IOC: Indicator of Compromise in Cybersecurity

Threat Intelligence
ByDecipherU Editorial
How is it pronounced?
eye-oh-see

IOC stands for Indicator of Compromise. An IOC is a piece of forensic evidence that signals a system or network has been breached. Common IOCs include malicious IP addresses, file hashes, domain names, and registry key modifications.

How IOC Is Used in Cybersecurity

Threat intelligence analysts collect and share IOCs through feeds and platforms like STIX/TAXII. SOC analysts search SIEM and EDR telemetry for IOC matches to identify compromised assets. Incident responders use IOCs to scope an intrusion and determine how far an attacker has spread.

Read the full glossary entry: Indicators of Compromise in Cybersecurity

Cybersecurity Roles That Work with IOC

Related Cybersecurity Acronyms

Frequently asked questions

What does IOC stand for?

IOC stands for Indicator of Compromise. An IOC is a piece of forensic evidence that signals a system or network has been breached. Common IOCs include malicious IP addresses, file hashes, domain names, and registry key modifications.

What is IOC used for in cybersecurity?

Threat intelligence analysts collect and share IOCs through feeds and platforms like STIX/TAXII. SOC analysts search SIEM and EDR telemetry for IOC matches to identify compromised assets. Incident responders use IOCs to scope an intrusion and determine how far an attacker has spread.

Last verified: April 2026?Report an inaccuracy