Terminology Index
Glossary
1801 terms
Showing 897-928 of 1801 terms
Indicators of Compromise
Observable artifacts that signal a system may be compromised, such as malicious file hashes, IP addresses, domains, or registry keys, used to detect, hunt for, and confirm known threats across an environment.
Indicators of compromise (IOCs) are concrete forensic artifacts tied to known malicious activity, file hashes, command-and-control domains and IPs, file paths, registry keys, that defenders use to detect and sweep for threats. Shared through threat intelligence, they enable fast matching against telemetry. Their limitation is that attackers can change them easily, so IOCs are strongest for known threats and are complemented by behavior-based indicators of attack for novel activity.
Introduced in: Logging, Monitoring, and Telemetry, Threat Landscape and Attacker Thinking, Threat Intelligence for SOC Analysts
Examples
- Matching a known-malicious file hash across endpoints.
- Blocking a command-and-control domain published as an IOC.
- Sweeping telemetry for IOCs shared by threat intelligence.
No related terms linked yet.
