Indicators of compromise

Identifies indicators of compromise patterns in security and access control contexts. Detects potential exposure of sensitive security information in Australian systems.

Type
regex
Engine
boost_regex
Confidence
medium
Confidence justification
structural regex with domain-specific anchors and constrained context replaces phrase-only marker.
Detection quality
Not detected
Jurisdictions
au
Regulations
NDB Scheme (Cth), SOCI Act 2018 (Cth), TIA Act 1979 (Cth)
Frameworks
CIS Controls, DISP, ISO 27001, NIST CSF, PCI-DSS, SOC 2
Data categories
credentials, security
Scope
wide
Platform compatibility
Purview: Compatible, GCP DLP: Unsupported, Macie: Unsupported, Zscaler: Compatible, Palo Alto: Unsupported, Netskope: Unsupported

Pattern

(?is)(?=\s*\b(?:ioc|indicator[s]?\s+of\s+compromise)\b)(?=\s*\b(?:ip|domain|hash|url)\b)\s+

Corroborative evidence keywords

indicators of compromise, indicators, compromise, security, operations, threat, data

Proximity: 300 characters

Should match

Should not match

Known false positives

References