What Are IOCs (Indicators of Compromise)?

Also called: Indicator of compromise

Related problems: A vendor or agency published IOCs and we don't know how to check for them; Not sure whether we were hit by a widely reported attack; Threat intelligence feeds we pay for don't seem to be used; Need evidence for an incident investigation

Indicators of compromise (IOCs) are pieces of forensic evidence that suggest a system or network may have been breached. They include malicious IP addresses and domains, hashes that identify known malicious files, suspicious registry or file changes, and the email addresses or URLs used in a campaign. Security teams search for IOCs to find intrusions, confirm whether a published threat affected them, and scope an incident.

At a glance

  • IOCs are evidence of past or ongoing compromise, mostly technical artifacts left by attackers.
  • They’re shared through threat intelligence feeds, vendor reports and government advisories.
  • Security tools such as SIEM, EDR and firewalls can match IOCs automatically against logs and traffic.
  • An IOC match is a lead to investigate, not proof of a breach.
  • Many IOCs go stale quickly as attackers change infrastructure; behavior-based detection complements them.

What problem it solves

When a new attack campaign is discovered, the first question for everyone else is “were we hit?” IOCs make that question answerable. Investigators who analyze one incident publish the addresses, domains and file fingerprints they found, and other organizations search their own logs and systems for the same evidence.

IOCs also make detection repeatable. Once an indicator is known, tools can block it or alert on it automatically. During an incident, IOCs found on one machine help responders find other affected systems. Without them, each organization would have to work out each attack from scratch.

How it works

Collection. IOCs come from incident investigations, security vendors, cyber threat intelligence (CTI) feeds, industry sharing groups and agency advisories. They’re often published in standard machine-readable formats so tools can import them.

Management. A threat intelligence platform (TIP) or similar tool collects indicators, removes duplicates, rates confidence and sets expiry dates, then pushes them to security tools.

Matching. A SIEM, EDR, firewall, DNS filter or email gateway compares activity against the IOC list. Matches can be blocked, alerted on, or both, depending on confidence and configuration.

Retrospective searching. Analysts search historical logs for newly published IOCs, which can reveal an intrusion that happened before the indicator was known. This depends on how long logs are kept and is often part of threat hunting.

Investigation. Each match is checked in context to decide whether it is real. Confirmed IOCs help scope the incident and support incident response.

Sharing back. IOCs found during your own incidents can be shared with industry groups, your security providers or, where appropriate, authorities, which helps others detect the same attacker. Agree beforehand what your providers may share and how it is anonymized.

Expiry and review. Indicators are typically given a lifetime. Addresses and domains go stale fastest; file hashes for known malware usually stay useful longer, though attackers can alter files to change the hash.

When it matters for buyers

  • When a major threat makes the news. Ask your security provider whether they’ve searched your environment for the published IOCs, and what they found.
  • When buying threat intelligence. Feeds add little unless something ingests and acts on them; check how indicators reach your tools and how stale ones are retired.
  • When choosing MDR or a SIEM. Compare how IOCs are used for detection and retrospective search, and how long data is kept. Our managed detection and response and SIEM overviews cover the trade-offs.
  • When responding to an incident. IOCs found early help decide how far the investigation needs to go.

Questions to ask vendors

  • Which threat intelligence sources do you use for IOCs, and how do you rate their confidence?
  • How quickly do new IOCs from advisories reach detection in our environment?
  • Do you search our historical data for newly published IOCs, and how far back?
  • How do you avoid false positives from shared or stale indicators?
  • Beyond IOCs, how do you detect attacker behavior when indicators are unknown?

How it differs from indicators of attack

IOCs describe what an attack leaves behind: a specific address, domain or file. Indicators of attack (IOAs) describe what an attacker is doing, such as stealing credentials, disabling security tools or running commands remotely, whatever tools they use. IOCs are precise and easy to share but are often specific to one campaign and easy for attackers to change. IOAs are harder to evade and can catch new attacks, but take more context to judge. Mature detection uses both.

Frequently Asked Questions

What are examples of IOCs?
Common examples include IP addresses and domains used by attackers, hashes of known malicious files, suspicious file names or registry changes, malicious URLs, and email sender addresses or subject lines used in a campaign.
Where do IOCs come from?
From incident investigations, security vendors, threat intelligence feeds, information-sharing groups and government agencies, which often publish IOCs with their advisories on major threats.
Does finding an IOC mean we've been breached?
Not necessarily. An IOC match is a lead to investigate. Indicators can be shared infrastructure, outdated or wrong, so an analyst needs to confirm whether the activity was really malicious.
Why do IOCs go stale?
Attackers change IP addresses, domains and file variants cheaply and often. An indicator that was accurate during one campaign may later point to a harmless or reassigned resource, so feeds need expiry dates and regular review.
What is the difference between IOCs and IOAs?
Indicators of compromise are evidence that something bad has already happened. Indicators of attack (IOAs) describe attacker behavior in progress, such as credential dumping or unusual remote execution, regardless of the specific tools or addresses used.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.