Indications of compromise events

An Indication of Compromise (IoC) event is a security detection mechanism that

  • identifies connection events with a very high malware confidence level, as reported by EVE,

  • triggers for encrypted sessions generated from a host using a malicious client, and

  • provides information such as the IP address, MAC address, operating system information of the malicious host, and timestamp of the suspicious activity.

A session with an Encrypted Visibility Threat Confidence score of 'Very High' as seen in connection events generates an IoC event. You must enable Hosts from Policies > + Show more > Advanced > Network Discovery. In the Cloud-Delivered Firewall Management Center, view the IoC event existence from here:

  • Click Events & Logs > Analysis > Unified Events and choose the Encrypted Visibility fields and IoC field from the column picker option.