Network Indicator
Definition
A network-based artefact produced by malware at runtime, such as a DNS query, an IP address contacted, an HTTP request path, a TLS certificate fingerprint, or a User-Agent string. Network indicators from sandbox reports feed directly into threat-intelligence platforms and firewall block-lists.
- Field
- Malware analysis
- Examples
- DNS query, IP, HTTP path, TLS fingerprint, User-Agent
- Source
- Sandbox execution
- Use
- Feeds threat-intel platforms and firewall blocklists
Common questions
Why are network indicators considered less durable than file hashes?+
Attackers can rotate IP addresses and domains quickly, so network indicators often have a shorter useful life than a malware sample's static file hash.
How are network indicators typically shared between organisations?+
Through threat-intelligence feeds and standardised formats such as STIX and TAXII, letting defenders block matching traffic before an infection spreads further.
Related terms
- API Hooking
- A monitoring technique in which the sandbox intercepts calls the malware makes to operating-system API functions. Each intercepted call is logged with...
- Behavioural Analysis
- The examination of what a program does at runtime rather than what its code says at rest. Behavioural analysis captures the actual...
- Evasion Detection
- Malware logic that checks whether the execution environment is a real host or an analysis sandbox. Checks may query hardware identifiers, count...
- MITRE ATT&CK Mapping
- The process of classifying observed malware behaviours against the MITRE ATT&CK framework's taxonomy of adversary tactics and techniques. Sandbox platforms increasingly produce...
- Sandbox
- An isolated execution environment, typically a virtual machine, where a malware sample runs under full instrumentation. The sandbox logs all system calls,...