Initial Indicator of Compromise (IoC)
Definition
The first observable artefact or event that triggers the investigation: a hash match, a suspicious process, an anomalous login, or an alert from a detection rule. The IoC is the starting point for scoping, not the conclusion.
- Field
- Digital forensics and incident response
- Role
- Starting point for scoping an investigation
- Examples
- Hash match, suspicious process, anomalous login, detection alert
- Not
- The conclusion of the investigation
Common questions
Why is it important not to treat the initial IoC as the full scope of a breach?+
The first artefact discovered is often only the visible edge of an intrusion. Responders use it to pivot outward, checking related systems, timestamps, and accounts, because stopping at the initial IoC risks missing lateral movement or persistence elsewhere.
What typically happens right after an initial IoC is identified?+
The team moves into scoping: correlating the IoC against logs and other hosts to confirm whether it represents a genuine compromise, then defining how far the affected systems and timeframe extend before containment begins.
Related terms
- Blast Radius
- The full set of systems, accounts, and data that an attacker has accessed or could access given their current level of compromise....
- Corroboration
- The practice of confirming an observed attacker action by finding evidence of the same action in at least two independent data sources,...
- Declaration Threshold
- The criteria defined in an organisation's IR plan that a suspected event must meet before it is formally declared a confirmed incident,...
- Dwell Time
- The period between an attacker gaining initial access and their detection. Reducing dwell time is a primary goal of threat hunting. The...
- Lateral Movement
- Attacker activity after initial compromise in which the threat actor traverses from one internal system to another, typically to escalate privileges, access...