA) is an authentication method that requires a user to present two or more independent forms of proof before being granted access to an account, application, or system. Instead of relying on a password alone, MFA combines factors from different categories, so that stealing one, a password, does not hand an attacker the keys. It is a core part of identity and access management (IAM) and one of the most effective single controls against account takeover. The logic is simple: a password can be guessed, phished, or reused, but an attacker is far less likely to also hold the user's phone or fingerprint. Microsoft has reported that MFA blocks the large majority of automated account-compromise attempts. That said, MFA is not a finish line. Attackers have adapted, and the gap between weak and strong MFA now matters as much as whether MFA is turned on at all. This page covers what MFA is, the factor types, common methods, how attackers bypass weaker forms, and why phishing-resistant MFA has become the standard to aim for.
read more
MITRE ATT&CK framework
The MITRE ATT&CK framework is a globally accessible, continuously updated knowledge base of real-world adversary tactics, techniques, and procedures (TTPs), based on observations of how attackers actually behave during intrusions. ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge. Created and maintained by MITRE, a US non-profit, the framework catalogs what attackers do at each stage of the attack lifecycle and gives defenders a common language to describe, detect, and respond to threats. Rather than chasing easily changed indicators like IP addresses or file hashes, ATT&CK focuses on durable behaviors, which is what makes it a cornerstone of modern threat detection, threat hunting, and security operations.
read more
MSSP
A managed security service provider (MSSP) is a third-party company that delivers outsourced cybersecurity monitoring, detection, and management for an organization's IT infrastructure, networks, systems, and applications, typically on a subscription basis. Operating from one or more security operations centers (SOCs), an MSSP provides around-the-clock visibility into a client's environment so threats are detected and addressed as they emerge. Core services usually include 24/7 security monitoring and alerting, managed firewalls and intrusion detection and prevention, SIEM management, vulnerability management, and compliance support. Organizations turn to MSSPs to close a gap they can't fill internally: maintaining continuous monitoring and specialized security expertise is expensive and hard to staff, especially amid a persistent cybersecurity skills shortage. By outsourcing all or part of their security operations, organizations gain enterprise-grade protection without building and maintaining a full in-house SOC.
read more
MTTD
Mean time to detect (MTTD) is a security operations metric that measures the average time between the moment malicious or anomalous activity begins in an environment and the moment the security team detects it. It's one of the most widely tracked KPIs for a Security Operations Center (SOC), because it quantifies how long a threat can operate undetected: the attacker's dwell window. A lower MTTD means threats are spotted faster, shrinking the time an adversary has to escalate privileges, move laterally, or exfiltrate data. A higher MTTD signals blind spots in visibility, noisy detections, or overwhelmed analysts. MTTD is almost always read alongside its response-side counterpart, mean time to respond (MTTR). Although the concept originated in IT reliability engineering, where it tracked how quickly teams noticed faults and outages, MTTD has become a core security metric. This page explains what it measures, how to calculate it, why the definition is trickier than it looks, how it relates to MTTR and the other SOC timing metrics, and the practical levers that bring it down.
read more
MTTR
Mean time to repair (MTTR) is a key performance indicator that measures the average time it takes to repair a failed system, component, or service and return it to full operation. It's calculated by dividing the total repair time over a period by the number of repairs completed in that same period, and it's used across IT operations, security, and maintenance to gauge how efficiently teams recover from failures. A lower MTTR means faster recovery, less downtime, and higher availability. Because the "R" in MTTR can stand for repair, recovery, respond, or resolve, the single most important step before tracking it is agreeing on which one you mean. Each measures a different slice of the incident lifecycle, and confusing them produces numbers that look precise but drive the wrong decisions. This page leads with mean time to repair as the primary definition, explains the formula with a worked example, disambiguates the four versions of MTTR that are so often confused, shows how MTTR relates to MTBF and availability, and covers the practical levers that bring it down, including in a security operations context.
read more
MuddyWater
MuddyWater is an Iranian state-sponsored cyber espionage group, assessed to operate as part of Iran's Ministry of Intelligence and Security (MOIS). Active since at least 2017, it conducts intelligence-gathering intrusions against government and private organizations, primarily in the Middle East but also across Asia, Africa, Europe, and North America. It is tracked under many names, including MERCURY, Seedworm, Static Kitten, Earth Vetala, TEMP.Zagros, and, in Microsoft's newer taxonomy, Mango Sandstorm. MITRE ATT&CK catalogs it as G0069. MuddyWater is known for a practical, adaptable style of operation: heavy use of PowerShell, living-off-the-land techniques, and, in particular, the abuse of legitimate remote monitoring and management (RMM) software to control compromised systems. This page covers the group's attribution and aliases, who it targets, how it operates, how its tooling has evolved, and how organizations defend against it, drawing in part on first-party research by Sekoia's Threat Detection & Research (TDR) team.
read more
NDR
Network detection and response (NDR) is a cybersecurity technology that monitors network traffic to detect, investigate, and respond to threats that other tools miss. Instead of matching known signatures, it applies behavioral analytics and machine learning to the traffic itself, spotting the patterns an intrusion leaves behind. That focus on behavior lets it catch threats with no prior signature, from lateral movement inside the network to command-and-control channels hidden in encrypted traffic. Gartner formally defined the category in 2020 and published its first Magic Quadrant for NDR in 2025. NDR earns its place because attackers who slip past the endpoint and the perimeter still have to use the network, and every move they make there leaves a trace. This page covers what NDR is, how it works, the traffic it watches, how it compares to endpoint and log-based tools, and where it fits in a modern security operations center (SOC).
read more
Open XDR architecture
Open XDR is a vendor-agnostic approach to extended detection and response (XDR) that unifies threat detection, investigation, and response across an organization's entire security stack, without requiring it to standardize on a single vendor's tools. Also called hybrid XDR, it acts as an analytics and orchestration layer sitting on top of existing best-of-breed tools: endpoint detection and response (EDR), network detection and response (NDR), cloud, identity, email, SIEM, SOAR. It ingests their telemetry through open APIs and integrations, normalizes it into a common data model, correlates it with AI and threat intelligence to surface high-fidelity incidents, and drives automated response back into the source tools. The defining contrast is with native XDR, also called closed XDR: an all-in-one platform from a single vendor. Open XDR's core promise is unified detection and response while preserving the security investments organizations already trust, and avoiding vendor lock-in.
read more
PAM in cybersecurity
Privileged access management (PAM) is a cybersecurity strategy, and the set of technologies that supports it, for controlling, monitoring, and auditing access to an organization's most critical systems by privileged users. A privileged user is anyone whose account can change how systems work or reach sensitive data: system and network administrators, database administrators, cloud administrators, and increasingly the service accounts and machine identities that run automated processes. PAM exists because these accounts are the most valuable target in an environment. Compromise one, and an attacker inherits its power. PAM works by granting only the access needed for a specific task, for as long as the task takes, and by recording what happens during privileged sessions so that misuse can be spotted and investigated. This page covers what PAM does, how its components fit together, how it differs from identity and access management (IAM) and from multi-factor authentication (MFA), the practices that make it effective, and where the discipline is heading.
read more
PCI-DSS
The Payment Card Industry Data Security Standard is an information security standard for organizations that handle credit card data, with compliant organizations recognized as PCI certified.
read more
Pikabot
Pikabot is a backdoor-type malware that appeared in early 2023, whose modus operandi resembles the well-known QBot malware.
read more
PlugX
PlugX is a modular remote access trojan (RAT) that gives an attacker covert, long-term control over a compromised Windows system. Active since around 2008, it is one of the most enduring tools in China-nexus cyber espionage and has been used by many different threat groups. It is best known for a plugin-based design that lets operators load only the capabilities they need, and for using DLL side-loading, in which a legitimate program is tricked into loading the malware, to install and hide itself. PlugX is also tracked under other names, including Korplug, SOGU, and Kaba. As a RAT, PlugX is the tool an attacker uses after breaking in, to maintain access, explore a network, and steal data, rather than the method of initial compromise. This entry explains what PlugX is, how it works, what it can do, who uses it, how it has evolved, and how organizations detect and defend against it, drawing in part on first-party research by Sekoia's Threat Detection & Research (TDR) team, which sinkholed a global PlugX botnet.
read more
Predator spyware
Predator is a commercial mobile spyware product developed by Cytrox and sold under the Intellexa banner, used to covertly surveil iOS and Android devices. Marketed almost exclusively to government and intelligence customers, Predator has been used to target journalists, politicians, academics, and activists, and it is widely regarded as one of the most capable mercenary spyware tools alongside NSO Group's Pegasus. Once installed, it can record calls and audio, read messages from encrypted apps, and exfiltrate a wide range of personal data. Because it is sometimes called "Predator malware," the two terms refer to the same Intellexa product. Predator has been documented extensively by researchers at Google's Threat Analysis Group, Citizen Lab, Cisco Talos, and Amnesty International, and it has drawn US government sanctions. This page explains what Predator is, who builds it, how it infects devices, who it has targeted, the regulatory response, and how at-risk users and organizations can reduce their exposure. It also clarifies one important naming point: Predator spyware is not the same as "Predator the Thief," an unrelated Windows infostealer.
read more
RaaS
Ransomware as a service (RaaS) is a cybercrime business model in which ransomware developers, known as operators, build and maintain ransomware and lease it to other criminals, known as affiliates, who carry out the actual attacks in exchange for a share of the proceeds. It's a criminal mirror of the legitimate software-as-a-service (SaaS) model: instead of every attacker writing their own malware, operators handle the hard technical work, developing the ransomware, running the infrastructure, hosting payment portals and leak sites, while affiliates focus on breaking into targets and deploying the payload. The result is a professionalized underground economy, complete with subscriptions, affiliate portals, dashboards, user reviews, and 24/7 support. By separating development from deployment, RaaS dramatically lowers the technical barrier to entry, letting people with little or no coding skill launch sophisticated ransomware attacks. That division of labor is a major reason ransomware has exploded in scale and frequency.
read more
RDDoS
Ransom Distributed Denial of Service is a type of cyberattack where criminals threaten to carry out a Distributed Denial of Service attack against a target unless a ransom is paid.
read more
Residential proxies
A residential proxy is an intermediary service that routes a user's internet traffic through an IP address assigned by a consumer internet service provider (ISP) to a real household device. Because the traffic appears to come from an ordinary home connection rather than a datacenter, residential proxies are highly effective at looking like a normal user. That property makes them genuinely useful for legitimate tasks such as ad verification and price monitoring, but it also makes them a favored tool for attackers who want to hide automation, bypass geographic and reputation controls, and blend malicious activity into everyday traffic. This dual-use nature is exactly why residential proxies matter to security and fraud teams. This page explains what residential proxies are, how they work, how their IPs are sourced, what that raises in terms of consent, how they differ from datacenter proxies, mobile proxies, and VPNs, why they're so hard to detect, and how defenders can approach them.
read more
Roaming Mantis
Roaming Mantis, also known as Shaoye, is a cybercriminal group that primarily targets mobile devices using rogue DNS settings and DNS hijacking to redirect victims to malicious websites or deliver malware.
read more
SaaS SIEM
A SaaS SIEM is a cloud-hosted version of traditional SIEM technology delivered as Software-as-a-Service, managed and operated by a third-party provider rather than running on the organization's own infrastructure.
read more
Scattered Spider
Scattered Spider is a financially motivated cybercriminal group, active since at least 2022, that has become one of the most disruptive threat actors targeting Western enterprises. It's best known for social engineering rather than technical exploits: its operators phone corporate IT help desks, impersonate employees, and talk their way past passwords and multi-factor authentication (MFA) to gain access, then escalate to data theft, extortion, and ransomware. Tracked under many names, including UNC3944, Muddled Libra, Octo Tempest, 0ktapus, Scatter Swine, and Star Fraud, the group is a loose, decentralized network of mostly young, native English-speaking members operating from the US, UK, and Europe, loosely part of a broader online community known as The Com. High-profile targets include MGM Resorts, Caesars Entertainment, Twilio, Transport for London, and major UK retailers such as Marks & Spencer.
read more
Security Information and Event Management (SIEM)
Security Information and Event Management (SIEM) is a security solution that collects, aggregates, and correlates log and event data from across an organization's entire IT infrastructure to provide real-time analysis of security alerts. By pulling data from servers, endpoints, applications, network devices, and cloud services into one central platform, a SIEM gives security teams a unified view of their security posture so they can detect, investigate, and respond to threats before those threats disrupt the business. It also automates much of the reporting needed to prove regulatory compliance.
read more
Security Operations Center (SOC)
A Security Operations Center (SOC) is a centralized team and function responsible for continuously monitoring an organization's IT environment to detect, analyze, and respond to cybersecurity threats. Often pronounced "sock" and sometimes called an Information Security Operations Center (ISOC), a SOC unifies the people, processes, and technology used to defend an organization, operating around the clock so that threats are caught and contained quickly, no matter when they occur. Its mission is twofold: handle security incidents in real time, and continuously improve the organization's security posture over the long run.
read more
Security Orchestration, Automation and Response (SOAR)
Security Orchestration, Automation and Response (SOAR) is a software solution that lets security teams integrate and coordinate separate security tools, automate repetitive tasks, and streamline incident and threat response through a single platform. Rather than having analysts manually pivot between disconnected tools, SOAR connects them into repeatable workflows called playbooks, automating the low-level work and giving the Security Operations Center (SOC) one place to manage alerts. The result is faster, more consistent response and a lower mean time to detect (MTTD) and mean time to respond (MTTR).
read more
Security Service Delivery Platform
A Security Service Delivery Platform is an integrated cybersecurity infrastructure that enables Managed Security Service Providers and security teams to deliver, manage, and orchestrate a wide range of security services from a unified platform.
read more
SEO poisoning
SEO poisoning, also called search poisoning, is a technique in which attackers manipulate search-engine rankings so that malicious websites appear high in the results for popular search terms. When someone searches for a common query and clicks a top result, they land on a site built to look legitimate but designed to deliver malware or steal information. It is a form of social engineering that turns the user's own trust in search results against them, and it is now a common way for attackers to gain an initial foothold inside an organization. What makes SEO poisoning effective is that the target comes looking. Unlike a phishing email that arrives uninvited, a poisoned search result meets a user who is actively searching and inclined to trust what ranks near the top. This page explains how SEO poisoning works, the stages of a typical attack, the malware it delivers, why it succeeds, and how organizations detect and defend against it.
read more
Shadow IT
Shadow IT is the use of software, hardware, cloud services, or other technology inside an organization without the knowledge or approval of the IT department. It usually appears in one of two ways: an employee adopts an unapproved tool to handle work data, or uses an approved tool in an unauthorized way, such as through a personal account. The intent is rarely malicious. People reach for whatever helps them get the job done. But because IT has no visibility into these tools, it cannot secure, monitor, or maintain them, and that blind spot is where the risk lives. Shadow IT has grown with the shift to cloud and software-as-a-service (SaaS), where a new tool is a sign-up away, and it has accelerated again with generative AI. This page covers what shadow IT is, why it happens, the risks and the genuine upsides, common examples including the fast-rising category of shadow AI, and how organizations bring it back under control.
read more
SOC as a Service (SOCaaS)
SOC as a Service (SOCaaS) is a subscription-based model that delivers the capabilities of a full Security Operations Center (SOC) through the cloud, run by a third-party provider instead of an in-house team. The provider supplies the people, the tools, and the processes needed for round-the-clock threat monitoring, detection, investigation, and response across your networks, endpoints, cloud, and applications. You get the protection of a fully staffed SOC without having to build, equip, or staff one yourself.
read more
SOC Best Practices: Strengthening Your Cybersecurity Posture
SOC best practices are the disciplined processes, continuous improvement habits, and culture of vigilance that an effective Security Operations Center must adopt to strengthen an organization's cybersecurity posture.
read more
SSO
Single sign-on (SSO) is an authentication method that lets users securely access multiple applications and websites with one set of login credentials. Instead of signing in separately to each app, a user authenticates once through a trusted identity provider, which then grants access to every connected system for the duration of the session. SSO removes the need to remember and re-enter a different password for each service, and it gives IT teams a single, central place to manage and secure access. It is a core building block of identity and access management (IAM), and it works best when paired with multi-factor authentication (MFA).
read more
STIX
STIX (Structured Threat Information Expression) is an open, standardized language for describing cyber threat intelligence (CTI) in a consistent, structured, and machine-readable format. It gives security teams and systems a common vocabulary for representing threats: indicators, malware, threat actors, attack patterns, and the relationships between them, so that intelligence can be shared, stored, and analyzed the same way across different organizations and tools. STIX defines the "what" of threat intelligence. Its companion protocol, TAXII (Trusted Automated Exchange of Intelligence Information), defines the "how" of transporting it. Because STIX is machine-readable, threat data expressed in it can flow automatically between SIEMs, SOAR platforms, EDR solutions, threat intelligence platforms, and sharing communities, without manual reformatting.
read more
Tactics, Techniques and Procedures (TTPs)
Tactics, Techniques and Procedures (TTPs) are the behavioral fingerprint of a threat actor, and the structured way security teams describe how adversaries plan and execute cyber attacks. Tactics are the high-level goals (the "why"), techniques are the methods used to achieve them (the "how"), and procedures are the specific, step-by-step implementations (the "how exactly"). Unlike Indicators of Compromise (IoCs), which describe artifacts an attacker leaves behind, TTPs describe behavior, making them far more durable intelligence for detecting and attributing threats.
read more
TAXII
TAXII (Trusted Automated Exchange of Intelligence Information) is an open, application-layer protocol for exchanging cyber threat intelligence (CTI) over HTTPS. In practical terms, TAXII is the transport: it defines a RESTful API and requirements for clients and servers so that organizations can send, receive, request, and manage threat intelligence in an automated, standardized way. TAXII is almost always mentioned alongside STIX, but the two do different jobs. STIX is the language that structures the intelligence (the "what"); TAXII is the protocol that moves it between systems (the "how"). TAXII was designed specifically to carry STIX, and support for exchanging STIX 2.1 is mandatory to implement, but it can also transport other formats.
read more
Top Security Operation Center Tools: Enhancing Threat Detection and Response
A modern SOC relies on a technology stack of essential tools, including SIEM, EDR, XDR, SOAR, and NDR, that work together to detect, investigate, and respond to threats efficiently.
read more
Traffer
Traffers are underground groups that distribute infostealers on compromised computers and are paid commissions by cybercriminals in exchange for the stolen credentials.
read more
Turla
Turla is a Russian nation-state cyber espionage group attributed to Russia's Federal Security Service (FSB). Active since at least 2004, with some assessments linking it to intrusions going back to the late 1990s, it has compromised organizations in more than 50 countries and concentrated consistently on foreign ministries, embassies, defense organizations, military bodies, research institutions, and pharmaceutical companies. Turla is one of the longest-running and most technically capable espionage groups on record, known for building its own malware rather than relying on commodity tools, and for tradecraft that other actors rarely attempt. The group is tracked under a long list of names, most commonly Snake, Uroburos, Waterbug, and Venomous Bear, and MITRE ATT&CK catalogs it as G0010. This page covers Turla's aliases and attribution, who it targets, how it operates, what makes its tradecraft distinctive, and how organizations defend against it, drawing in part on first-party research by Sekoia's Threat Detection & Research (TDR) team.
read more
Tycoon 2FA phishing
Tycoon 2FA is a Phishing-as-a-Service kit designed to conduct adversary-in-the-middle attacks, capable of bypassing multi-factor authentication, particularly time-based one-time passwords.
read more
Vice Society
Vice Society is a ransomware group that emerged in 2021, known for its double extortion tactic and for targeting the education, healthcare, and government sectors.
read more
VPN
A virtual private network (VPN) is a technology that creates a secure, encrypted connection over a less secure network, typically the public internet. It works by encrypting a device's traffic and routing it through an encrypted tunnel to a VPN server or gateway, which masks the user's real IP address and makes the data unreadable to anyone who intercepts it. Organizations use VPNs to give remote employees protected access to corporate resources and to link sites together over the internet; individuals use them to protect their privacy on public Wi-Fi and keep their online activity private. The name captures the concept well. Virtual, because no dedicated physical line is involved. Private, because encryption keeps the traffic confidential. Network, because the device and the VPN server work together to maintain the connection.
read more
WebDAV
WebDAV (Web Distributed Authoring and Versioning) is an extension of the HTTP protocol that lets users read and write files on a remote web server, not just download them. Standard HTTP treats a web server as a read-only source of content. WebDAV adds the ability to create, edit, move, copy, delete, and lock files remotely, effectively turning a web server into a shared file store that can be accessed over the same HTTP or HTTPS connection a browser uses. It is defined by RFC 4918, which replaced the original RFC 2518. WebDAV has been part of the web for decades and underpins familiar tools, including the calendar and contact protocols CalDAV and CardDAV, which are built on top of it. This page explains how WebDAV works, what it is used for, how it compares with alternatives such as FTP, and, because this is a security glossary, how attackers have learned to abuse a legitimate protocol to deliver malware.
read more
XDR (Extended Detection and Response)
XDR (Extended Detection and Response) is a unified security technology that collects and automatically correlates data across multiple layers, including endpoints, networks, cloud workloads, email, and identities, into a single detection and response platform. Sometimes called cross-layered detection and response, XDR evolved from Endpoint Detection and Response (EDR) to give security teams the visibility, analytics, and automation to detect, investigate, and respond to threats that move across an environment, rather than analyzing each layer in isolation. The result is faster detection, less alert fatigue, and a stronger overall security posture.
read more
XDR integration with existing solutions
XDR integration with existing solutions is the process of connecting an Extended Detection and Response platform with a company's current security tools, such as firewalls, SIEM, and EDR, to strengthen cybersecurity without starting from scratch.
read more
XDR vs EDR vs MDR
XDR, EDR, and MDR are three detection and response approaches that are often compared: EDR focuses on endpoints, XDR extends detection across multiple layers into a unified platform, and MDR is a managed service combining technology with human expertise.
read more
XDR vs. SIEM: Which Solution Should You Choose?
The difference between XDR and SIEM lies in their approach: a SIEM collects and correlates logs across the IT environment mainly for monitoring and compliance, while XDR integrates multiple security products into a unified system focused on threat detection and response.
read more
YARA Rule
YARA rules are human-readable pattern-matching descriptions that let security analysts identify and classify malware based on textual or binary patterns. YARA itself is an open-source tool, often called "the pattern-matching Swiss army knife for malware researchers," and a YARA rule is a single description written in its language. Each rule pairs a set of patterns (strings, hex byte sequences, or regular expressions) with a Boolean condition that decides when a file or process is a match. The power of the approach is that it captures the durable "DNA" of a malware family, code fragments, configuration strings, and structural patterns, rather than a single file hash. That means one well-written rule can detect many variants of a threat, surviving the mutations that defeat simple hash matching. YARA is widely used by malware researchers, threat hunters, detection engineers, and incident responders across sandboxes, antivirus engines, threat intelligence platforms, and SIEMs.
read more
Zero-Day vulnerability
A zero-day vulnerability is a security flaw in software, hardware, or firmware that's unknown to the vendor or anyone capable of fixing it. No patch exists. The name captures the situation precisely: developers have had zero days to address the flaw before it can be exploited. Because there's no official fix and traditional signature-based defenses have nothing to match against, a zero-day leaves every user of the affected system exposed during the gap between first exploitation and patch release. Security professionals call this the window of vulnerability. Zero-day vulnerabilities are among the most dangerous threats in cybersecurity, prized by cybercriminals, nation-state actors, and advanced persistent threat (APT) groups precisely because defenders can't prepare for a weakness no one knows about yet.
read more
Zero Trust
Zero Trust Architecture (ZTA) is a cybersecurity architecture built on one foundational principle: never trust, always verify. Where traditional security models treat everything inside the network perimeter as trustworthy, a zero trust architecture treats every user, device, application, and connection as untrusted by default, whether it sits inside or outside the corporate network. Every access request is authenticated, authorized, and continuously validated based on identity, device health, and context, and access is granted with the least privilege necessary. The goal is to shrink the attack surface, prevent lateral movement, and contain breaches before they spread across a distributed environment of cloud services, remote workers, and connected devices.
read more
Speak to a Sekoia expert
Your security challenges deserve expert answers. Get a tailored demo and discover how Sekoia helps your team detect and respond to threats faster.

get a demo

Act from clarity
Stay ahead of cyber threats

Get the latest insights on threat intelligence, SOC best practices and Sekoia product updates delivered straight to your inbox.

SUBSCRIBE

PLATFORM

AI SOC platformSekoia DefendSekoia IntelligenceSekoia RevealSekoia ElevateIntegrations

use cases

SIEM replacementStack integrationContinuous threat detectionAutomated incidence responseAlert fatigue relief

Verticals

HealthcareEnergy & UtilitiesManufacturingTechnologyGovernmentMSSP

Company

About SekoiaAbout TDR TeamNewsroomOur customersJoin usPrivacy & security

Partners

Our business partnersWhy become a partnerPartner portalTraining coursesTechnology partnersAssociationsMarketplaces

Resources

BlogCyberglossaryWebinarsCase studiesSolution briefsReportsDocumentation
© 2026 Sekoia. All rights reserved.
Privacy PolicyLegal noticeCookie policyTrust centerIndex egapro
en
en
fr