in SOC

2 Answers

by
IOC (indicator of compromise) it is proof of evidence that cyber attack has taken place in organization.
by

IOC stands for Indicator Of Compromise.

IOC serves as the forensic evidence of potential intrusion on a host system or network.

list of IOC's:

  • PUP
  • high CPU utilization
  • system abnormal behaviour
  • tampered file

