IOC tracking
Publish indicators only with sufficiently clear sources, timestamps and context.
Hash
A hash needs its algorithm, sample source and observation time.
- Value
- —
- Source / last seen
- —
- Status
- Not released
Domain
A domain needs a role, observation time and a fresh ownership assessment.
- Value
- —
- Source / last seen
- —
- Status
- Not released
IP
An IP address needs context; historical data must not automatically become a blocking rule.
- Value
- —
- Source / last seen
- —
- Status
- Not released
File artifact
File artifacts need a path, collection source and relationship to the event.
- Value
- —
- Source / last seen
- —
- Status
- Not released
Registry
Registry keys and values need process and environment context.
- Value
- —
- Source / last seen
- —
- Status
- Not released
URL
URLs are defanged when needed. Do not automatically visit suspected malicious links.
- Value
- —
- Source / last seen
- —
- Status
- Not released
Filename
Filenames have low specificity; corroborate behavior and hashes.
- Value
- —
- Source / last seen
- —
- Status
- Not released
Extension
An extension is a lead, not a family conclusion.
- Value
- —
- Source / last seen
- —
- Status
- Not released
A released record needs type, value, source, time, confidence, observation context and update history.
IOC types
Hashes, domains, IPs, URLs, mutexes, service names, file paths and log indicators.
Using IOCs safely
Do not execute samples or upload suspected malware to public services when it contains sensitive data.
Link context
Correlate IOCs with related ransomware families and TTPs.
Threat IntelligenceIncident responseSources
Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.