{
  "number": 9424,
  "title": "Indicators of Compromise (IoCs) and Their Role in Attack Defence",
  "authors": [
    "K. Paine",
    "O. Whitehouse",
    "J. Sellwood",
    "A. Shaw"
  ],
  "published": "2023-08",
  "status": "Informational",
  "stream": "IETF",
  "area": "ops",
  "working_group": "opsec",
  "pages": 24,
  "formats": [
    "HTML",
    "TXT",
    "PDF",
    "XML"
  ],
  "abstract": "Cyber defenders frequently rely on Indicators of Compromise (IoCs) to identify, trace, and block malicious activity in networks or on endpoints. This document reviews the fundamentals, opportunities, operational limitations, and recommendations for IoC use. It highlights the need for IoCs to be detectable in implementations of Internet protocols, tools, and technologies -- both for the IoCs' initial discovery and their use in detection -- and provides a foundation for approaches to operational challenges in network security.",
  "keywords": [
    "IOC",
    "Attack Defence"
  ],
  "draft": "draft-ietf-opsec-indicators-of-compromise-04",
  "doi": "10.17487/RFC9424",
  "errata_url": "https://www.rfc-editor.org/errata/rfc9424",
  "urls": {
    "html": "https://rfc.dk/rfc9424/",
    "text": "https://rfc.dk/rfc9424.txt",
    "rfc_editor": "https://www.rfc-editor.org/rfc/rfc9424",
    "datatracker": "https://datatracker.ietf.org/doc/rfc9424/"
  },
  "text_modified": "2023-08-12T03:59:41.629492979Z"
}
