Skip to content
Glossary

What are IOCs?

IOCs, short for Indicators of Compromise, are technical clues or digital traces that indicate a security breach or cyber attack. They are used to detect, analyze and respond to suspicious activities.

Typical IOCs are, for example, suspicious IP addresses, hash values of infected files, conspicuous domain names, unusual logins, manipulated registry entries or certain patterns in network traffic. They are used to identify compromised systems, trace attack paths and initiate suitable countermeasures.

As part of darknet monitoring or incident response processes, IOCs help to understand whether and how an attacker has already gained access to systems. They can be fed into security systems such as firewalls, endpoint detection tools or SIEM platforms in order to automatically detect and block attacks.

IOCs are therefore a central tool in the field of cyber defense. They enable security teams to react faster, stop the spread of attacks and prevent further damage.

 

 

Infographic listing examples of indicators of compromise (IOCs) in cybersecurity, including unusual network traffic, suspicious activity, and anomalies in various system areas.