Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is an indicator of compromise?

An indicator of compromise — often shortened to IOC — is a technical artefact or characteristic associated with possible malicious activity.

It gives you something concrete to search for.

Examples include a file hash, IP address, domain, URL, certificate, registry value or traffic pattern.

Indicators vary in strength

Not every indicator is equally specific.

Indicator What a match may tell you
Exact malicious file hash This exact file appears to be present
Domain or URL A system queried or contacted a known address
IP address Traffic involved an address associated with suspicious activity
Filename A similarly named file exists
Registry value A configuration or persistence-like artefact exists
Certificate Files or services may share signing/infrastructure relationships

A shared IP address or common filename may be weak.

An exact hash of a known malicious file can be much more specific.

Indicators also age

Infrastructure changes.

Domains expire.

Cloud addresses are reassigned.

Malware is repacked.

That means the value of an IOC depends partly on when the intelligence was observed and whether it was still relevant at the incident time.

Keep the intelligence context

If an IOC matters, record:

  • who supplied it;
  • when it was observed;
  • confidence;
  • what it is supposed to represent;
  • relevant dates;
  • any threat/intelligence reference.

Then identify the local event that matched.

Example IOC match
IOC type=domainvalue=update-example.testintelligence observed=2026-09-10local event=DNS query from ADMIN-07time=2026-09-14 05:22 UTC

Now you have an intelligence pointer connected to a real system event.

Presence, execution and consequence are different

A suspicious file may exist without being run.

A DNS query may occur without a successful connection.

A network connection may occur without compromise.

Does an indicator of compromise prove compromise? takes that next step.

The practical point is: an IOC is a useful search value, not a verdict. Its value comes from its specificity, age and the local event that matched it.

Reference: CIM-018Cyber Incidents & Offender Methods