乐播传媒app最新版本

Articles
8/9/2022
5 minutes

A Comprehensive Indicators of Compromise List to Detect and Prevent Threats

Table of contents

Indicators of Compromise, or IOCs, are warning signs that malicious actors have breached your network. In DevSecOps environments, IOCs help detect and stop an attack in progress or aid foresnic investigation of a breach that’s already occurred. In the latter application, IOCs are invaluable for preventing a similar breach from succeeding in the future. Below is a “common indicators of compromise list” that you can use to detect, investigate, and prevent threats to your network.

A Comprehensive Indicators of Compromise List

The most common indicators of compromise include:

Abnormal Network Traffic

Unusual outbound network traffic is a sign that something is amiss. If you’re seeing more outbound connections than is typical for that time of night or a larger-than-normal quantity of data leaving your network, that’s a potential IOC. Both indicators mean that attackers are likely exfiltrating valuable data from your network.

On the inbound side, attackers often use tools like Netcat to direct their traffic to any accessible port, even obscure ones. If you see any application activity on ports that typically aren’t used, that’s a potential sign of compromise.

Anomalous DNS Requests

Malware that is used to penetrate networks and open backdoors will often contact a Command and Control (C&C) server to initiate data exfiltration. To accomplish this, the malware needs to call upon your DNS resolver to request the location of the malicious C&C server.?

Signs of anomalous DNS requests include:

  • Weird domain names that have apparent misspellings or look like random keystrokes (e.g., wajjrrpl.com).
  • A large number of DNS queries from many different blacklisted domains interspersed with successful requests from weird domain names. This scenario indicates the usage of a Domain Generation Algorithm (DGA), which is used to bypass reputation filters.
  • On that note, any suspiciously large volume of DNS requests – especially to unusual domain names or during odd hours.

DDoS Attacks

Distributed Denial of Service attacks (DDoS attacks) involve flooding a service with traffic to overwhelm it and shut it down. Malicious actors frequently use DDoS attacks to disguise their true intentions and camouflage data exfiltration. Signs of a DDoS attack, such as slow network performance or service unavailability, are thus an obvious indicator of compromise.

Unusual Login Activity

User login activity follows predictable patterns, so any unusual behavior is a red flag.?

Examples include:

  • Geography: If a user lives and works in one region, but their account logs in from another country, that could mean the account has been compromised by a foreign attacker or a hacker using a VPN.
  • Unsuccessful Attempts: An account failing to log on many times is a clear sign that someone is trying to penetrate your network. Another signal is failed login attempts from accounts that don’t exist in your system.
  • Unusual Endpoints: Most users always access the network from the same device(s), so if, for example, the receptionist’s account logs on from an accounting workstation, that’s an indicator of compromise.
  • Time: Most people work a similar schedule every day. So, if an account accesses your network at an unusual time, it might be compromised.

Abnormal Privileged Account Activity

Privileged accounts typically have access to restricted network resources and sensitive data, so hackers frequently target them for compromise. If a privileged account behaves abnormally on the network – for example, elevating the privileges of other accounts seemingly at random or being used to access a large volume of sensitive data outside of their normal job functions – is another clear indicator of compromise.

Spikes in Database Read Volume

Hackers often target databases because they’re likely to contain the most sensitive and valuable information. Suspicious spikes in database read volume, particularly at odd times, indicate that a malicious actor may be accessing that data.

Repeated Requests for Same File

Generally, when an employee tries to open a file they don’t have access to, they give up after the first or second error message. If you see an account repeatedly attempting to access the same restricted file – especially if that file contains valuable information – it is a sign of compromise.

User-Application Mismatch

Authorized users on your network will generally use the same handful of applications, so any deviation from the norm should be treated as suspicious. For example, a non-IT user shouldn’t suddenly start running network tools, RDP sessions, or config scripts.

Suspicious Changes

Malware is frequently used to make changes to registry or system files to create a backdoor for data exfiltration. Evidence of suspicious changes to a system can indicate a breach has occurred. As with every point on this list, pay attention to any out-of-the-ordinary behavior.

Using an Indicators of Compromise List to Detect and Prevent Threats

This list of IOCs is only useful if you have a way to detect these signs and signals on your network. For example, Security Information and Event Management (SIEM) tools gather important login and event data from your network applications, endpoints, security devices, and other sources. They also provide real-time analysis so you can detect IOCs. User and Entity Behavior Analytics (UEBA) monitor the activity of accounts on your network and detect deviations from normal patterns, so you’re notified when a potential compromise has occurred.

In addition, the Zero Trust Security methodology restricts the damage a hacker can do on your network before you detect their presence. Zero trust follows the principle of “never trust, always verify,” which means accounts must continuously re-establish their trust before jumping to other network segments or resources. Zero trust security also uses the principle of least privilege to ensure a single compromised account will have limited lateral movement on your network.

It’s also important to recognize that not every IOC represents an actual breach. False positives are relatively common, so you need a way to prioritize IOC alerts based on how likely they are to be an actual threat. AI threat analysis tools are a great way to filter out false positives without overwhelming human security engineers.

The right security tools will give you the data to use an “indicators of compromise list” to spot signs of an attack. Robust security practices will ensure you can limit the damage of an attack or even prevent it from occurring in the first place.

?

Book a demo

About The Author

#1 DevOps Platform for Salesforce

We Build Unstoppable Teams By Equipping DevOps Professionals With The Platform, Tools And Training They Need To Make Release Days Obsolete. Work Smarter, Not Longer.

AWTTセッションレポート:カインズが再定義したAI時代のSalesforce DevOps
【AWTT Summer 2026 振り返り】AIエージェント時代に、私たちが本当に備える開発?运用の新標準とは?
Accelerating the Agentic Era in Brazil: 乐播传媒app最新版本 and Capgemini Deepen Strategic Partnership
Salesforce Source Format vs Metadata Format
Get Started with Agentforce in Salesforce
Data 360 Is the Operational Backbone of Agentforce — But Most Enterprises Are Not Ready to Deploy It Safely
What Is Agentforce Salesforce?
AIエージェント時代のシステム戦略 ~ROIを最大化するIT部門の再設計~【イベントレポート CIO Round Table 2026】
Will AI Replace DevOps Jobs?
How to Use AI in DevOps
Agentic AI DevOps Explained
「汎用AI」ではまだ成しえない Salesforce运用を劇的に変える3つのポイント
乐播传媒app最新版本 Introduces Agentia?, Bringing Context-Aware AI Agents to Salesforce DevOps
「AI駆動開発」が切り拓くSalesforce内製化 ?次世代运用モデル実装への道のり?
础滨エージェントが切り拓く厂滨ビジネスの未来とリーダーシップの変革
How Does Salesforce Agentforce Work
Agentforce vs Einstein: Choosing the Right AI to Move from Insight to Action
Agentforce Developer Guide
DevOps Pipeline Best Practices
DevSecOps vs. DevOps
DevOps vs. Agile
Generative AI in DevOps
How DevOps Teams Use AI to Win
Using AI in DevOps
Salesforce開発?运用の未来?AIと共にSIビジネスモデルを「工数」から「価値」へ変革
顿别惫翱辫蝉におけるエージェンティック础滨:チームのための自动化ソリューション
乐播传媒app最新版本 Awarded on CarahSoft’s GSA Schedule, Expanding Access for Federal Agencies
颁辞辫补诲辞、贵别诲搁础惭笔认証を更新し、米国军事组织向け滨尝5取得に向けて前进
成功を“設計”するという発想──乐播传媒app最新版本が提唱する「Project Success Design」
コパード、础滨と协働する未来に向けてパートナー6社と顿谤别补尘蹿辞谤肠别でパネルディスカッション初开催!
乐播传媒app最新版本、Salesforce 2025 Partner Innovation Awardを受賞
乐播传媒app最新版本 CI/CD & Robotic Testing Now TX-RAMP Certified for Texas Government
なぜテストが形骸化するのか? - Salesforce開発現場で「テストはやっている」のに、本番障害が減らない理由
Org Intelligence:なぜ「コンテキスト」がSalesforce DevOpsツールにおいてこれほど重要なのか?
「人ではなくAIに聞ける時代へ ― Salesforce環境を理解する乐播传媒app最新版本 AI Org Intelligence」
厂补濒别蝉蹿辞谤肠别プロジェクトの“隠れコスト”とは??顿别惫翱辫蝉活用で毎月100时间を削减した実践例?
コパード、セールスフォースの环境をエンドツーエンドで可视化する「组织インテリジェンス」をリリース
パイプラインの可視性が Salesforce DevOps 変革成功の鍵である理由
AIが変える意思決定 - スピードと精度は両立できるのか?
属人运用の限界が経営を止める?今こそ始めるSalesforce DevOps?
厂补濒别蝉蹿辞谤肠别におけるユーザー受入テストの进め方:课题、ベストプラクティス、および戦略
Navigating Salesforce Data Cloud: DevOps Challenges and 乐播传媒app最新版本 for Salesforce Developers
独自にSalesforce DevOpsソリューションを構築する際の見えざるコスト
CPQ and Revenue Cloud Deployment: A DevOps Approach
Salesforce DevOpsを支えるAI活用型リリース戦略
コパード、サンブリッジパートナーズとの提携により日本での事业を拡大
础滨で顿别惫翱辫蝉をより简単に、より高速に
Reimagining Salesforce Development with 乐播传媒app最新版本's AI-Powered Platform
ビジネスアプリケーション向けの顿别惫翱辫蝉(デブオプス)って何?
セールスフォースエコシステムにおける顿别惫翱辫蝉の卓越性
セールスフォーステストにおける础滨活用のベストプラクティス
6 testing metrics that’ll speed up your Salesforce release velocity (and how to track them)
第4章: 手動テストの概要
セールスフォース向け础滨动作テスト
Chapter 3: Testing Fun-damentals
Salesforce Deployment: Avoid Common Pitfalls with AI-Powered Release Management
Exploring DevOps for Different Types of Salesforce Clouds
What’s Special About Testing Salesforce? - Chapter 2
Why Test Salesforce? - Chapter 1
Continuous Integration for Salesforce Development
Comparing Top AI Testing Tools for Salesforce
Avoid Deployment Conflicts with 乐播传媒app最新版本’s Selective Commit Feature: A New Way to Handle Overlapping Changes
From Learner to Leader: Journey to 乐播传媒app最新版本 Champion of the Year
The Future of Salesforce DevOps: Leveraging AI for Efficient Conflict Management
How To Sync Salesforce Environments | 乐播传媒app最新版本
乐播传媒app最新版本 and Wipro Team Up to Transform Salesforce DevOps
DevOps Needs for Operations in China: Salesforce on Alibaba Cloud
What is Salesforce Deployment Automation? How to Use Salesforce Automation Tools
From Chaos to Clarity: Managing Salesforce Environment Merges and Consolidations
Future Trends in Salesforce DevOps: What Architects Need to Know
Enhancing Customer Service with 乐播传媒app最新版本GPT Technology
What is Efficient Low Code Deployment?
乐播传媒app最新版本 Launches Test Copilot to Deliver AI-powered Rapid Test Creation
Cloud-Native Testing Automation: A Comprehensive Guide
Building a Scalable Governance Framework for Sustainable Value
乐播传媒app最新版本 Launches 乐播传媒app最新版本 Explorer to Simplify and Streamline Testing on Salesforce
Exploring Top Cloud Automation Testing Tools
Master Salesforce DevOps with 乐播传媒app最新版本 Robotic Testing
Exploratory Testing vs. Automated Testing: Finding the Right Balance
A Guide to Salesforce Source Control | 乐播传媒app最新版本
A Guide to DevOps Branching Strategies
Family Time vs. Mobile App Release Days: Can Test Automation Help Us Have Both?
How to Resolve Salesforce Merge Conflicts | 乐播传媒app最新版本
乐播传媒app最新版本 Expands Beta Access to 乐播传媒app最新版本GPT for All Customers, Revolutionizing SaaS DevOps with AI
Is Mobile Test Automation Unnecessarily Hard? A Guide to Simplify Mobile Test Automation
From Silos to Streamlined Development: Tarun’s Tale of DevOps Success
Simplified Scaling: 10 Ways to Grow Your Salesforce Development Practice
What is Salesforce Incident Management?
What Is Automated Salesforce Testing? Choosing the Right Automation Tool for Salesforce
乐播传媒app最新版本 Appoints Seasoned Sales Executive Bob Grewal to Chief Revenue Officer
Business Benefits of DevOps: A Guide
乐播传媒app最新版本 Brings Generative AI to Its DevOps Platform to Improve Software Development for Enterprise SaaS
乐播传媒app最新版本 Celebrates 10 Years of DevOps for Enterprise SaaS 乐播传媒app最新版本
Celebrating 10 Years of 乐播传媒app最新版本: A Decade of DevOps Evolution and Growth
5 Reasons Why 乐播传媒app最新版本 = Less Divorces for Developers
What is DevOps? Build a Successful DevOps Ecosystem with 乐播传媒app最新版本’s Best Practices
Scaling App Development While Meeting Security Standards
5 Data Deploy Features You Don’t Want to Miss
How to Elevate Customer Experiences with Automated Testing
Top 5 Reasons I Choose 乐播传媒app最新版本 for Salesforce Development
Go back to resources
There is no previous posts
Go back to resources
There is no next posts

Explore more about

セキュリティとガバナンス
Articles
June 25, 2026
AWTTセッションレポート:カインズが再定義したAI時代のSalesforce DevOps
Articles
June 17, 2026
【AWTT Summer 2026 振り返り】AIエージェント時代に、私たちが本当に備える開発?运用の新標準とは?
Articles
May 12, 2026
Accelerating the Agentic Era in Brazil: 乐播传媒app最新版本 and Capgemini Deepen Strategic Partnership
Articles
May 8, 2026
Salesforce Source Format vs Metadata Format

础滨を有効活用し顿别惫翱辫蝉を加速

より速くリリースし、リスクを排除し、仕事を楽しんでください。
Try 乐播传媒app最新版本 Devops.

リソース

Explore our DevOps resource library. Level up your Salesforce DevOps skills today.

今后のイベントと
オンラインセミナー

电子书籍とホワイトペーパー

サポートとドキュメンテーション

デモライブラリ