Terminology Index
Glossary
1801 terms
Showing 897-928 of 1801 terms
Indicator Pivot
Using one observed indicator on a host, such as a suspicious process, path, or registry key, as a starting point to find related artifacts and expand understanding of what an attacker did on the system.
Framed for OS-level defense, an indicator pivot takes a single host artifact, an odd process, an executable path, a persistence key, and follows its connections to uncover more: the process's parent and children, files it touched, registry it modified, network it contacted. Pivoting this way reconstructs attacker activity on a system from one lead, a core investigative technique that turns an isolated indicator into a fuller picture of the compromise.
Introduced in: Operating Systems for Defenders
Examples
- Pivoting from a suspicious process to its parent, children, and files touched.
- Following a malicious executable path to related registry persistence.
- Expanding from one host artifact to reconstruct attacker activity.
No related terms linked yet.
