MDR Terms to Know
Cut through the industry acronyms and complex jargon.
Explore our interactive glossary of essential MDR terms and core definitions.
That term wasn't found on our page.
Accessible API
A set of rules and protocols that allow different software systems to communicate and share data securely which are accessible by external developers with minimal restrictions.
Active Mitigation
Dynamic, real-time actions taken to contain, neutralize, or minimize the impact of cyber threat or breach. Unlike passive defenses, it actively disrupts attackers’ actions, isolates compromised systems, and reduces the severity of a cyberattack as it unfolds.
Agentic AI Architecture
One that shapes the virtual space and workflow structure to automate AI models within and agentic AI system.
AI Agent
Autonomous software program powered by large language models (LLMs) that can understand goals, reason, make decisions, and take independent actions to complete tasks without constant human oversight.
AI-Based Threat Prevention
The use of machine learning algorithms and behavioral analytics to autonomously detect, anticipate, and block cyberattacks in real time.
Alert Fatigue
State of mental and operational exhaustion caused by an overwhelming number of alerts – many of which are low priority, false positives or otherwise non-actionable.
Alert Triage
Systematic process of validating, prioritizing, and assigning incoming security notifications. Its goal is to act as a crucial decision-making layer separating harmless background noise from genuine, high-risk threats, ensuring security teams focus their efforts on what matters most.
Autonomous Threat Hunts
The use of artificial intelligence and machine learning to proactively search for hidden, advanced cyber threats without human intervention. It continuously analyzes network data and refines hypotheses to detect stealthy attacks that slip past standard automated defenses, dramatically reducing attacker dwell time.
Business Resilience
The ability of an organization to anticipate, withstand, recover from, and adapt to cyber threats or IT incidents.
Bring Your Own License (BYOL)
Software licensing model that allows you to use your existing, previously purchased software licenses on a new cloud platform or third-party services.
CVE Mapping
Process of correlating detected software vulnerabilities, system weaknesses, or active security threats with their standardized CVE (Common Vulnerabilities and Exposures) identifier. This translates raw technical alerts into actionable, recognizable security risks.
Detection Agents
Autonomous software programs or AI systems designed to continuously monitor networks, devices, and user behavior to identify and respond to threats in real time.
Detection Engineering
Specialized cybersecurity process of designing, building, and continuously refining the rules and logic used to identify malicious activity in real time.
Domain Specific Language Model (DSLM)
Specialized AI model trained exclusively on the terminology, logic, data patterns, and regulatory frameworks unique to cybersecurity operations.
Endpoint Detection and Response (EDR)
Cybersecurity solution that continuously monitors end-user devices (laptops, smartphones, servers, etc.) to detect suspicious behavior, block malicious activity, and help security teams investigate and remediate threats.
Endpoint Security
Protects an organization’s endpoint devices and users against cyberattacks and malicious threats. It acts as a digital barrier, preventing cybercriminals from using these devices as entry points to infiltrate corporate networks and access sensitive data.
Faster Investigation
Reducing the time between a system anomaly and the confirmation of what it means, known as “dwell time”.
Granular Filtration
The practice of evaluating, classifying, and controlling digital traffic, data, or access with extreme precision. It applies surgical, highly specific criteria to filter out threats and protect sensitive assets.
Human-in-the-Loop (HITL)
Model where human insight and oversight are integrated into an automatic or Artificial Intelligence process.
Intel Feeds
A continuous, automated data stream providing real-time information on emerging or known cyber threats. It delivers actionable data like malicious IP addresses, phishing URLs, and malware signatures, allowing security systems to proactively block attacks before they cause damage.
Investigation Agents
An advanced, autonomous AI software designed to dissect security threats.
Indicator of Compromise (IoC)
It refers to digital forensic evidence such as suspicious IP addresses, malware file hashes, or unusual network traffic that suggests a computer network or system has been breached or subjected to malicious activity.
Knowledge-Graph Augmented Generation (KGAG)
An advanced AI framework that combines Large Language Models (LLMs) with Cybersecurity Knowledge Graphs (KGs).
Managed Cloud SIEM
Cybersecurity service where a third-party provider hosts, configures and monitors a cloud-native Security Information and Event Management (SIEM) platform for your organization.
Managed Detection and Response (MDR)
An outsourced cybersecurity service that combines artificial intelligence with human security experts to continuously monitor networks, detect threats, and rapidly neutralize attacks before they cause damage.
Mean Time To Detect (MTTD)
Critical cybersecurity KPI measuring the average time it takes an organization to identify a security breach from the moment an attack begins.
Mean Time To Identify (MTTI)
Critical metric that measures the average time it takes for a security team to detect or become aware of a security breach or anomalous event after it has initially occurred.
MITRE
A not-for-profit organization that operates federally funded research centers. It is famous for creating and maintaining globally recognized cybersecurity frameworks and standards used to model attacker behavior and secure systems.
Network Detection and Response (NDR)
A cybersecurity solution that continuously monitors network traffic to identify suspicious or abnormal behaviors. Instead of solely relying on known threat signatures, it uses AI, machine learning, and behavioral analytics to spot evasive threats like insider attacks, lateral movement, and ransomware.
Noise Reduction
The process of filtering out harmless, repetitive, or irrelevant system events to identify actual threats. It improves the signal-to-noise ratio in Security Operations Centers (SOCs).
Open Search SIEM
Using the OpenSearch search and analytics platform often paired with the built-in Security Analytics plugin- as a lightweight, highly scalable Security Information and Event Management (SIEM) solution. It aggregates, correlates, and analyzes security logs to detect and respond to cyber threats.
Response Agents
Autonomous software systems that detect, investigate, and remediate cyber threats. These agents use multi-step reasoning to independently execute complex containment actions such as isolating hosts, blocking IPs, or revoking access.
Retrieval-Augmented Generation (RAG)
AI technique that combines intelligence of Large Language Models (LLMs) with an organization’s specific, private data.
Security Data Lake
A centralized repository that collects, stores, and analyzes massive volumes of cybersecurity data from across an organization. It retains raw, unstructured data (like firewall logs and endpoint telemetry) affordably, applying structure only when queried.
Security Information and Event Management (SIEM)
Core cybersecurity solution that aggregates and analyzes log and event data form across an entire IT infrastructure. It acts as a central hub, enabling security teams to detect threats, monitor activity in real time, and manage compliance.
Security Operations Center (SOC)
It acts as a centralized “command center” or “nerve center” for an organization’s IT infrastructure. Staffed by cybersecurity professionals, it monitors, detects, analyzes, and responds to cyber threats and security incidents 24/7.
Security Playbook
Structured, step-by-step guide that outlines exactly how security teams should detect, respond to, and recover from specific threats. It provides actionable instructions, decision trees, and workflows designed to eliminate guesswork, speed up incident response, and reduce human error during a crisis.
SOC Automation
The use of AI, machine learning, and predefined workflows to handle routine, repetitive security tasks. It replaces manual alert triage and investigations, enabling human analysts to focus on complex, high-value threats and proactive threat hunting.
Threat Intel Exposure Assessment
Proactive cybersecurity process that aligns external threat intelligence with your internal digital footprint to identify, quantify, and prioritize security risks.
Unified MDR
An outsourced cybersecurity service that provides continuous, 24/7 monitoring, threat detection, and incident response across an organization’s entire digital footprint. It functions as a fully outsourced Security Operations Center (SOC), combining advanced automation with expert human analysis.
User and Entity Behavior Analytics (UEBA)
A cybersecurity approach that uses machine learning and advanced analytics to detect cyberthreats by monitoring the “normal” activity of users and machines and flagging any suspicious deviations.