Terms that come up constantly in security operations work, defined plainly. For how they fit together in a working system, see the AI SOC platform overview.

Agentic SOC
A security operations center (SOC) where AI agents carry work through to completion across detection, triage, investigation, and response, with analysts supervising rather than executing each step.
AI SOC
The broader term for any SOC using artificial intelligence in its workflow. Coverage ranges from a chat assistant to full agentic operation, so the label alone says very little about capability.
Alert triage
Deciding whether an alert represents real malicious activity. Historically the largest consumer of analyst time and the main source of burnout in the role. Exaforce customers report a 90% reduction in false positives.
Exabots
Exaforce's task-specific AI agents. Exabot Detect, Exabot Triage, Exabot Investigate, Exabot Respond, and Exabot Hunt each handle one part of the lifecycle, under human oversight.
MDR
Managed detection and response. A service where an external team monitors and responds on the customer's behalf. Exaforce MDR runs the same Exabots the platform uses, 24/7. More on exaforce.com
MTTI
Mean time to investigate. How long it takes to reach a verdict on an alert. Accton took theirs from three hours to ten minutes. Accton case study
MTTR
Mean time to respond. How long from detection to containment. Forcepoint holds 14 minutes on P0 incidents. Forcepoint case study
Multi-Model AI
Exaforce's three-model engine. The Semantic Data Model resolves entities and relationships, the Behavioral Model learns normal activity, and the Knowledge Model reasons across both. More on exaforce.com
Semantic context
Structured meaning attached to events at ingest, so AI reasons over an understood environment rather than raw log text. The reason verdicts stay consistent between runs.
SIEM
Security information and event management. The traditional log aggregation and correlation layer. Exaforce replaces it and is not one.
SOAR playbooks
Deterministic automation scripts for security operations. They apply rigid logic to non-deterministic processes, which is why they break whenever an API changes.
Threat hunting
Proactively searching for adversary activity that no alert fired on. Exaforce calls natural-language threat hunting vibe hunting.
UEBA
User and entity behavior analytics. Baselining normal behavior to spot deviation from it. Exaforce's Behavioral Model does this across both human and machine identities.