Terminology Index
Glossary
2953 terms
B32
Blue Team
The defenders in cybersecurity, the people and functions responsible for protecting systems, detecting attacks, and responding to incidents. It contrasts with the red team, which simulates attackers to test defenses.
The blue team spans security operations, detection engineering, incident response, threat hunting, and forensics, working continuously to prevent, detect, and recover from attacks. The term frames defensive work as a coordinated discipline and is most meaningful in contrast with offensive red-team activity.
Introduced in: Blue Team Operations
Examples
- A SOC analyst triaging alerts as part of blue-team operations.
- Detection engineers building rules to catch attacker techniques.
- Incident responders containing and recovering from a breach.
Related
Security Operations Centerrelates_toDetection engineeringrelates_toIncident Responserelates_toThreat Huntingrelates_toThreat Intelligencerelates_toCoverage Metricsrelates_toDefenderrelates_toForensic Analystsrelates_toHybrid SOCrelates_toIncident Responserelates_toIncident Responderrelates_toDetection Engineerrelates_to
