What is an indicator of compromise?¶
An indicator of compromise — often shortened to IOC — is a technical artefact or characteristic associated with possible malicious activity.
It gives you something concrete to search for.
Examples include a file hash, IP address, domain, URL, certificate, registry value or traffic pattern.
Indicators vary in strength¶
Not every indicator is equally specific.
| Indicator | What a match may tell you |
|---|---|
| Exact malicious file hash | This exact file appears to be present |
| Domain or URL | A system queried or contacted a known address |
| IP address | Traffic involved an address associated with suspicious activity |
| Filename | A similarly named file exists |
| Registry value | A configuration or persistence-like artefact exists |
| Certificate | Files or services may share signing/infrastructure relationships |
A shared IP address or common filename may be weak.
An exact hash of a known malicious file can be much more specific.
Indicators also age¶
Infrastructure changes.
Domains expire.
Cloud addresses are reassigned.
Malware is repacked.
That means the value of an IOC depends partly on when the intelligence was observed and whether it was still relevant at the incident time.
Keep the intelligence context¶
If an IOC matters, record:
- who supplied it;
- when it was observed;
- confidence;
- what it is supposed to represent;
- relevant dates;
- any threat/intelligence reference.
Then identify the local event that matched.
Now you have an intelligence pointer connected to a real system event.
Presence, execution and consequence are different¶
A suspicious file may exist without being run.
A DNS query may occur without a successful connection.
A network connection may occur without compromise.
Does an indicator of compromise prove compromise? takes that next step.
The practical point is: an IOC is a useful search value, not a verdict. Its value comes from its specificity, age and the local event that matched it.