End of Life of an Indicator of Compromise (IOC)
ID: 306046e8-5a19-5987-8f19-4610e9e2e6b0
STIX ID: report--306046e8-5a19-5987-8f19-4610e9e2e6b0
Feed Name: Dragos Blog
This blog post provides operational guidance on using Indicators of Compromise (IOCs), explaining that while hashes, IPs, and domains can all aid detection, they differ in stability and utility: file hashes are highly specific and long-lived, IP addresses are time-sensitive, and domains are often persistent but context-dependent. It outlines how IOCs can be 'burned' by public reporting or blocking and recommends prioritizing behavior-based detections, building trusted indicator sources, automating ingestion and weekly scans, applying date filters (especially for IPs), and triaging matches using confidence, last-seen, and threat-context questions to reduce alert fatigue and improve SOC effectiveness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
