Incident Detection

Noun · Security & Infosec

Definitions

  1. The discovery of signs that a real security incident may be occurring or has occurred, through alerts, user reports, anomaly analysis, or other sources. Effective incident detection depends on telemetry quality, tuned rules, and humans who can separate noise from real compromise.

    In plain English: The process of noticing that a real security incident may be happening.

    Example: "The company improved incident detection by adding cloud audit logs and endpoint telemetry to the SOC pipeline."

Related Terms