Use indicators of compromise as contextual clues by separating observable values, supporting evidence, hypotheses, scope, decay, and validation.
What you will be able to do
- Distinguish indicator value from observable evidence in a realistic indicators of compromise case.
- Interpret the evidence and boundary associated with context and scope.
- Choose an appropriate action involving investigation hypothesis without exceeding the stated authority.
- Verify decay and validation through an observable result and a documented handoff.
01
Frame Indicators of Compromise
Use indicators of compromise as contextual clues by separating observable values, supporting evidence, hypotheses, scope, decay, and validation.
A threat report lists a file hash, domain, and process name seen during an intrusion. The analyst must search safely without assuming every match proves the same compromise.
Keep observed facts, working assumptions, authorized actions, safety boundaries, and expected evidence separate. Begin with read-only inspection and preserve the context another analyst needs to reproduce the decision.
02
Indicator Value
An indicator is a value or pattern associated with activity that may warrant investigation. Within indicators of compromise, this concept answers a separate question and should retain its own evidence.
Record the exact value, type, source, first seen, last seen, and handling limits. Apply that action to the named case before expanding the investigation or changing protected state.
Respect this boundary: do not alter case, encoding, or structure while copying the value. The required result is specific: the indicator is searchable and traceable to its source.
03
Observable Evidence
An observable is a measured event or state such as a connection, file, process, account action, or registry change. Within indicators of compromise, this concept answers a separate question and should retain its own evidence.
Preserve the matching event, host, user, time, path, and collection source. Apply that action to the named case before expanding the investigation or changing protected state.
Respect this boundary: do not report a match without the surrounding observable. The required result is specific: another analyst can reproduce the match from protected evidence.
04
Context and Scope
Indicator context describes where a value mattered, what behavior accompanied it, and how broadly it may apply. Within indicators of compromise, this concept answers a separate question and should retain its own evidence.
Compare environment, period, technology, and activity with the current case. Apply that action to the named case before expanding the investigation or changing protected state.
Respect this boundary: do not block a shared service from an old report without current impact analysis. The required result is specific: the scope explains which systems and period require review.
05
Investigation Hypothesis
A hypothesis explains how the indicator could connect to the observed activity and predicts what else should exist. Within indicators of compromise, this concept answers a separate question and should retain its own evidence.
Write a safe search or test that could support or weaken the explanation. Apply that action to the named case before expanding the investigation or changing protected state.
Respect this boundary: do not treat the hypothesis as a final incident conclusion. The required result is specific: the next evidence changes confidence in a stated explanation.
06
Decay and Validation
Indicator value can decay as infrastructure changes, benign reuse grows, or the original context expires. Within indicators of compromise, this concept answers a separate question and should retain its own evidence.
Track validity, false positives, review date, and removal criteria. Apply that action to the named case before expanding the investigation or changing protected state.
Respect this boundary: do not leave temporary blocks active without an owner and expiry. The required result is specific: expired indicators are removed or renewed with current evidence.
07
Apply Indicators of Compromise to One Case
Use the case as a bounded investigation: A threat report lists a file hash, domain, and process name seen during an intrusion. The analyst must search safely without assuming every match proves the same compromise.
First, record the exact value, type, source, first seen, last seen, and handling limits. Then, preserve the matching event, host, user, time, path, and collection source. Keep both observations in the case record before choosing the next step.
Next, compare environment, period, technology, and activity with the current case. After that, write a safe search or test that could support or weaken the explanation. Finish only after you track validity, false positives, review date, and removal criteria.
08
Recap Before Practice and Prove
Indicator Value: An indicator is a value or pattern associated with activity that may warrant investigation. In practice, record the exact value, type, source, first seen, last seen, and handling limits. Preserve the boundary: do not alter case, encoding, or structure while copying the value.
Observable Evidence: An observable is a measured event or state such as a connection, file, process, account action, or registry change. In practice, preserve the matching event, host, user, time, path, and collection source. Preserve the boundary: do not report a match without the surrounding observable.
Context and Scope: Indicator context describes where a value mattered, what behavior accompanied it, and how broadly it may apply. In practice, compare environment, period, technology, and activity with the current case. Preserve the boundary: do not block a shared service from an old report without current impact analysis.
Investigation Hypothesis: A hypothesis explains how the indicator could connect to the observed activity and predicts what else should exist. In practice, write a safe search or test that could support or weaken the explanation. Preserve the boundary: do not treat the hypothesis as a final incident conclusion.
Decay and Validation: Indicator value can decay as infrastructure changes, benign reuse grows, or the original context expires. In practice, track validity, false positives, review date, and removal criteria. Preserve the boundary: do not leave temporary blocks active without an owner and expiry.