Indicator of Compromise
An observable artifact or behavior that may indicate malicious activity or a security breach.
Security Context
An indicator of compromise can be a hash, domain, IP address, registry path, process behavior, log pattern, or another observable artifact associated with malicious activity. Detection pipelines should manage indicators with confidence, context, provenance, and expiration because many values change quickly.
Attribution Boundary
An IOC does not by itself prove adversary intent or identity. Behavioral TTP information is often more durable than an easily replaced IP address, file hash, or domain.
Related Security Concepts
- Tactics Techniques and Procedures
- YARA
- Threat Intelligence
- Detection