IOC
An Indicator of Compromise (IOC) is a technical characteristic that indicates a potential security breach.
An Indicator of Compromise (IOC) is a technical characteristic that points towards a cyber attack. Typical examples include IP addresses, domains, file hashes or specific registry entries.
How it works
After an incident, analysts document the attacker's traces. These IOCs are shared and imported into SIEM, EDR and firewall systems. If a known IOC reappears, it immediately generates an Alert. The SOC also retrospectively searches logs to see if the IOC has appeared before.
For example: A report names a domain used by malware to receive its commands. The SOC searches for the domain in the DNS logs from the last 90 days. It finds three requests from a laptop two weeks ago. The laptop is then isolated and investigated.
What to look out for
- Lifespan: Attackers often change IP addresses and domains within hours. Old IOCs quickly lose their value.
- False positives: Shared hosting addresses can match legitimate services.
- Retrospective searches: These are not possible without sufficient log retention.
- Limitations: IOCs detect known attacks. They miss new variants.
How it differs from TTP
IOCs are easy for attackers to change at little cost. Tactics, Techniques and Procedures (TTP) change much less frequently. Detection based on behaviour is therefore more durable.
Questions for operations
How quickly does a new IOC from a report get into your detection rules? How long does it remain active before it is automatically removed? Can you search retrospectively over 90 days or more? Who assesses matches that point to shared cloud addresses? A clear process for these questions prevents IOC lists from growing without being maintained.
How we implement it
We use IOCs from threat intelligence to enrich Alerts. Our detection focus is on behaviour and techniques.