Glossary · Term

Indicators of Compromise (IoCs) explained

Indicators of Compromise (IoCs) are technical signs of a compromise – suspicious IP addresses, file hashes or domains, for example.

At a glance
Meaning
Technical traces of an attack
Examples
IP addresses, file hashes, suspicious domains
Benefit
Detect and contain attacks
Related
Incident response, vulnerabilities
Updated
June 2026
Editorial team
Compliance Compass

What are IoCs?

Indicators of Compromise are concrete technical traces suggesting that a system has been attacked or already infiltrated. They are the forensic evidence of cyber defence: measurable artefacts a security team can find in logs, in network traffic or on endpoints. Unlike a mere suspicion, IoCs are verifiable – they can be fed into detection systems and matched automatically in order to confirm or rule out an Incident with certainty.

Typical IoCs

IoCs and incident response

IoCs are a central tool of Incident response: known indicators let you check whether an incident is under way, which systems are affected and how far an attack has already progressed. In the detection phase they give the first signal, in the analysis phase they help determine the extent. Keeping IoCs current matters, because attackers change infrastructure and tooling quickly.

Sharing strengthens everyone

If IoCs are shared – through CSIRTs or sector-wide networks, for example – other organisations can spot and fend off the same attack earlier. This coordinated exchange of information is an important idea behind NIS2, which promotes cooperation between entities and authorities. A typical case: a municipal utility receives a warning from its CSIRT with the IP addresses and file hashes of a new ransomware wave; the SOC feeds these IoCs straight into its firewall and EDR solution and thereby discovers a connection already running and unnoticed until then – before the encryption even starts.

Further reading: ENISA – the EU Agency for Cybersecurity (Threat Landscape)

Frequently asked questions

What are Indicators of Compromise?

Indicators of Compromise (IoCs) are concrete technical traces suggesting that a system has been attacked or already infiltrated – suspicious IP addresses, domains linked to malware, file hashes of known malware (SHA-256, for example) or unusual login and network patterns. Unlike a suspicion, IoCs are verifiable and can be fed into detection systems and matched automatically.

What are Indicators of Compromise used for?

Indicators of Compromise (IoCs) help security teams spot ongoing or past attacks, identify and contain affected systems quickly and improve defences with matching detection rules. They are a central tool of incident response: in the detection phase IoCs give the first signal, in the analysis phase they help determine the extent of an incident.

Why should you share Indicators of Compromise?

Shared Indicators of Compromise (IoCs) let other organisations spot and fend off the same attack earlier, before damage occurs. This coordinated exchange of information – often through CSIRTs or sector-wide networks – is an important idea behind NIS2, which promotes cooperation between entities and authorities across the Union. In this way IoCs strengthen collective cyber defence.

Detection

Attacks spotted early

Compliance Compass supports the detection and documentation of incidents – the basis for a fast response.