Glossary
IOC
IOCs are fingerprints attackers leave behind - IP addresses they used, file hashes of their malware, domains they control. Security tools use IOCs to detect if the same attackers are in your network.
What is IOC?
Indicator of Compromise - forensic data that identifies potentially malicious activity, such as IP addresses, file hashes, or domain names.
Why Should You Care?
IOCs enable security teams to move from reactive incident response to proactive threat hunting—once forensic analysis identifies an attacker's infrastructure, that same IOC can be fed into detection tools to find other compromised systems before attackers escalate access. Without IOCs, each intrusion appears isolated; with them, disconnected breaches reveal coordinated campaigns, allowing teams to prioritize remediation efforts and prevent lateral movement across the network.
Is your business exposed?
Real-World Example
When the SolarWinds supply-chain attack was discovered in 2020, security researchers extracted IOCs such as command-and-control server addresses and malicious file hashes from the affected software. Organizations across government and private industry then searched their logs and network traffic for these same IOCs to determine if their systems had communicated with attacker infrastructure, turning a single discovered breach into a detection mechanism across thousands of networks.
How to Protect Against IOC
- 1.
Integrate threat intelligence IOCs into security tools
- 2.
Hunt for known IOCs in your environment
Related Terms
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required