Malware
Indicator of compromise
Also called IOC.
Indicator of compromise is a concrete fact you can search for that says an attack touched a system: a file hash, a domain, an IP address, a registry key, or an odd user account. Teams share them so others can look for the same traces.
How it is measured
An IOC is a value plus context: type, value, first seen, and confidence. You use it by searching logs, files, and DNS history for the exact value. A hit is a lead, not a verdict.
Count how many IOCs you checked and how many matched. Keep age in mind, because IP addresses and domains rotate within days.
Worked example
A security note lists three IOCs from a campaign against WordPress sites: a file named `wp-feed.php` in the uploads folder with SHA-256 `3fa1…`, a callback domain `api-wpcache.top`, and a new admin user called `wpadmin_sys`. An agency checks its 18 sites.
Two have `wpadmin_sys` and one also has the file. The third match is on logs showing a request to `api-wpcache.top` from the server.
How it differs
An IOC is a clue left by an attack. A file hash is one type of IOC, narrow and exact. The Tarsier Threat Index is a list of hostile hosts, which means its entries behave like host-type IOCs. An IOC says something happened; it does not say how severe it was or whether it is still happening.
Common errors
Treating an old IP as current. Matching on partial strings. Stopping at the first match. Clearing the indicator without finding the cause. Collecting feeds nobody reads. Assuming absence of IOCs means absence of compromise.
In practice
When you read a security report, extract its IOCs and search your logs and files for each one the same day. Note the date. A match means isolate and investigate, not merely delete.