AI SOC glossary
Terms that come up constantly in security operations work, defined plainly. For how they fit together in a working system, see the AI SOC platform overview.
- Agentic SOC
- A security operations center (SOC) where AI agents carry work through to completion across detection, triage, investigation, and response, with analysts supervising rather than executing each step.
- AI SOC
- The broader term for any SOC using artificial intelligence in its workflow. Coverage ranges from a chat assistant to full agentic operation, so the label alone says very little about capability.
- Alert triage
- Deciding whether an alert represents real malicious activity. Historically the largest consumer of analyst time and the main source of burnout in the role. Exaforce customers report a 90% reduction in false positives.
- Exabots
- Exaforce's task-specific AI agents. Exabot Detect, Exabot Triage, Exabot Investigate, Exabot Respond, and Exabot Hunt each handle one part of the lifecycle, under human oversight.
- MDR
- Managed detection and response. A service where an external team monitors and responds on the customer's behalf. Exaforce MDR runs the same Exabots the platform uses, 24/7. More on exaforce.com
- MTTI
- Mean time to investigate. How long it takes to reach a verdict on an alert. Accton took theirs from three hours to ten minutes. Accton case study
- MTTR
- Mean time to respond. How long from detection to containment. Forcepoint holds 14 minutes on P0 incidents. Forcepoint case study
- Multi-Model AI
- Exaforce's three-model engine. The Semantic Data Model resolves entities and relationships, the Behavioral Model learns normal activity, and the Knowledge Model reasons across both. More on exaforce.com
- Semantic context
- Structured meaning attached to events at ingest, so AI reasons over an understood environment rather than raw log text. The reason verdicts stay consistent between runs.
- SIEM
- Security information and event management. The traditional log aggregation and correlation layer. Exaforce replaces it and is not one.
- SOAR playbooks
- Deterministic automation scripts for security operations. They apply rigid logic to non-deterministic processes, which is why they break whenever an API changes.
- Threat hunting
- Proactively searching for adversary activity that no alert fired on. Exaforce calls natural-language threat hunting vibe hunting.
- UEBA
- User and entity behavior analytics. Baselining normal behavior to spot deviation from it. Exaforce's Behavioral Model does this across both human and machine identities.