IOA
Indicator of Attack
An IOA describes active attacker behaviors and techniques rather than static artifacts. IOAs focus on what an attacker is trying to do, such as credential dumping or privilege escalation, regardless of the specific tools used.
Como é usado em cibersegurança
Threat hunters use IOAs to build behavioral detection rules that catch attackers even when they change their tools. SOC analysts correlate IOAs with MITRE ATT&CK techniques to classify the stage of an ongoing attack. Security engineers write detection logic based on IOAs to identify threats that signature-based tools miss.
Termo relacionado no glossário: indicators of attack
As definições são explicações originais escritas para fins de desenvolvimento profissional. Para definições técnicas autoritativas, consulte NIST, ISO ou o órgão de normalização correspondente.