IOC
Indicator of Compromise
An IOC is a piece of forensic evidence that signals a system or network has been breached. Common IOCs include malicious IP addresses, file hashes, domain names, and registry key modifications.
Como é usado em cibersegurança
Threat intelligence analysts collect and share IOCs through feeds and platforms like STIX/TAXII. SOC analysts search SIEM and EDR telemetry for IOC matches to identify compromised assets. Incident responders use IOCs to scope an intrusion and determine how far an attacker has spread.
Termo relacionado no glossário: indicators of compromise
As definições são explicações originais escritas para fins de desenvolvimento profissional. Para definições técnicas autoritativas, consulte NIST, ISO ou o órgão de normalização correspondente.