Threat Indicator
A threat indicator is an observable artifact associated with threat activity—such as a hash, domain, or IP—used as decision-support input after contextual validation, not as standalone proof of compromise.
Threat Indicator
Definition
A threat indicator (often IoC—indicator of compromise) is an observable artifact associated with threat activity—such as a file hash, domain, IP address, or email pattern.
Indicators are inputs to investigation and prioritization. A match suggests where to look; it is not synonymous with a Finding (KID-GLS-0008) or proof of active compromise until validated with evidence.
Usage discipline
| Indicator match means | Indicator match does not mean |
|---|---|
| Hunt or investigate | Incident declared |
| Possible relevance | Automatic remediation |
| Hypothesis trigger | Replacement for risk analysis |
Related terms
- Threat Intelligence —
KID-GLS-0005 - Finding —
KID-GLS-0008
Related knowledge
- Threat Intelligence vs Detection —
KID-CON-0051