Indication of Compromise (IoC)
A piece of observable evidence that suggests malicious or unauthorized activity has occurred. In cybersecurity, IoCs include artifacts such as malicious IP addresses, domains, file hashes, or unusual network activity. In digital information environments, indicators of compromise may also include coordinated behavioral patterns, synchronized account activity, artificial amplification, or other signals that suggest an organized influence operation.
Why is it important?
Indicators of Compromise provide early evidence that a coordinated threat may be underway. While a single indicator rarely confirms malicious activity, multiple correlated signals can reveal influence campaigns, coordinated inauthentic behavior, or other digital risks before they escalate. By identifying and connecting these indicators, Cyabra helps organizations investigate suspicious activity more efficiently, prioritize meaningful threats, and make informed, proportionate decisions based on evidence rather than isolated events.