CurrentINFORMATIONALIETF stream

RFC 9424: Indicators of Compromise (IoCs) and Their Role in Attack Defence

In plain English — editorial summary, not part of the RFC

Cyber defenders frequently rely on Indicators of Compromise (IoCs) to identify, trace, and block malicious activity in networks or on endpoints. This document reviews the fundamentals, opportunities, operational limitations, and recommendations for IoC use. It highlights the need for IoCs to be detectable in implementations of Internet protocols, tools, and technologies -- both for the IoCs' initial discovery and their use in detection -- and provides a foundation for approaches to operational challenges in network security.

Document record

Document ID
RFC9424
Published
August 2023
Authors
K. Paine; O. Whitehouse; J. Sellwood; A. Shaw
Status
INFORMATIONAL
Stream
IETF
Area
ops
Pages
24
Also known as

Topics

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/9424-indicators-of-compromise-iocs-and-their-role-in-attack-defence