Indicators Of Compromise (IoC) Flashcards
What is IoC?
Indicators Of Compromise
Data pieces that detect potential malicious activity on a network or system
What is Account Lockout?
Example of IoC
Signals a compromise when its triggered by numerous failed log in attempts
What is Concurrent Session Usage?
Example of IoC
One user having multiple active sessions
What is Blocked Content?
Example of IoC
When a user attempts to access or download content that has been blocked by security protocol.
What is Impossible Travel?
Example of IoC
When suspicious logins occur from distant locations in a timeframe that doesnt make physical sense
What is Resource Consumption?
Example of IoC
Unusual resource spikes can signal a compromise
What is Resource Inaccessibility?
Example of IoC
The inability to access certain resources such as files, databases, or network services.
What is Out-of-Cycle Loggin?
Example of IoC
log entries that occur at unusual times when no one is supposed to be active
What are Missing Logs?
Example of IoC
Attackers delete logs to cover their tracks and hinder investigations
What are Articles or Documents on Security Breach?
Example of IoC
Attackers may publicly announce their hacks to brag about their abilities or harm the organizations