Terminology Index

Glossary

1801 terms

Open concept maps

Showing 897-928 of 1801 terms

I
32

Indicator Pivot

Using one observed indicator on a host, such as a suspicious process, path, or registry key, as a starting point to find related artifacts and expand understanding of what an attacker did on the system.

Framed for OS-level defense, an indicator pivot takes a single host artifact, an odd process, an executable path, a persistence key, and follows its connections to uncover more: the process's parent and children, files it touched, registry it modified, network it contacted. Pivoting this way reconstructs attacker activity on a system from one lead, a core investigative technique that turns an isolated indicator into a fuller picture of the compromise.

Introduced in: Operating Systems for Defenders

Examples

  • Pivoting from a suspicious process to its parent, children, and files touched.
  • Following a malicious executable path to related registry persistence.
  • Expanding from one host artifact to reconstruct attacker activity.

No related terms linked yet.