Indicators define allow, audit, warn, block, or block-and-remediate behavior according to entity type. Supported entities include file hashes, external IP addresses, URLs/domains, and certificates. Scope and expiration reduce operational risk.
| Indicator | Typical actions / prerequisites |
|---|
| File | Allow, audit, warn, block execution, block and remediate; cloud protection and supported Defender AV required. |
| IP / URL / domain | Allow, audit, warn, block; Network Protection and custom network indicators required. Internal IPs and CIDR ranges are not supported in the lesson. |
| Certificate | Allow or block leaf certificates; requires supported AV and cloud protection. |
Indicators are honored by cloud detection, endpoint prevention, and automated investigation. They can be created contextually, manually, or imported by CSV.
Official lessonIoC types, actions, and prerequisites