Indicators of compromise (IOCs) are pieces of forensic evidence that suggest a system or network may have been breached. They include malicious IP addresses and domains, hashes that identify known malicious files, suspicious registry or file changes, and the email addresses or URLs used in a campaign. Security teams search for IOCs to find intrusions, confirm whether a published threat affected them, and scope an incident.
At a glance
- IOCs are evidence of past or ongoing compromise, mostly technical artifacts left by attackers.
- They’re shared through threat intelligence feeds, vendor reports and government advisories.
- Security tools such as SIEM, EDR and firewalls can match IOCs automatically against logs and traffic.
- An IOC match is a lead to investigate, not proof of a breach.
- Many IOCs go stale quickly as attackers change infrastructure; behavior-based detection complements them.
What problem it solves
When a new attack campaign is discovered, the first question for everyone else is “were we hit?” IOCs make that question answerable. Investigators who analyze one incident publish the addresses, domains and file fingerprints they found, and other organizations search their own logs and systems for the same evidence.
IOCs also make detection repeatable. Once an indicator is known, tools can block it or alert on it automatically. During an incident, IOCs found on one machine help responders find other affected systems. Without them, each organization would have to work out each attack from scratch.
How it works
Collection. IOCs come from incident investigations, security vendors, cyber threat intelligence (CTI) feeds, industry sharing groups and agency advisories. They’re often published in standard machine-readable formats so tools can import them.
Management. A threat intelligence platform (TIP) or similar tool collects indicators, removes duplicates, rates confidence and sets expiry dates, then pushes them to security tools.
Matching. A SIEM, EDR, firewall, DNS filter or email gateway compares activity against the IOC list. Matches can be blocked, alerted on, or both, depending on confidence and configuration.
Retrospective searching. Analysts search historical logs for newly published IOCs, which can reveal an intrusion that happened before the indicator was known. This depends on how long logs are kept and is often part of threat hunting.
Investigation. Each match is checked in context to decide whether it is real. Confirmed IOCs help scope the incident and support incident response.
Sharing back. IOCs found during your own incidents can be shared with industry groups, your security providers or, where appropriate, authorities, which helps others detect the same attacker. Agree beforehand what your providers may share and how it is anonymized.
Expiry and review. Indicators are typically given a lifetime. Addresses and domains go stale fastest; file hashes for known malware usually stay useful longer, though attackers can alter files to change the hash.
When it matters for buyers
- When a major threat makes the news. Ask your security provider whether they’ve searched your environment for the published IOCs, and what they found.
- When buying threat intelligence. Feeds add little unless something ingests and acts on them; check how indicators reach your tools and how stale ones are retired.
- When choosing MDR or a SIEM. Compare how IOCs are used for detection and retrospective search, and how long data is kept. Our managed detection and response and SIEM overviews cover the trade-offs.
- When responding to an incident. IOCs found early help decide how far the investigation needs to go.
Questions to ask vendors
- Which threat intelligence sources do you use for IOCs, and how do you rate their confidence?
- How quickly do new IOCs from advisories reach detection in our environment?
- Do you search our historical data for newly published IOCs, and how far back?
- How do you avoid false positives from shared or stale indicators?
- Beyond IOCs, how do you detect attacker behavior when indicators are unknown?
How it differs from indicators of attack
IOCs describe what an attack leaves behind: a specific address, domain or file. Indicators of attack (IOAs) describe what an attacker is doing, such as stealing credentials, disabling security tools or running commands remotely, whatever tools they use. IOCs are precise and easy to share but are often specific to one campaign and easy for attackers to change. IOAs are harder to evade and can catch new attacks, but take more context to judge. Mature detection uses both.
