What distinguishes an indicator of attack (IoA) from indicators of compromise (IoC)?
An IoC is forensic evidence that a computer or network intrusion has already occurred, such as a known-malicious file hash, domain, or traffic signature. An IoA identifies attacker behaviors or actions early enough to interrupt the attack before a vulnerability is exploited or the attacker achieves the objective. Microsoft Defender for Endpoint: Overview of indicators
Community Discussion