What is an IoC?
Indicator of Compromise (IoC)
An indicator of compromise (IoC) is an observable artifact or condition that suggests malicious activity may be occurring or may have occurred. Examples include a known-malicious file hash, an unexpected persistence entry, a suspicious domain, a command pattern, or a characteristic network connection.
An IoC is a lead, not automatic proof. Analysts must consider the source, context, timing, and possibility of legitimate reuse or deliberate deception. Some indicators—especially attacker-controlled infrastructure—change quickly, while artifacts tied to behavior may remain useful longer.
Related terms
Often confused with
An indicator of attack focuses on behavior suggesting an attack in progress; usage varies, and both require contextual analysis.
