Skip to content

IoC (Indicator of Compromise)

Observable artefact linked to malicious activity. File hashes (MD5, SHA-256, ImpHash, ssdeep, TLSH), IPs, domains, URLs, registry keys, mutex names, named pipes, scheduled task names, service names. Shared between organisations using STIX (data model) over TAXII (transport).

Explained in

Related terms

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.