travel_exploreOSINTGuide
Category: Identifiers & artifacts

Indicator of Compromise (IOC)

indicators of compromiseioc

A piece of forensic evidence — an IP, domain, file hash, or URL — that signals a system may have been breached and can be used to detect or track malicious activity.

An indicator of compromise is an observable artefact that suggests a system has been attacked or is behaving maliciously: a suspicious IP address or domain, a file hash for a piece of malware, a URL used for command-and-control, or a distinctive registry key. IOCs are the shareable, machine-readable breadcrumbs of an intrusion — the concrete details defenders exchange so that if one organisation sees an attack, others can recognise it too.

In threat intelligence, IOCs are the raw currency: they feed detection rules, block-lists, and hunts. For an OSINT analyst they are also pivots — a single malicious domain or hash, looked up across public feeds, can expose an attacker's wider infrastructure and help with attribution. Their weakness is that they are easily changed, which is why they are paired with more durable behavioural analysis.

Related terms