logo

Differentiating between IoC , IaC and indicators of fraud

ID: 09ba9ab9-18cb-5ee2-ae4b-262dbc4d23fe

STIX ID: report--09ba9ab9-18cb-5ee2-ae4b-262dbc4d23fe

Feed Name: Detect FYI

Date Published: 2025-06-16

Date Updated: 2026-04-19

Author: Sergio Albea

...
...

This article explains the distinctions between Indicators of Attack (proactive behavioral signs), Indicators of Compromise (post-breach artifacts), and fraud indicators (financially motivated anomalies), and provides practical Microsoft Defender XDR/KQL queries to detect each. It includes examples such as detecting renamed PowerShell, excessive SMTP, LOLBAS/base64 commands, RDP/C2 behaviors, malicious hashes/IPs/domains, registry tampering, log clearing, high-risk ASN phishing, and impossible-travel logins, helping teams move from static IOC matching to behavior-led threat hunting and fraud monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.