Indications of compromise events

An Indication of Compromise (IoC) event is a security detection mechanism that

  • identifies connection events with a very high malware confidence level, as reported by EVE,

  • triggers for encrypted sessions generated from a host using a malicious client, and

  • provides information such as the IP address, MAC address, operating system information of the malicious host, and timestamp of the suspicious activity.

IoC event generation and viewing locations

A session with an Encrypted Visibility Threat Confidence score of 'Very High' as seen in connection events generates an IoC event. You must enable Hosts from Policies > + Show more > Advanced > Network Discovery. In the Cloud-Delivered Firewall Management Center, you can view the IoC event existence from these locations:

  • Events & Logs > + Show more > Hosts > Indications of Compromise, and then Analysis > Indications of Compromise.

  • Events & Logs > Hosts > Network Map > Choose the host that must be checked.

    You can view the process information of the session that generated the IoC on the Connection Events page. Click Events & Logs > + Show more > Connection > Events to access the Connection Events page. Note that you must manually select the Encrypted Visibility fields and IoC field from the Table View of Connection Events tab.