Examples include a known-malicious file hash, an unexpected persistence entry, a suspicious domain, a command pattern, or a characteristic network connection.
An IoC is a lead, not automatic proof. Analysts must consider the source, context, timing, and possibility of legitimate reuse or deliberate deception. Some indicators — especially attacker-controlled infrastructure — change quickly, while artifacts tied to behavior may remain useful longer.
Indicators range from easily changed artifacts — file hashes, IP addresses, domains — to harder-to-fake behaviors such as tools, techniques, and sequences; disrupting behavioral indicators costs the adversary far more than rotating an address. Indicators also age: infrastructure is recycled and re-registered, so confidence scores, first and last observed times, and expiration rules matter as much as the indicator list itself.
Key points
Primary purposeSupport detection, threat hunting, scoping, and investigation.
Where it appearsEndpoint, identity, email, network, cloud, application, and threat-intelligence data.
Good practiceRecord provenance, confidence, first and last observed times, context, and expiry or review conditions.
Important limitationA match can be false or historical, while the absence of a known IoC does not show that an environment is clean.