IOC
Indicator of Compromise
An IOC is a piece of forensic evidence that signals a system or network has been breached. Common IOCs include malicious IP addresses, file hashes, domain names, and registry key modifications.
Cómo se usa en ciberseguridad
Threat intelligence analysts collect and share IOCs through feeds and platforms like STIX/TAXII. SOC analysts search SIEM and EDR telemetry for IOC matches to identify compromised assets. Incident responders use IOCs to scope an intrusion and determine how far an attacker has spread.
Término relacionado en el glosario: indicators of compromise
Las definiciones son explicaciones originales escritas con fines de desarrollo profesional. Para definiciones técnicas autorizadas, consulta NIST, ISO o el organismo de normalización correspondiente.