---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# IoC Repository

# IoC Repository {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

IoC repository contains STIX objects, each of these objects contain a specific piece of
information.

When you combine STIX objects together through relationships, you allow for easy or complex
representations of Cyber Threat Intelligence (CTI).

Threat Intelligence supports STIX versions 1.1, 2.0, and 2.1.
* **[Attack modes and methods](https://servicenow-prod.fluidtopics.net/~rTBCjiojwrIpGnLMomOQw)**   
  Attack modes and methods, sometimes referred to as Tactics, Techniques, and Procedures (TTPs), are representations of how cyber adversaries behave. They characterize what these adversaries do and how they do it, in increasing levels of detail. Attack modes and methods apply for STIX 1.1.
* **[Indicators of compromise](https://servicenow-prod.fluidtopics.net/HLk_VjQcZWgRoKtyJZSQ6g)**   
  Indicators of Compromise (IoC) are artifacts observed on a network or operating system that are likely to indicate an intrusion. Typical IoCs are virus signatures and IP addresses, MD5 hashes of malware files or URLs, or domain names. IoC applies for STIX 1.1 and 2.x.
* **[Observables](https://servicenow-prod.fluidtopics.net/4L_hJnjzyDpy7sO2F5Ujbw)**   
  Observables represent stateful properties (such as the MD5 hash of a file or the value of a registry key) or measurable events (such as the creation of a registry key or the deletion of a file) that are pertinent to the operation of computers and networks. Observables apply for STIX 1.1 and 2.x.
* **[Attack patterns](https://servicenow-prod.fluidtopics.net/sIVAkmeYBBZnSCXUeEe2Hg)**   
  Attack patterns are a type of Tactics, Techniques, and Procedures (TTPs) that describe the methods that adversaries attempt to compromise targets. Attack Patterns apply for STIX 2.x.
* **[Campaigns](https://servicenow-prod.fluidtopics.net/pMlkAMvePRl9Hyj0UYymvw)**   
  A Campaign is a grouping of adversarial behaviors. These behaviors describe a set of malicious activities or attacks that occur over time against a specific set of targets. Campaigns apply for STIX 2.x.
* **[Course of actions](https://servicenow-prod.fluidtopics.net/7cDYVTHGDKGPpEbY1cD~VA)**   
  A course of action is an action taken either to prevent an attack or to respond to an attack that is in progress. Course of actions apply for STIX 2.x.
* **[Identities](https://servicenow-prod.fluidtopics.net/xoxPUvBWMHgllgYzI7GSPA)**   
  Identities represent actual individuals, organizations, or groups (ACME, Inc.) and classes of individuals, systems, or groups (the finance sector). Identities apply for STIX 2.x.
* **[Infrastructure](https://servicenow-prod.fluidtopics.net/fmERWDgPjHCKRz1ZbgvPqQ)**   
  The Infrastructure SDO represents a type of Tactics, Techniques, and Procedures (TTPs). They describe any systems, software services, and any associated physical or virtual resources intended to support some purpose of an attack. Infrastructure applies for STIX 2.x.
* **[Intrusion set](https://servicenow-prod.fluidtopics.net/ywBHd7DoR3ZK93fCr1oFVw)**   
  An Intrusion Set is a grouped set of adversarial behaviors and resources with common properties. An Intrusion Set usually involves a single organization. Intrusion set applies for STIX 2.x.
* **[Locations](https://servicenow-prod.fluidtopics.net/Epde9861SCWsU3kcy8yPTQ)**   
  A Location represents a geographic location. Locations are primarily used to give context to other SDOs. Locations apply for STIX 2.x.
* **[Malware](https://servicenow-prod.fluidtopics.net/UHuEFVsFY8l8X7oI1Ysz1w)**   
  Malware is a type of TTP that represents malicious code. It refers to a program that is covertly inserted into a system. Malware applies for STIX 2.x.
* **[Malware analysis](https://servicenow-prod.fluidtopics.net/mwqfR9Hdsj2i5PG94glaMQ)**   
  Malware Analysis captures the metadata and results of a malware. Malware analysis applies for STIX 2.x.
* **[Observed data](https://servicenow-prod.fluidtopics.net/o_7Ao0eDrodDhmHeRFd6xg)**   
  Observed Data conveys information about cyber security-related entities such as files, systems, and networks using the STIX Cyber-observable Objects (SCOs). Observed data applies for STIX 2.x.
* **[Threat actors](https://servicenow-prod.fluidtopics.net/2vf6vJ3S0o18_2XpJE1SNw)**   
  Threat Actors are individuals, groups, or organizations who act with malicious intent. Threat actors applies for STIX 2.x.
* **[Threat groupings](https://servicenow-prod.fluidtopics.net/t6PHG8c1NUG6wM8DvQyAGA)**   
  A Threat Groupings object explicitly asserts that the referenced STIX Objects have a shared context. Threat groupings applies for STIX 2.x.
* **[Marking definitions](https://servicenow-prod.fluidtopics.net/4F4CFHZm2hyrcpRQh6HrhQ)**   
  The marking definitions object represents a specific marking.
* **[Threat notes](https://servicenow-prod.fluidtopics.net/FhnJMGKGkRhpn3pdzhH~xQ)**   
  A Threat Note conveys informative text to provide additional analysis not contained in the STIX Objects, Marking Definition objects, or Language Content objects which the Note relates to. Threat notes applies for STIX 2.x.
* **[Threat opinions](https://servicenow-prod.fluidtopics.net/o23E~5KjnsdGnGxzUGFvOQ)**   
  An Opinion is an assessment of the accuracy of the information in a STIX Object produced by a different entity. Threat opinions apply for STIX 2.x.
* **[Threat reports](https://servicenow-prod.fluidtopics.net/qgEyeGcehw1fUp5a20rlJA)**   
  Threat Reports are collections of threat intelligence focused on one or more topics. Threat reports apply for STIX 2.x.
* **[Sightings](https://servicenow-prod.fluidtopics.net/RvrXVLz7khJ0A5~dwySz8g)**   
  Sightings denote that an indicator or object was seen. Objects may be a malware, tool, threat actor, and so on.
* **[Tools](https://servicenow-prod.fluidtopics.net/ftEtOj1IbeUJvZQBKq70IQ)**   
  Tools are legitimate software that are used by threat actors to perform attacks. Tools apply for STIX 2.x.
* **[Vulnerabilities](https://servicenow-prod.fluidtopics.net/1AYpDAo_V9V120GdWCRsWA)**   
  A Vulnerability is a weakness or defect in a software or hardware component that attackers exploit. Vulnerabilities apply for STIX 2.x.
* **[Relationships](https://servicenow-prod.fluidtopics.net/7hDsCR9xgdRFffGOXxXV6g)**   
  Use the relationship objects to link together two SDOs or STIX Cyber-observable Objects (SCOs) to describe how they relate to each other.
* **[STIX Visualizer](https://servicenow-prod.fluidtopics.net/vL4O8J9AC2t4QFu1t9vZBQ)**   
  The STIX Visualizer visually represents the structure of the STIX object and its relationship.

**Related concepts**   

* [Understanding Threat Intelligence](https://servicenow-prod.fluidtopics.net/4JNgG8kLOuC9ul~kyB8WEQ "The Threat Intelligence application allows you to access and provide a point of reference for your company's Structured Threat Information Expression (STIX) data. Included in Threat Intelligence is the Security Case Management application, which provides a means for analyzing threats to your organization posed by targeted campaigns or state actors.")
* [Set up Threat Intelligence](https://servicenow-prod.fluidtopics.net/bf5wVW2WDwbfY01wsvCdPA#c_GetStartedWithThreatIntel "Before you run Threat Intelligence in your instance, you must download it from the ServiceNow Store. You can also set up properties and define a threat source.")
* [MITRE-ATT\&CK framework overview](https://servicenow-prod.fluidtopics.net/PLekA4nA93WU0EmB3U06Gw "The MITRE-ATT&CK framework is a knowledge base of common tactics, techniques, and procedures (TTP) that your organization can access to develop specific threat models and methodologies against cyberattacks.")
* [MITRE D3FEND framework](https://servicenow-prod.fluidtopics.net/AEcU76jD~0HZpZmyWUIOXw "MITRE D3FEND is a knowledge graph of cybersecurity countermeasure techniques that complements the MITRE-ATT&CK framework by providing defensive techniques.")
* [Threat Intelligence integrations](https://servicenow-prod.fluidtopics.net/9sJ8C7LcH1yxYckRbWLCuw "The Threat Intelligence base system includes integrations to third-party malware-detection software packages. This section provides instructions for activating the plugins and configuring both ServiceNow and third-party integrations. Also included are some basic guidelines for developing your own integrations, as well as details on specific integrations included in the base system.")
* [Threat Intelligence Orchestration](https://servicenow-prod.fluidtopics.net/3WD6pR8K4Q6BLyNM8Hd7rg "Threat Intelligence Orchestration activities allow users to determine whether a threat has been seen before in other security incidents or on other systems using workflow orchestration.")
* [Security Case Management](https://servicenow-prod.fluidtopics.net/Y2pnftV6QRdUlHoNUrOfNA "Security Case Management provides a means for security analysts who are engaged in threat hunting to gather information on suspicious activity in their environment. Case-related records, such as security incidents, observables, CIs, and affected users can be added to cases to accommodate broad and specific analysis.")  
**Related reference**   

* [Threat Intelligence administration](https://servicenow-prod.fluidtopics.net/pKHEorlejIVQ8w4zw4oYlA "The Threat Intelligence base system is ready to use on activation. You can add records to certain modules in the Administration application menu, but most are already populated with industry-standard information.")

