Common IOCs include suspicious IP addresses, malicious domains, file hashes associated with malware, abnormal login patterns, or unusual outbound traffic. SOC analysts use IOCs to detect, investigate, and correlate threats across their environment. IOCs are often sourced from threat intelligence feeds and represent known-bad artifacts that have been observed in previous attacks.