Tuesday 14 July 2026 23:33:57 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

WIKICROOK

IOC (Indicator of Compromise)

A technical clue, such as a hash or IP address, used to detect malicious activity.

An IOC is a technical artifact that can suggest malicious activity, such as a file hash, IP address, domain name, email address, registry key, or URL. Security teams use IOCs to search logs, endpoints, and network traffic for known signs of intrusion.

IOCs matter because they turn a suspicion into something measurable. In ransomware and extortion cases, a hash-like string or suspicious domain may help defenders correlate a public claim with real activity. But an IOC is not proof by itself: a single IP or hash can be reused, spoofed, or unrelated. Good defense combines IOCs with context from authentication logs, endpoint telemetry, and cloud audit trails. That helps confirm whether an alert is a true compromise, a false alarm, or only a public claim.

← WIKICROOK index