RFC 9424: Indicators of Compromise (IoCs) and Their Role in Attack Defence
In plain English — editorial summary, not part of the RFC
Cyber defenders frequently rely on Indicators of Compromise (IoCs) to identify, trace, and block malicious activity in networks or on endpoints. This document reviews the fundamentals, opportunities, operational limitations, and recommendations for IoC use. It highlights the need for IoCs to be detectable in implementations of Internet protocols, tools, and technologies -- both for the IoCs' initial discovery and their use in detection -- and provides a foundation for approaches to operational challenges in network security.
Document record
- Document ID
- RFC9424
- Published
- August 2023
- Authors
- K. Paine; O. Whitehouse; J. Sellwood; A. Shaw
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- ops
- Pages
- 24
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9418A YANG Data Model for Service AssuranceCurrent
July 2023
- RFC 9417Service Assurance for Intent-Based Networking ArchitectureCurrent
July 2023
- RFC 9432DNS Catalog ZonesCurrent
July 2023
- RFC 9411Benchmarking Methodology for Network Security Device PerformanceCurrent
March 2023
- RFC 9439Application-Layer Traffic Optimization (ALTO) Performance Cost MetricsCurrent
August 2023
- RFC 9408A YANG Network Data Model for Service Attachment Points (SAPs)Current
June 2023
- RFC 9445RADIUS Extensions for DHCP-Configured ServicesCurrent
August 2023
- RFC 9455Avoiding Route Origin Authorizations (ROAs) Containing Multiple IP PrefixesCurrent
August 2023
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?