Skip to main content

Indicator of Compromise and TTP

Distinguish short-lived technical observables from adversary tactics, techniques, and procedures used to build more durable detection and response.

Observable and behavior

An indicator of compromise is an artifact or observable that suggests attack or compromise, such as a domain, address, file hash, account change, process, certificate, or request pattern. Tactics describe adversary goals, techniques describe how goals are achieved, and procedures describe specific observed implementations.

Durability and context

Hashes and addresses can be precise and easy for an adversary to change. Behavioral detections can survive infrastructure change and can be less precise. Record the indicator type, source, first and last seen, confidence, scope, related behavior, expected benign use, and expiration.

An indicator without local asset and time context can create false confidence or block shared infrastructure.

Detection and response use

Use exact indicators for retrospective search, enrichment, and time-bounded blocking where false-positive cost is acceptable. Use TTPs to form hypotheses across identity, process, network, cloud, application, and policy events. Combine independent signals and validate on real local data.

Record what response follows a match. A match that no one can investigate or contain is not a complete control.

Failure and residual risk

Attackers can poison public feeds, reuse benign services, rotate infrastructure, or imitate expected behavior. Broad technique mappings can make a detection appear comprehensive when it sees only one narrow procedure. Missing an indicator does not clear a system.

Behavior changes and legitimate administrators can perform attacker-like actions. Detection needs identity, asset, change, and purpose context.

Pomerium boundary

Pomerium access logs can show identity, route, decision, and selected request context for covered traffic. They cannot supply host process, endpoint, direct-origin, or final application-object evidence. Map external indicators and TTPs only to fields that the deployed sources actually observe.

Evaluation checklist

  • Is this an observable indicator, a tactic, a technique, or a specific procedure?
  • What source, confidence, local scope, time range, benign use, and expiration apply?
  • Which owned data source can observe the behavior with the required fidelity?
  • Does a match produce a defined enrichment, triage, containment, and recovery action?
  • Which alternate procedure or unobserved path remains outside the detection?

Sources and further reading

Keep learning

Security Operations and Risk

Cyber Threat Intelligence

Turn evaluated information about adversaries, behavior, infrastructure, vulnerabilities, and incidents into a time-bounded security decision.

Learn this term
Security Operations and Risk

MITRE ATT&CK

MITRE ATT&CK catalogs observed adversary tactics and techniques that can guide hypotheses, detections, and investigations.

Learn this term
Security Operations and Risk

Security Telemetry

Security telemetry uses logs, metrics, traces, and events to answer defined detection, investigation, and control questions.

Learn this term
Security Operations and Risk

Detection Quality

Evaluate whether a detection observes the intended behavior with useful fidelity, timeliness, coverage, context, response, and manageable error.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo