Does an indicator of compromise prove compromise?¶
Not necessarily.
A match tells you that a system, file or event is associated with an indicator you were looking for.
What you need next is to establish what actually happened around that match.
A match can describe very different events¶
For example:
Those are useful observations, but they are not identical to compromise.
Follow the indicator into behaviour¶
Suppose a known malicious file hash is found on a workstation.
Ask:
- where was the file found;
- how did it arrive;
- did it execute;
- which process launched it;
- did it create persistence;
- did it connect externally;
- did accounts or files change afterwards.
A sequence like this is much stronger:
That begins to establish compromise from behaviour, not just reputation.
Keep timing and provenance in view¶
An indicator may have been valid last year and irrelevant now.
A cloud IP address may be shared.
A domain may have changed owner.
Keep the intelligence source, observation period and confidence alongside the local match.
Absence of indicators is not proof of safety¶
Threat infrastructure, malware and techniques change.
An incident can be real even when none of your existing IOC lists match it.
The practical point is: treat an IOC match as a useful observation. Establish compromise from the linked execution, communication, account activity or system consequence around it.