RFC 9424 · INFORMATIONAL · 2023

Indicators of Compromise and Their Role in Attack Defence

Overview

RFC 9424, “Indicators of Compromise and Their Role in Attack Defence”, is an Informational document published in August 2023 by K. Paine, O. Whitehouse, J. Sellwood, A. Shaw. The canonical text is published by the RFC Editor.

Abstract

Cyber defenders frequently rely on Indicators of Compromise (IoCs) to identify, trace, and block malicious activity in networks or on endpoints. This document reviews the fundamentals, opportunities, operational limitations, and recommendations for IoC use. It highlights the need for IoCs to be detectable in implementations of Internet protocols, tools, and technologies -- both for the IoCs' initial discovery and their use in detection -- and provides a foundation for approaches to operational challenges in network security.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 9424 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2023

Who Is Online

In total there are 309 users online: 0 registered, 304 guests and 5 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: AhrefsBot Applebot Other Bot SemrushBot YandexBot

Users active in the past 15 minutes. Total registered members: 356