A device audit finds that an executable named update_tool.exe was created late at night in a public folder. What type of IoC is this?
A user logs in at 2:00 AM from a city they never visit, which is unusual for their normal schedule. What does this suggest?
A malware scanner detects a file whose hash matches a known malicious signature. What type of IoC is this?
Several employees attempt to log in from the same IP address within seconds using the same password, but most fail. Which password attack is likely happening?
An administrator sees a series of logins using default credentials (like admin:admin) across multiple accounts in quick succession. What type of attack is this?
After a suspected attack, a device’s firewall rules were modified without authorization. What type of IoC is this?
A user’s account fails login five times in a row, then succeeds on the sixth attempt. This happened from an unusual IP. What should be investigated?
A system shows a background process named updater.exe running automatically on startup, but no software was installed by the user. What kind of indicator is this?
A system administrator reviews logs and sees repeated failed login attempts on a single account over 10 minutes. Which attack does this pattern suggest?
A login attempt is made from an IP address in a foreign country that the user has never logged in from before. What type of IoC is this?
Which type of attack is impossible to detect using logs?
An IT audit finds that a new service was configured to start automatically at boot, linked to a suspicious executable. Which IoC is this?
A device has unusual processes running that weren’t part of normal startup routines. Which category of IoC is this?
A security officer finds that several user accounts have been successfully logged in from unusual locations at unusual times. The officer locks out the accounts. What should the officer do next?
An audit shows that a file has a name matching a known malicious program, but was not executed. What type of IoC is this?
A single user’s account tries multiple passwords in a short period the final attempt succeeds in logging in the account. Which of the following should the administrator do first?
A log shows dozens of failed logins across multiple accounts from one IP within seconds. What type of attack is this?
An administrator observes a series of default passwords attempted on several accounts from the same IP, none of the accounts are accessed. What action should the administrator take?
A user account is seen logging in at odd hours from unusual IPs, and immediately changes permissions on files. Which IoC is this?
A system shows many failed logins on a single account, then a successful login occurs, and immediately sensitive data is accessed. What type of IoC is this?
What Indicators of Compromise are present?
Are the IoCs host-based, file-based, or behavior-based? Explain
What type of attack is occuring?
What actions would you take to mitigate the attack? How would that secure the device?