Skip to content

IOCs & TTPs

Indicators are the observable evidence of a threat. Understanding the difference between IOCs (indicators of compromise) and TTPs (tactics, techniques, and procedures) —and which to detect— is key to a defense that actually hurts the attacker.

IOC a CONCRETE indicator: hash, IP, domain, URL, mutex, file name, registry key
-> easy to detect... and easy for the attacker to change (short-lived)
TTP the BEHAVIOR: how they operate (e.g. "phishing -> macro -> C2 over DNS")
-> hard to change -> more durable detection (see pyramid of pain)

The pyramid of pain (what hurts the attacker)

Section titled “The pyramid of pain (what hurts the attacker)”
Hash trivial to change (little pain)
IP easy to rotate
Domain a bit more effort
Artifacts tools/implants
Network/host usage patterns
TTPs MAXIMUM pain: changing how they operate is expensive
-> invest in detecting TTPs, use IOCs for fast blocking and pivoting
Network IPs, domains, URLs, certificates (JA3), traffic patterns (see mal-c2)
Host hashes, file names/paths, registry keys, mutexes, services
Email senders, subjects, attachments (phishing, see se-phishing)
Behavioral sequences of actions -> already bordering on TTP
- IOCs EXPIRE: a C2 IP is rotated; a hash changes on recompile
- enrich (context, confidence, source) and date them -> don't block blindly
- share in STIX/MISP with TLP; false positives if blocking without context
- pivot: from one IOC to related infrastructure (passive DNS, WHOIS, TLS)
- tactical IOC -> immediate block in DNS/firewall/proxy/EDR (def-deteccion)
- TTP -> behavior rule (Sigma) and hunting hypothesis (def-hunting)
- a finding in IR (dfir-triage) generates IOCs -> retrospective hunt across the fleet
  • Block by IOC to buy time, but invest in TTP detection for durability.
  • Enrich and date indicators; avoid blind blocks that create false positives.
  • Pivot from an IOC to related infrastructure (pDNS/WHOIS/CT) to widen the hunt.
  • Share with MISP/STIX respecting TLP; integrate with the SIEM (SIEM) and hunting.
  • The pyramid of pain (David Bianco) is the reference framework for prioritizing IOC vs TTP.
  • Campaigns where blocking only hashes/IPs was useless (the attacker rotated) until hunting TTPs.
  • MISP and feeds (abuse.ch) sustain the tactical exchange of IOCs between organizations.
  • Distinguish IOC (concrete) from TTP (behavior)
  • Prioritize by the pyramid of pain (invest in TTPs)
  • Classify IOCs by type (network/host/email/behavioral)
  • Enrich, date, and assign confidence to each indicator
  • Pivot to related infrastructure (pDNS/WHOIS/CT)
  • IOC → block; TTP → Sigma rule / hunting hypothesis
  • Share in MISP/STIX with the correct TLP