Definition

An indicator of compromise (IoC) is forensic data, such as a file hash or system log entry, that suggests potential or confirmed malicious activity on a network or system.

IoCs prove that a cybersecurity breach has occurred or is currently in progress. They are used in forensics, incident response, and malware defense to understand the threat environment better and boost an organization’s defenses.

Examples of Indicators of Compromise

Pros and Cons of Indicator of Compromise

Pros

Cons