- Meaning
- Technical traces of an attack
- Examples
- IP addresses, file hashes, suspicious domains
- Benefit
- Detect and contain attacks
- Related
- Incident response, vulnerabilities
- Updated
- June 2026
- Editorial team
- Compliance Compass
What are IoCs?
Indicators of Compromise are concrete technical traces suggesting that a system has been attacked or already infiltrated. They are the forensic evidence of cyber defence: measurable artefacts a security team can find in logs, in network traffic or on endpoints. Unlike a mere suspicion, IoCs are verifiable – they can be fed into detection systems and matched automatically in order to confirm or rule out an Incident with certainty.
Typical IoCs
- Suspicious IP addresses and domains that malware communicates with
- File hashes (SHA-256, for example) of known malware
- Unusual login, sign-in or network patterns
- Conspicuous registry changes or unknown running processes
IoCs and incident response
IoCs are a central tool of Incident response: known indicators let you check whether an incident is under way, which systems are affected and how far an attack has already progressed. In the detection phase they give the first signal, in the analysis phase they help determine the extent. Keeping IoCs current matters, because attackers change infrastructure and tooling quickly.
Sharing strengthens everyone
If IoCs are shared – through CSIRTs or sector-wide networks, for example – other organisations can spot and fend off the same attack earlier. This coordinated exchange of information is an important idea behind NIS2, which promotes cooperation between entities and authorities. A typical case: a municipal utility receives a warning from its CSIRT with the IP addresses and file hashes of a new ransomware wave; the SOC feeds these IoCs straight into its firewall and EDR solution and thereby discovers a connection already running and unnoticed until then – before the encryption even starts.
Further reading: ENISA – the EU Agency for Cybersecurity (Threat Landscape)
Frequently asked questions
What are Indicators of Compromise?
Indicators of Compromise (IoCs) are concrete technical traces suggesting that a system has been attacked or already infiltrated – suspicious IP addresses, domains linked to malware, file hashes of known malware (SHA-256, for example) or unusual login and network patterns. Unlike a suspicion, IoCs are verifiable and can be fed into detection systems and matched automatically.
What are Indicators of Compromise used for?
Indicators of Compromise (IoCs) help security teams spot ongoing or past attacks, identify and contain affected systems quickly and improve defences with matching detection rules. They are a central tool of incident response: in the detection phase IoCs give the first signal, in the analysis phase they help determine the extent of an incident.
Why should you share Indicators of Compromise?
Shared Indicators of Compromise (IoCs) let other organisations spot and fend off the same attack earlier, before damage occurs. This coordinated exchange of information – often through CSIRTs or sector-wide networks – is an important idea behind NIS2, which promotes cooperation between entities and authorities across the Union. In this way IoCs strengthen collective cyber defence.