Security Information and Event Management — a platform that aggregates and analyzes log data from across an organization to detect security incidents.
SIEM tools are the backbone of most SOC operations. Analysts write queries against SIEM data to investigate alerts, correlate events across systems, and reconstruct the timeline of an incident.