Technical Procedures
IOC Collection Guide
Best practices for IOC collection, formatting, and sharing during and after incident response.
Technical Procedures · beginner · Ongoing
Standardized procedures for collecting and documenting indicators of compromise.
Steps
5
01
IOC Identification
Identify indicators during investigation.
- Extract file hashes from malware samples
- Document malicious IP addresses and domains
- Capture file paths and names
- Note registry keys and values
- Document user agent strings
02
IOC Validation
Validate indicators before sharing.
- Check IOCs against legitimate sources
- Verify IOCs are not false positives
- Confirm IOCs are specific to the threat
- Remove internal-only indicators
03
IOC Documentation
Document IOCs in standard format.
- Use standardized IOC format (STIX/OpenIOC)
- Include context and confidence levels
- Note first and last seen dates
- Reference source of IOC
04
IOC Deployment
Deploy IOCs for detection.
- Add to threat intelligence platform
- Update SIEM detection rules
- Add to EDR watchlists
- Update firewall/proxy blocklists
05
IOC Sharing
Share IOCs with appropriate parties.
- Share with ISACs if applicable
- Consider sharing with vendors
- Document sharing decisions
- Track IOC usage and feedback
Checklist
- All indicator types collected
- IOCs validated against false positives
- Internal indicators removed before sharing
- IOCs documented in standard format
- Context and confidence noted
- IOCs deployed to security tools
- Sharing decisions documented
- IOC effectiveness tracked
Evidence
- IOC list with context
- Validation notes
- STIX/OpenIOC exports
- Sharing records