How real-world IR teams work
SOC
Security Operations Center. The team (often 24/7) that watches alerts and runs incident response. Tier-1 analysts triage, Tier-2 dig deeper, Tier-3 lead the toughest investigations.
SIEM
Security Information and Event Management. Collects logs from many sources, correlates events, and raises alerts on patterns.
Log sources
Firewalls, IDS/IPS, servers, endpoints, applications, DNS, identity systems. Centralized into the SIEM for correlation.
IoC
Indicator of Compromise. A specific artifact (file hash, IP address, domain, registry key) that points to a breach having happened.
Playbook
A pre-written, step-by-step response for a specific incident type. Reduces the number of decisions to make under pressure.
Chain of custody
A documented trail showing who handled the evidence, when, and how. Required for evidence to hold up later.
Tabletop exercise
A walkthrough drill where the team talks through how they would respond to a simulated incident. Reveals gaps before a real event.