Terminology Index

Glossary

2953 terms

Open concept maps
I
32

Indicator Extraction

Pulling concrete indicators, such as file hashes, domains, IPs, or behavioral patterns, out of a threat hunt's findings, so what the hunt discovered can be operationalized into detections and shared intelligence.

When a hunt uncovers malicious activity, indicator extraction captures the reusable signals it revealed, IOCs like hashes, domains, and IPs, and behavioral indicators of the technique, so they can be turned into detections, fed to threat intelligence, and used to sweep for the same activity elsewhere. It is a key step in converting hunt findings into lasting value, bridging the hunt's discovery to detection engineering and the finding lifecycle.

Introduced in: Threat Hunting Fundamentals

Examples

  • Extracting a malicious domain and hash from a hunt's findings.
  • Capturing a behavioral pattern to turn into a detection.
  • Sharing extracted indicators with threat intelligence.