IOC (Indicator of Compromise)
An indicator of compromise is an indicator supported by evidence of compromise or malicious activity. Security teams use IOCs to detect, contain, and investigate threats; an arbitrary IP address, domain, URL, file hash, or email address is only an observable until evidence supports that promotion.
The word that does the work in “indicator of compromise” is compromise. An IOC is not any suspicious-looking address or hash; it is an observable that evidence ties to an intrusion or to malicious activity: a C2 domain seen in beaconing traffic, a hash of a dropper recovered from a disk, an address that delivered a phishing kit.
That distinction matters operationally. A feed of every address that ever scanned a honeypot is a list of observables with a weak signal each. A feed of IOCs is a list of things a control should act on. Mixing the two is how a blocklist grows to a million entries and starts denying customers.
IOCs also age. A domain used for C2 in March is parked in June and sold in September; the indicator was true and stopped being true. Good intelligence records when the evidence was last seen and lets the confidence decay, so the IOC is retired before it becomes a false positive.
Example
Three observables from the same alert: a hash, a domain, an address. The hash matches a known infostealer build, the domain is its configured C2, and the address is a shared CDN edge. Two IOCs, one observable that stays context.
In isMalicious
A lookup on isMalicious tells the two apart. The report shows which sources list the observable, for what activity and when they last saw it, and the confidence level states how far the evidence supports calling it an IOC rather than a name that once appeared somewhere.
Frequently Asked Questions
What is IOC (Indicator of Compromise)?
An indicator of compromise is an indicator supported by evidence of compromise or malicious activity. Security teams use IOCs to detect, contain, and investigate threats; an arbitrary IP address, domain, URL, file hash, or email address is only an observable until evidence supports that promotion.
How is IOC (Indicator of Compromise) related to Observable?
IOC (Indicator of Compromise) and Observable are both key concepts in threat intelligence. An observable is a domain, IP address, URL, file hash, email address, phone number, or wallet address that can be examined during a security investigation. A submitted observable is not automatically malicious and is not automatically an indicator of compromise.
Related Terms
Observable
An observable is a domain, IP address, URL, file hash, email address, phone number, or wallet address that can be examined during a security investigation. A submitted observable is not automatically malicious and is not automatically an indicator of compromise.
Indicator
An indicator is an observable whose evidence makes it relevant to a security investigation or detection. It becomes an indicator of compromise only when the evidence supports compromise or malicious activity.
TTP (Tactics, Techniques, and Procedures)
TTPs describe the behavior of threat actors: the high-level goals they pursue (tactics), the specific methods they use to achieve those goals (techniques), and the detailed, repeatable actions that implement those methods (procedures). The MITRE ATT&CK framework catalogues TTPs used by real adversaries.
Threat Intelligence
Threat intelligence is evidence-based knowledge about cyber threats, including observed infrastructure, behaviors, campaigns, and likely intent. It combines source observations with context so security teams can make a specific detection, triage, containment, or response decision.
Threat Feed
A threat feed is a structured, continuously updated stream of IOCs and threat data from a single source or aggregator. Security tools ingest threat feeds to keep blocklists and detection rules current. Examples include Spamhaus DROP, abuse.ch URLhaus, and CISA KEV.
Put this intelligence to work
Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.