Terminology Index
Glossary
1801 terms
Showing 897-928 of 1801 terms
Indicator Pivoting
An analyst investigation skill of moving from one indicator to related ones, an IP to the domains it hosts, a hash to where else it appears, to expand an investigation and uncover the full scope of activity.
Framed as a SOC analyst skill, indicator pivoting follows the links between indicators across data sources: from an IP to associated domains and the hosts that contacted it, from a file hash to every system it appears on, from an account to its activity. Each pivot widens the investigation, revealing related infrastructure, affected assets, and the true scope of an incident. It is a core investigative technique, complementing behavioral pivoting and cross-source correlation.
Introduced in: SOC Analyst Fundamentals
Examples
- Pivoting from a malicious IP to the domains and hosts tied to it.
- Following a file hash to every system where it appears.
- Expanding an investigation's scope by chaining related indicators.
No related terms linked yet.
