A
- Alert triage
- Reviewing alerts that detection rules have already raised and deciding which need action. Hunting works the other way round: it starts from a question and looks for activity no rule has flagged.
- ATT&CK tactic
- The adversary's goal at a stage of an attack, such as Initial Access or Lateral Movement. ATT&CK v19 lists 15 Enterprise tactics.Source: MITRE ATT&CK
- ATT&CK technique
- The way an adversary achieves a tactic, such as a specific method of gaining credentials. Coverage views usually count techniques rather than tactics.Source: MITRE ATT&CK
B
- Backtesting
- Running a new detection rule against past data before it goes live, to see how often it would have fired. A backtest window is the length of past data used.
- Behavioral hunt
- A hunt for a pattern of attacker actions, such as a run of sign-ins followed by a privilege change, rather than for one known file hash or address. Mars Security describes converting threat intelligence into behavioral hunts.
- Buyer question
- The single question a comparison is built to answer. On this site it is which tool turns new threat intelligence into hunts and detections on existing data without a new ingestion pipeline. All weights follow from it.
C
- Connector
- The integration that lets a tool read from or act on another platform. A connector list is most useful when it says whether each platform is queried in place or ingested.
- Continuous hunting
- Hunts that run without a person starting each one, on a schedule or when new intelligence arrives. One of the seven criteria scored on this site.Scored on the matrix
- Coverage gap
- An ATT&CK technique or tactic with no detection rule mapped to it in your environment.
- Coverage view
- A screen or report that shows which ATT&CK techniques have at least one detection rule mapped to them, often drawn as a heatmap. Tagging rules with ATT&CK is not the same thing; the view is what adds them up.
- Criterion
- One of the seven things every tool is scored on here, each from 1 to 5.
- Criterion weight
- The share of the weighted figure a criterion carries. The seven weights on this site add up to 100%.
D
- Data lake
- A store for large volumes of raw data, often in cloud object storage, queried with its own compute. Snowflake and Databricks are examples named on vendor pages.
- Defense Impairment
- The ATT&CK tactic TA0112, covering adversary efforts to weaken security tools and monitoring. MITRE created it on 14 April 2026, and in ATT&CK v19 it and Stealth replaced Defense Evasion.Source: MITRE ATT&CK
- Detection engineering
- The work of designing, writing, testing, deploying and maintaining detection rules. Several tools on this site use AI agents for parts of it.
- Detection rule
- A saved query or logic that raises an alert when data matches a pattern of attacker behaviour.
- Detection-as-code
- Keeping detection rules in source control, with changes reviewed, versioned and deployed like software.
E
- EDR (endpoint detection and response)
- Software on laptops and servers that records process, file and network activity and can act on the device. CrowdStrike Falcon, Microsoft Defender and SentinelOne are EDR products named on vendor pages we reviewed.
F
- Federated search
- A single query sent to several data platforms where the data sits, with results combined, instead of copying the data into one store first.
H
- Head-to-head
- A page on this site comparing two tools criterion by criterion, with both scores and reasons on every row.
- Hot-path data
- Data a tool needs quickly and often, such as the events its detections run on. Artemis Security states that it ingests hot-path data and queries high-volume data where it lives.
- Hypothesis-led hunt
- A hunt that starts from a stated guess about attacker behaviour, such as a technique that may be in use, and looks for evidence for or against it.
I
- Identity provider (IdP)
- The service that signs users in and holds their accounts and groups, such as Okta or Microsoft Entra. Its logs of sign-ins, MFA prompts and privilege changes are where many credential-theft hunts start.
- Indicator of compromise (IOC)
- A specific artifact linked to an attack, such as a file hash, domain or IP address. Behaviour-based detections look at actions rather than single artifacts.
- Ingestion pipeline
- The forwarding, parsing and storage work needed to copy data from its source into a tool's own store.
- Intelligence-led hunt
- A hunt that starts from a published threat report or advisory and looks for the behaviour it describes in your own data.
L
- Level
- Our word for a tie. Two tools are level on a criterion when their scores are equal, and level overall when their weighted figures match to two decimals.
M
- MCP (Model Context Protocol)
- An open protocol that lets AI agents call outside tools and data sources through one standard interface. Cotool supports custom MCP servers and Vega lists MCP support.
N
- Native query language
- The query language a data platform uses itself, such as SPL on Splunk. Mars Security states that it writes each query in the native query language of each source.
O
- OCSF
- The Open Cybersecurity Schema Framework, an open schema for describing security events in one shape. Artemis Security said in June 2026 that it normalizes Claude Enterprise Compliance API events to OCSF.
P
- Proof of concept (PoC)
- A time-boxed trial of a tool on a buyer's own data, judged against success criteria agreed before it starts.
Q
- Query in place
- Running a search on the platform that already holds the data, so the data is not copied. Vendors also describe it as querying data "where it lives".
R
- Retrohunt
- Searching past data for activity that a new rule or new intelligence would have caught. Nebulock requires every rule to pass one before deployment.
- Rule lifecycle
- Everything that happens to a detection rule after it is written: testing, review, versioning, deployment, tuning and rollback. One of the seven criteria scored here.Scored on the matrix
S
- Shortlist
- The two or three tools a team takes into demos and a proof of concept after a first comparison.
- Sigma
- An open, generic format for writing detection rules once and converting them to different SIEM query languages. The SigmaHQ repository holds more than 3,000 rules.Source: SigmaHQ on GitHub
- STIX/TAXII
- STIX is a standard format for describing threat intelligence, and TAXII is a protocol for exchanging it. Tools that accept STIX/TAXII can take in custom intelligence feeds.
T
- Threat advisory
- A published notice from a government agency or research team describing an active threat, usually with the behaviours and indicators to look for. Mars Security names CISA, Mandiant, Unit 42 and Microsoft Threat Intelligence as advisory sources.
- Time to first value
- How long it takes a team to run its first useful hunt on its own data after buying. Scored here from stated deployment models, setup times and listings.Scored on the matrix
W
- Weighted figure
- A tool's overall number on this site: each 1 to 5 score times its criterion weight, summed and divided by 100. The result is out of 5.
Editorial assessment · Desk research from public vendor material, last reviewed September 2026