IOA
Indicator of Attack
An IOA describes active attacker behaviors and techniques rather than static artifacts. IOAs focus on what an attacker is trying to do, such as credential dumping or privilege escalation, regardless of the specific tools used.
Cómo se usa en ciberseguridad
Threat hunters use IOAs to build behavioral detection rules that catch attackers even when they change their tools. SOC analysts correlate IOAs with MITRE ATT&CK techniques to classify the stage of an ongoing attack. Security engineers write detection logic based on IOAs to identify threats that signature-based tools miss.
Término relacionado en el glosario: indicators of attack
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.