Problem Statement
What distinguishes an Indicator of Compromise (IOC) from an Indicator of Attack (IOA)?
Explanation
IOCs are reactive clues like bad hashes, domains, or file paths that confirm compromise. IOAs are behavioral signals like suspicious parent-child processes, repeated credential failures, and privilege-seeking actions. Mature detection uses both: IOCs for quick blocking and IOAs for early disruption.
