Threat Indicator

A threat indicator is an observable artifact associated with threat activity—such as a hash, domain, or IP—used as decision-support input after contextual validation, not as standalone proof of compromise.

Threat Indicator

Definition

A threat indicator (often IoC—indicator of compromise) is an observable artifact associated with threat activity—such as a file hash, domain, IP address, or email pattern.

Indicators are inputs to investigation and prioritization. A match suggests where to look; it is not synonymous with a Finding (KID-GLS-0008) or proof of active compromise until validated with evidence.

Usage discipline

Indicator match means Indicator match does not mean
Hunt or investigate Incident declared
Possible relevance Automatic remediation
Hypothesis trigger Replacement for risk analysis

Related terms

Related knowledge


Related Articles