Skip to content
Unlisted Report logoUnlisted ReportSubscribe
Threat Intel

Indicators of compromise: what they are and how to use them

Discover what indicators of compromise (IoCs) are, the different types, and how security teams use these digital clues to detect and respond to cyberattacks.

By · Published · 12 min read

A close-up of a digital network map with glowing red nodes indicating anomalies, symbolizing the detection of a security threat.

Indicators of compromise (IoCs) are the digital breadcrumbs that attackers leave behind—pieces of forensic data that point to a potential intrusion on a network or device. For security teams, these artifacts are crucial clues used to detect, investigate, and respond to cyberattacks, helping to piece together what happened and how to stop it.

What Are Indicators of Compromise (IoCs)?

Think of a physical crime scene. Investigators look for fingerprints, footprints, or discarded tools. In the digital world, IoCs are the equivalent. They are observable, concrete pieces of evidence that, by their presence, suggest a system's security has been breached. An IoC is not proof of malicious intent on its own, but its presence where it shouldn't be is a strong signal for investigation.

For example, a file with a specific cryptographic hash known to belong to a piece of malware is a high-confidence IoC. Likewise, network traffic from a corporate laptop communicating with a command-and-control (C2) server used by a ransomware gang is a clear sign of trouble.

It's important to distinguish IoCs from Indicators of Attack (IoAs). While IoCs are the static artifacts *left behind* by an attack (the "what"), IoAs focus on the attacker's actions and behaviors (the "how"). An IoA might be a process attempting to scrape credentials from memory or an unusual series of PowerShell commands. IoAs are more proactive, aiming to detect an attack in progress, whereas IoCs are often used to identify a compromise after the fact.

Common Types of Indicators of Compromise

IoCs come in many forms and can be found across networks, endpoints, and email systems. Security analysts typically categorize them to streamline detection and response. Some of the most common types are organized by where they are found.

CategoryExamplesDescription
:---:---:---
Network IoCsMalicious IP addresses, C2 domains, suspicious URLsThese artifacts relate to network traffic. A firewall or IDS can block traffic to or from a known bad IP address or domain.
Host-based IoCsMalicious file hashes (MD5, SHA-1, SHA-256), registry keys, suspicious file names/paths, mutexesThese are found on an individual device (a host), like a server or laptop. Antivirus and EDR tools use them to find malware on disk.
Email IoCsPhishing email sender addresses, subject lines, malicious attachment file names/hashesThese help identify and block malicious email campaigns. They are often the first sign of a phishing or malware delivery attempt.
Behavioral IoCsUnusual outbound network traffic, strange admin account activity, geographical irregularities, odd login patternsThese are less concrete but highly valuable. They might include a user account logging in from two countries at once or a server suddenly trying to scan the internal network.

These categories help security teams know which tools to use for detection. A network IoC is a job for a firewall or network sensor, while a host-based IoC requires an endpoint security tool.

The Pyramid of Pain: Not All IoCs Are Created Equal

Cybersecurity expert David J. Bianco developed a model called the "Pyramid of Pain" to illustrate the effectiveness of different types of indicators. The concept is simple: the higher up the pyramid you go, the more "pain" you cause the adversary when you deny them that indicator. Blocking indicators at the top of the pyramid forces attackers to change their core tactics, which is far more costly and difficult than simply registering a new domain.

The levels of the pyramid, from bottom (easiest for attackers to change) to top (hardest), are: - Hash Values: Trivial for an attacker to change. A single bit flipped in a file creates a new hash. - IP Addresses: Also very easy for attackers to change, often using proxy networks or compromised infrastructure. - Domain Names: Slightly more effort to acquire, but still relatively simple for attackers to cycle through. - Network/Host Artifacts: Things like specific URL patterns or file names created by malware. These require the attacker to modify their tools. - Tools: The actual software used by the attacker, such as a specific remote access trojan (RAT) or vulnerability scanner. Detecting and blocking the tool itself forces them to retool. - Tactics, Techniques, and Procedures (TTPs): At the top of the pyramid is attacker behavior. This is about *how* they operate—for example, using PowerShell to move laterally or exploiting a specific vulnerability. Detecting and blocking TTPs causes the most pain, as it forces them to learn entirely new methods.

Focusing on the top of the pyramid is a key principle of mature threat intelligence programs. While blocking a known bad IP address is useful, it's a short-term fix. Understanding and defending against the TTPs of groups like the one behind the China-linked NeedyMantis implant hid in telecoms for a year provides a much more durable defense.

How Security Teams Use Indicators of Compromise

IoCs are a fundamental component of modern defensive cybersecurity operations. They are integrated into nearly every phase of security monitoring and incident response.

Threat Hunting Threat hunting is the proactive search for threats that have bypassed existing security controls. Analysts don't wait for an alert; they form a hypothesis (e.g., "I believe threat actor X may be targeting our industry") and search for the IoCs associated with that actor in their environment's logs and network data. This proactive stance can uncover silent, long-running compromises.

Incident Response When an alert fires or a breach is suspected, IoCs become the primary evidence for investigators. They help answer critical questions: 1. **Validation:** Is this a real incident or a false positive? 2. **Scoping:** How widespread is the compromise? Which other systems are affected? 3. **Containment:** What domains, IPs, or files do we need to block to stop the bleeding? 4. **Eradication:** Have we removed all artifacts of the attacker's presence?

Following a major incident, a list of IoCs is often a key deliverable of the investigation, allowing the organization to strengthen its defenses against a recurrence. The process of discovering these digital clues is central to understanding how a ransomware attack unfolds, step by step.

Automated Detection and Prevention Most security tools are designed to consume IoCs. - **Security Information and Event Management (SIEM)** systems correlate logs from across the enterprise, flagging events that match known IoCs. - **Endpoint Detection and Response (EDR)** tools monitor file systems, processes, and network connections on endpoints, comparing activity against databases of malicious file hashes and behaviors. - **Firewalls and Intrusion Detection/Prevention Systems (IDS/IPS)** use lists of malicious IP addresses and domains to block malicious traffic at the network perimeter.

These tools are often fed by threat intelligence platforms that aggregate IoCs from numerous sources.

Sources for Threat Intelligence and IoCs

No organization can discover every IoC on its own. The cybersecurity community relies heavily on sharing threat intelligence to build a collective defense.

  • Government Agencies: Organizations like the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the UK's National Cyber Security Centre (NCSC) regularly publish alerts and advisories containing IoCs related to active campaigns, especially those targeting critical infrastructure.
  • Information Sharing and Analysis Centers (ISACs): These are industry-specific groups (e.g., for finance, healthcare, or energy) where members share threat data, including IoCs, relevant to their sector.
  • Open Source Intelligence (OSINT): There are many free, community-driven projects that aggregate and share IoCs. Platforms like AlienVault OTX and the MISP Project are popular examples where researchers and companies contribute data.
  • Commercial Threat Intelligence Providers: Companies like CrowdStrike, Mandiant, Recorded Future, and others offer subscription-based threat intelligence feeds. These are often highly curated, contextualized, and integrated directly into security tools.
  • Security Blogs and Research Reports: Security vendors and independent researchers frequently publish deep-dive analyses of new malware and attack campaigns. These reports are a goldmine of fresh IoCs for defenders.

The Challenges and Limitations of IoCs

While essential, an IoC-based defense is not a silver bullet. Relying on them exclusively creates a purely reactive security posture, and defenders face several significant challenges.

First, the shelf life of many IoCs is extremely short. Attackers using modern infrastructure can cycle through thousands of IP addresses and domains in a single day, making lists of these indicators obsolete almost as soon as they are published.

Second, false positives are a constant concern. An IP address that was used by an attacker yesterday might be assigned to a legitimate cloud service today. Blocking it could disrupt business operations. Careful vetting and context are required, but this takes time and resources.

Third, the sheer volume of IoCs generated daily is overwhelming. A typical commercial threat feed can contain millions of indicators. Without powerful automation and analytics, security teams can drown in data they are unable to act upon.

Finally, and most importantly, IoCs are inherently reactive. An IoC is evidence that something bad *has already happened*. It signifies a compromise has begun. A truly proactive defense cannot wait for an IoC to appear, especially in the case of what 'zero-day' really means in security headlines, where no known signatures exist yet.

Moving Beyond IoCs for a Proactive Defense

A mature security program uses IoCs as one part of a multi-layered strategy. To get ahead of attackers, organizations must shift their focus up the Pyramid of Pain toward detecting behaviors and TTPs.

This involves leveraging frameworks like the MITRE ATT&CK explained for beginners, which provides a comprehensive knowledge base of adversary tactics and techniques. Instead of just asking "Is this bad file hash on my network?" security teams can ask "Is any process exhibiting behavior consistent with credential dumping, like Mimikatz?" This behavioral approach is much harder for attackers to evade.

This proactive defense is built on a foundation of strong cyber hygiene: - Comprehensive Logging and Monitoring: You can't detect what you can't see. Ensure robust logging from endpoints, servers, and network devices is being collected and analyzed. - Behavioral Analytics: Use tools like EDR and User and Entity Behavior Analytics (UEBA) to baseline normal activity and flag suspicious deviations. - Asset and Patch Management: Know what's on your network and keep it patched. Unpatched vulnerabilities are a primary entry point for attackers, negating the need for them to use novel techniques. - Strong Access Control: Enforce the principle of least privilege and mandate multi-factor authentication everywhere possible to make it harder for attackers to move laterally even if they gain an initial foothold.

Indicators of compromise remain a vital tool in the defender's arsenal. They are indispensable for incident response and threat hunting. However, they should be seen as the starting point, not the end goal, of a robust cybersecurity strategy that prioritizes understanding and disrupting attacker behavior.

Read next