Indicator of Attack
Also known as:IoA
Indicator of Attack: A behavioral pattern indicating ongoing or preparatory attack activity. This capability processes information about threats and attackers into actionable insights. Source evaluationSource EvaluationAssessment of a source's reliability, relevance, timeliness, and potential bias., context, currency, structured dissemination, and feedback into protective measures determine the utility.
How it works and where it fits
Indicator of Attack connects data sources to detection or assessment logic. Raw records become security-relevant only when timing, identity, system context, and expected behavior are considered. Rules, correlations, statistical models, and analyst decisions may work together; no single method reliably covers every attack pattern.
Practical security relevance
Operational quality is reflected in coverage, data completeness, detection time, and false-alert workload. Data sources need owners, time synchronization, retention, and quality controls. Detections should be tested, versioned, and improved using real incidents. Every meaningful alert also requires triage guidance, escalation, and possible response actions.
Related concepts
- Threat HuntingThreat HuntingSearches for previously undetected attacker activity based on hypotheses.: Searches for previously undetected attacker activity based on hypotheses.
- Detection EngineeringDetection EngineeringSystematic development, testing, and maintenance of rules for attack detection.: Systematic development, testing, and maintenance of rules for attack detection.
- Security Information and Event ManagementSecurity Information and Event ManagementCollects and correlates security events for monitoring, alerting, and evidence gathering.: Collects and correlates security events for monitoring, alerting, and evidence gathering.
- Security Operations CenterSecurity Operations CenterA central function for the continuous monitoring, analysis, and response to security events.: A central function for the continuous monitoring, analysis, and response to security events.