Indicators of Attack Vs. Indicators of Compromise - CrowdStrike
文章推薦指數: 80 %
An IOC is often described in the forensics world as evidence on a computer that indicates that the security of the network has been compromised. Investigators ... WhitePaper | ResourceCenter IndicatorsofAttackvs.IndicatorsofCompromise Formanyyears,theinformationsecuritycommunityhasreliedonindicatorsofcompromise(IOC)asthefirstindicationthatasystemororganizationhasbeenbreached.AnIOCisoftendescribedintheforensicsworldasevidenceonacomputerthatindicatesthatthesecurityofthenetworkhasbeencompromised.Investigatorsusuallygatherthisdataafterbeinginformedofasuspiciousincident,onascheduledbasis,orafterthediscoveryofunusualcall-outsfromthenetwork.Ideally, thisinformationisgatheredtocreate“smarter”toolsthatcandetectandquarantinesuspiciousfilesinthefuture. Unfortunately,IOCmonitoringisreactiveinnature,whichmeansthatifanorganizationfindsanindicator,itisalmostcertainthattheyhavealreadybeencompromised. AnIndicatorofAttack(IOA)isrelatedtoanIOCinthatitisadigitalartifact.However,unlikeIOCs,IOAsareactiveinnatureandfocusonidentifyingacyberattackthatisinprocess. DownloadthiswhitepapertobetterunderstandthefundamentaldifferencebetweenIndicatorsofCompromiseandIndicatorsofAttackandlookatIOAsinaction. LatestWhitePapers 4EssentialsWhenSelectingCybersecuritySolutions eBook:SecuringGoogleCloudwithCrowdStrike FiveQuestionstoAskBeforeChoosingSentinelOneforWorkforceIdentityProtection DiscoverMoreatourResourceCenter CaseStudies CommunityTools CrowdCasts DataSheets Demos Guides Infographics Reports Videos WhitePapers TECHNICALCENTER Fortechnicalinformationoninstallation,policyconfigurationandmore,pleasevisittheCrowdStrikeTechCenter. VisittheTechCenter
延伸文章資訊
- 1What are Indicators of Compromise (IOCs)? - UpGuard
- 2What Are Indicators of Compromise (IoC) | Proofpoint US
During a cybersecurity incident, indicators of compromise (IoC) are clues and evidence of a data ...
- 3資安分析師的日常 - iThome
他所在的SOC團隊位於隸屬於公部門組織,使用RiskIQ PassiveTotal調查入侵指標(Indicators of Compromise,IOC),透過PassiveTotal,他們在回...
- 4What are Indicators of Compromise? | Digital Guardian
Indicators of compromise act as breadcrumbs that lead infosec and IT pros to detect malicious act...
- 5Indicators of Attack Vs. Indicators of Compromise - CrowdStrike
An IOC is often described in the forensics world as evidence on a computer that indicates that th...