Indicators of compromise (IOCs) are forensic evidence of discrepancies, or unusual activities in the organization's network, that help identify security threats, data breaches, insider threats, and more before any harm occurs. IOCs act not just as a warning sign for impending attacks, but they also help in analyzing what has happened. By learning about possible security threats, organizations can deploy their counter security measures to limit or prevent damage to their network.
The Indicator of Compromise (IoC) – Hashes feature in SonicOS enables administrators to block file transfers based on known malicious or unwanted file hashes. By leveraging a custom-defined list of file hashes, SonicOS can detect and prevent the transfer of identified threats across the network perimeter.
When enabled, SonicOS inspects files traversing supported protocols and compares their computed hash values against the configured IoC hash lists. If a match is detected, the file transfer is blocked and an event is generated.
Supports custom hash list creation and management
SonicOS supports the following hash algorithms:
SHA-256 is recommended for improved accuracy and security.