Skip to main content
Threat IntelligenceUpdated September 3, 2026

IOC (Indicator of Compromise)

An indicator of compromise is an indicator supported by evidence of compromise or malicious activity. Security teams use IOCs to detect, contain, and investigate threats; an arbitrary IP address, domain, URL, file hash, or email address is only an observable until evidence supports that promotion.

The word that does the work in “indicator of compromise” is compromise. An IOC is not any suspicious-looking address or hash; it is an observable that evidence ties to an intrusion or to malicious activity: a C2 domain seen in beaconing traffic, a hash of a dropper recovered from a disk, an address that delivered a phishing kit.

That distinction matters operationally. A feed of every address that ever scanned a honeypot is a list of observables with a weak signal each. A feed of IOCs is a list of things a control should act on. Mixing the two is how a blocklist grows to a million entries and starts denying customers.

IOCs also age. A domain used for C2 in March is parked in June and sold in September; the indicator was true and stopped being true. Good intelligence records when the evidence was last seen and lets the confidence decay, so the IOC is retired before it becomes a false positive.

Example

Three observables from the same alert: a hash, a domain, an address. The hash matches a known infostealer build, the domain is its configured C2, and the address is a shared CDN edge. Two IOCs, one observable that stays context.

In isMalicious

A lookup on isMalicious tells the two apart. The report shows which sources list the observable, for what activity and when they last saw it, and the confidence level states how far the evidence supports calling it an IOC rather than a name that once appeared somewhere.

Frequently Asked Questions

What is IOC (Indicator of Compromise)?

An indicator of compromise is an indicator supported by evidence of compromise or malicious activity. Security teams use IOCs to detect, contain, and investigate threats; an arbitrary IP address, domain, URL, file hash, or email address is only an observable until evidence supports that promotion.

How is IOC (Indicator of Compromise) related to Observable?

IOC (Indicator of Compromise) and Observable are both key concepts in threat intelligence. An observable is a domain, IP address, URL, file hash, email address, phone number, or wallet address that can be examined during a security investigation. A submitted observable is not automatically malicious and is not automatically an indicator of compromise.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary