Retain the indicator value and type together with source, first/last observed time, confidence, related actor/campaign/malware where justified, affected assets, sightings, expiry or review date, handling restrictions and the action the indicator is expected to support. An indicator without context can become stale, ambiguous or operationally misleading.
External reference
NIST describes cyber threat information as broader than indicators alone, including adversary tactics, techniques and procedures, suggested defensive actions and incident-analysis findings.
Primary source →Operational method
Preserve provenance
Record who or what supplied the indicator, when it was received, and whether the source can be redistributed or cited.
Record observations
Keep first/last observed times, internal sightings and the assets, identities or network flows where the indicator appeared.
Separate confidence from fact
Distinguish observed facts from analytical confidence and attribution hypotheses. Do not turn a vendor label into confirmed actor attribution.
Set expiry or review
Domains, IP addresses, infrastructure and file relationships can change. Use expiry/review dates so stale indicators do not remain permanently authoritative.
Tie the indicator to an action
Document whether the indicator supports monitoring, enrichment, hunting, blocking, incident scoping or exposure prioritisation and what evidence is required before higher-impact action.
Relevant Cybatar sources
Claim boundary
An IOC match is a signal, not proof of compromise, attribution or malicious intent in every context. Cybatar does not guarantee indicator freshness or independent validation of every external source.
These pages are Cybatar-authored threat-intelligence and threat-hunting guidance. NIST, OASIS and MITRE ATT&CK are external sources. References do not establish certification, endorsement, native STIX/TAXII compatibility, complete threat coverage, attribution certainty or proof that a hunt found all malicious activity.