Observable and behavior
An indicator of compromise is an artifact or observable that suggests attack or compromise, such as a domain, address, file hash, account change, process, certificate, or request pattern. Tactics describe adversary goals, techniques describe how goals are achieved, and procedures describe specific observed implementations.
Durability and context
Hashes and addresses can be precise and easy for an adversary to change. Behavioral detections can survive infrastructure change and can be less precise. Record the indicator type, source, first and last seen, confidence, scope, related behavior, expected benign use, and expiration.
An indicator without local asset and time context can create false confidence or block shared infrastructure.
Detection and response use
Use exact indicators for retrospective search, enrichment, and time-bounded blocking where false-positive cost is acceptable. Use TTPs to form hypotheses across identity, process, network, cloud, application, and policy events. Combine independent signals and validate on real local data.
Record what response follows a match. A match that no one can investigate or contain is not a complete control.
Failure and residual risk
Attackers can poison public feeds, reuse benign services, rotate infrastructure, or imitate expected behavior. Broad technique mappings can make a detection appear comprehensive when it sees only one narrow procedure. Missing an indicator does not clear a system.
Behavior changes and legitimate administrators can perform attacker-like actions. Detection needs identity, asset, change, and purpose context.
Pomerium boundary
Pomerium access logs can show identity, route, decision, and selected request context for covered traffic. They cannot supply host process, endpoint, direct-origin, or final application-object evidence. Map external indicators and TTPs only to fields that the deployed sources actually observe.
Evaluation checklist
- Is this an observable indicator, a tactic, a technique, or a specific procedure?
- What source, confidence, local scope, time range, benign use, and expiration apply?
- Which owned data source can observe the behavior with the required fidelity?
- Does a match produce a defined enrichment, triage, containment, and recovery action?
- Which alternate procedure or unobserved path remains outside the detection?
