IoC

Indicator of Compromise

Kompromittierungsindikator

An IoC is a concrete, observable artefact that points to a compromise — such as a malicious IP address, a domain, a file hash or a suspicious registry entry. IoCs are the tangible currency of threat intelligence: they can be shared and matched against one's own environment automatically. They describe the trace, however, not the behaviour.

History & facts. IoCs emerged from the need to make insights about attacks exchangeable in a machine-readable way. Platforms such as MISP structure and share them, and the TLP model governs how far they may be passed on. An important counter-concept is the Indicator of Attack (IoA), which targets behaviour rather than concrete artefacts — because IoCs age quickly once an attacker changes infrastructure or files. Outlook & recommendation. IoCs are useful but no panacea: they detect mainly the known. Those who rely solely on indicator lists are blind to new or targeted attacks. The sensible approach combines IoC matching (fast, automatable) with behaviour-based detection (more robust against change). Quality is also decisive: an IoC without context and without correlation to one's own telemetry produces more noise than value.
IoC — Indicator of Compromise