Indicators of Compromise
Indicators of Compromise (IOCs) are pieces of digital evidence that suggest an organization's network, system, or endpoint may have been attacked or breached. They act as clues that security teams look for to determine whether an attack is imminent, currently happening, or has already occurred. Finding an IOC signals that further investigation may be needed to confirm whether a compromise has taken place.
An Indicator of Compromise (IOC) is a technical artifact or observable that suggests an attack is imminent, is currently underway, or that a compromise may have already occurred. IOCs are generally used as forensic and detection evidence to identify potential breaches of networks, systems, or endpoints. As reflected in the evidence, IOCs are commonly distinguished from Indicators of Attack (IoA), which are used to determine whether an attack is actively ongoing; practitioners should confirm the precise scope and usage of these terms against current authoritative sources, as vendor and framework definitions may vary.
Why it matters
Indicators of Compromise are foundational to threat detection and incident response because they give security teams concrete, observable evidence to act on rather than relying on suspicion alone. When an organization can recognize the digital artifacts left behind by an attacker, it can move more quickly to investigate, contain, and remediate a potential breach. For defense and public sector environments, where systems may process Controlled Unclassified Information (CUI) or operate under the DoD Risk Management Framework, timely recognition of IOCs supports the continuous monitoring expectations that accompany an Authority to Operate (ATO) and helps demonstrate that security is being actively maintained rather than treated as a one-time checkbox.
Who it's relevant to
Inside IOC
Common questions
Answers to the questions practitioners most commonly ask about IOC.