Indicators of Compromise (IoCs)
Definition
Artefacts observed on a network or system that suggest an intrusion or malicious activity has occurred, such as unusual outbound connections, known-malicious file hashes, registry keys created by malware, or account logins from unexpected locations. IoCs drive the Detection and Analysis phase.
- Full name
- Indicators of compromise
- Examples
- Malicious file hashes, unusual outbound traffic, rogue registry keys
- Drives
- The Detection and Analysis phase of incident response
- Field
- Digital forensics and incident response
Common questions
How do IoCs differ from indicators of attack (IoAs)?+
IoCs are typically static, backward-looking artefacts, such as a known-bad file hash, useful for confirming that a specific known threat is present. IoAs describe behaviour patterns in progress, such as an unusual sequence of process activity, and aim to catch an attack while it is still unfolding.
Why do IoCs lose value over time?+
Attackers routinely change file hashes, domains, and IP addresses between campaigns, so a static IoC list ages quickly. Effective detection programmes refresh IoC feeds continuously and pair them with behavioural detection that does not depend on any single fixed artefact.
Related terms
- Containment Strategy
- A deliberate decision about how to limit an incident's spread, balancing the need to stop harm immediately against the risk of alerting...
- Decision Gate
- A checkpoint within a playbook at which the responder must evaluate a condition, such as whether data exfiltration has been confirmed, and...
- Eradication
- The phase in which the root cause of an incident is removed from the environment: deleting malware, patching exploited vulnerabilities, revoking compromised...
- Incident Response Lifecycle
- The structured sequence of phases NIST SP 800-61 defines for handling computer security incidents: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity....
- Incident Response Plan
- A formal document that defines an organisation's approach to incident handling: roles and responsibilities, escalation paths, communication procedures, legal and regulatory obligations,...
- Lessons-Learned Meeting
- A structured post-incident review, recommended by NIST within approximately two weeks of incident resolution, that examines what happened, what the response did...
- Playbook
- A documented step-by-step procedure for responding to a specific type of security event. Playbooks standardise analyst behaviour, reduce response time, and ensure...
- Runbook
- A technical execution document, sometimes used interchangeably with playbook but more precisely refers to the low-level commands and scripts used during a...
- SOAR
- Security Orchestration, Automation and Response. A platform that can execute playbook steps automatically, such as blocking an IP address or disabling a...
- Tabletop Exercise
- A structured, discussion-based simulation in which team members walk through a hypothetical incident using the playbook as a guide, without touching live...
Explained in these topics
- Developing and Using Incident Response PlaybooksObservable artefacts, such as malicious IP addresses, file hashes, domain names, or registry keys, that indicate a system may have been breached. Playbooks spe...
- The NIST SP 800-61 Incident Response Lifecycle