IOCs & TTPs
Indicators are the observable evidence of a threat. Understanding the difference between IOCs (indicators of compromise) and TTPs (tactics, techniques, and procedures) —and which to detect— is key to a defense that actually hurts the attacker.
IOC vs TTP
Section titled “IOC vs TTP”IOC a CONCRETE indicator: hash, IP, domain, URL, mutex, file name, registry key -> easy to detect... and easy for the attacker to change (short-lived)TTP the BEHAVIOR: how they operate (e.g. "phishing -> macro -> C2 over DNS") -> hard to change -> more durable detection (see pyramid of pain)The pyramid of pain (what hurts the attacker)
Section titled “The pyramid of pain (what hurts the attacker)”Hash trivial to change (little pain)IP easy to rotateDomain a bit more effortArtifacts tools/implantsNetwork/host usage patternsTTPs MAXIMUM pain: changing how they operate is expensive-> invest in detecting TTPs, use IOCs for fast blocking and pivotingIOC types
Section titled “IOC types”Network IPs, domains, URLs, certificates (JA3), traffic patterns (see mal-c2)Host hashes, file names/paths, registry keys, mutexes, servicesEmail senders, subjects, attachments (phishing, see se-phishing)Behavioral sequences of actions -> already bordering on TTPIndicator lifecycle and management
Section titled “Indicator lifecycle and management”- IOCs EXPIRE: a C2 IP is rotated; a hash changes on recompile- enrich (context, confidence, source) and date them -> don't block blindly- share in STIX/MISP with TLP; false positives if blocking without context- pivot: from one IOC to related infrastructure (passive DNS, WHOIS, TLS)From IOC to detection/hunting
Section titled “From IOC to detection/hunting”- tactical IOC -> immediate block in DNS/firewall/proxy/EDR (def-deteccion)- TTP -> behavior rule (Sigma) and hunting hypothesis (def-hunting)- a finding in IR (dfir-triage) generates IOCs -> retrospective hunt across the fleetBlue Team / operation
Section titled “Blue Team / operation”- Block by IOC to buy time, but invest in TTP detection for durability.
- Enrich and date indicators; avoid blind blocks that create false positives.
- Pivot from an IOC to related infrastructure (pDNS/WHOIS/CT) to widen the hunt.
- Share with MISP/STIX respecting TLP; integrate with the SIEM (SIEM) and hunting.
Real-world cases
Section titled “Real-world cases”- The pyramid of pain (David Bianco) is the reference framework for prioritizing IOC vs TTP.
- Campaigns where blocking only hashes/IPs was useless (the attacker rotated) until hunting TTPs.
- MISP and feeds (abuse.ch) sustain the tactical exchange of IOCs between organizations.
Testing checklist
Section titled “Testing checklist”- Distinguish IOC (concrete) from TTP (behavior)
- Prioritize by the pyramid of pain (invest in TTPs)
- Classify IOCs by type (network/host/email/behavioral)
- Enrich, date, and assign confidence to each indicator
- Pivot to related infrastructure (pDNS/WHOIS/CT)
- IOC → block; TTP → Sigma rule / hunting hypothesis
- Share in MISP/STIX with the correct TLP