Indicator of compromise
IoC · A concrete trace that points to a system being compromised: a malicious IP address or domain, the hash of a malicious file, an unusual registry entry or a suspicious network connection.
- 01
Why it matters
When an attack is detected in one place, the indicators it leaves let you search for the same attacker elsewhere. One of the first steps in incident response is collecting indicators and sweeping the whole environment. Because attackers change addresses and files often, indicators should be used together with behaviour monitoring.
- 02
Example
The hash of a malicious file found on a server is taken and searched for on every computer. The same file turns up on two laptops, revealing that the attack was not limited to a single server.
- 03
Common mistake
Searching for indicators only after the clean-up is over. The search belongs inside the clean-up; otherwise an entry point the attacker kept stays open and the incident repeats.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.