Case 4B9537 · Malware & intel · L1 Foundations
IOCs vs TTPs
Practise as: Explain it · Interview
Interview questionWhat is the difference between an IOC and a TTP, and which is more valuable for detection?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- IOCs are artifacts of a past compromise: hashes, IPs, domains, file paths, registry keys
- TTPs are adversary behaviors: tactics, techniques and procedures, e.g. dumping LSASS with comsvcs.dll
- IOCs are cheap to share and match but short-lived; attackers rotate infrastructure and recompile in minutes
- TTP-based detections are harder to build but survive tool changes, so they last longer
- Use IOCs for fast sweeps and scoping; invest in TTP detections for durable coverage
If the interviewer pushes back
- How would you turn a vendor IOC report into a behavioral detection?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.