About IOCs

Indicators of Compromise (IOCs) are pieces of evidence that suggest a security breach or malicious activity has occurred on a network or system. They help cybersecurity professionals identify, detect, and respond to potential threats by providing clues about malicious activity.

Examples of Good IOCs

Examples of Poor IOCs

IOC Database Fields

Below are the default fields, and their meanings, tied to an IOC in the Incident Management System.

Metadata

Correlations

<aside> 💡

These fields are populated automatically. Read more about the correlation capabilities of the Incident Management System: Correlations

</aside>