IOCs Are Dead—Long Live IOCs!

  • Friday, March 4, 2016 | 11:20 AM – 12:10 PM | West | Room: 2006

View all Sessions

Indicators of Compromise were meant to solve the failures of signature-based detection tools. Yet today’s array of IOC standards, feeds and products haven’t impeded attackers, and most intel is shared in flat lists of hashes, IPs and strings. This session will explore why IOCs haven’t raised the bar, how to better utilize brittle IOCs and how to use intrinsic network data to craft better IOCs.


This document was retrieved from on Fri, 19 Jul 2019 06:24:15 -0400.