Common examples
Typical IoCs include connections to IP addresses or domains linked to attackers, hashes of known malware files, suspicious email senders or subjects, unexpected scheduled tasks or services, logins from impossible locations and large data transfers at unusual times.
IoCs vs indicators of attack
IoCs describe evidence that something has already happened and are easy for attackers to change: a new domain or a recompiled file is enough to avoid them. Indicators of attack (IoAs) describe behaviour, such as a document opening a command line or credentials being dumped from memory, and help detect new attacks that have no known IoC yet. Modern detection uses both.
How they are used
IoCs arrive through threat intelligence feeds, CERT advisories and incident reports, and are loaded into the SIEM, EDR and firewalls. When a new campaign is published, the SOC searches past logs for its IoCs to check whether the company was already affected, which is why keeping logs long enough matters.
Sharing
Sharing IoCs with peers and authorities helps others defend themselves. National CERTs such as INCIBE-CERT and CCN-CERT publish them regularly.




