Differentiating between IoC , IaC and indicators of fraud
ID: 09ba9ab9-18cb-5ee2-ae4b-262dbc4d23fe
STIX ID: report--09ba9ab9-18cb-5ee2-ae4b-262dbc4d23fe
Feed Name: Detect FYI
This article explains the distinctions between Indicators of Attack (proactive behavioral signs), Indicators of Compromise (post-breach artifacts), and fraud indicators (financially motivated anomalies), and provides practical Microsoft Defender XDR/KQL queries to detect each. It includes examples such as detecting renamed PowerShell, excessive SMTP, LOLBAS/base64 commands, RDP/C2 behaviors, malicious hashes/IPs/domains, registry tampering, log clearing, high-risk ASN phishing, and impossible-travel logins, helping teams move from static IOC matching to behavior-led threat hunting and fraud monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
