IDS / IPS Intrusion Detection/Prevention System
Monitoring system that detects attacks (IDS) or actively blocks them (IPS).
Inspects network traffic or log events for patterns. Snort, Suricata, Zeek (open source). Signature-based or anomaly-based. Modern SOC stacks (SIEM + XDR) integrate the IDS function.