Indicators of Pre-Attack
Every IOC confirms malicious activity already occurred. An Indicator of Pre-Attack surfaces adversary infrastructure while it is still being assembled. The question is not whether you will see the attack. It is whether you can see the preparation.
An IoPA, Indicator of Pre-Attack, is a validated, evidence-backed signal that adversary infrastructure is being prepared before use.
IoPAs connect observable preparation artifacts through common identity attributes, such as registration patterns, naming conventions, hosting choices, certificate behavior, and infrastructure configuration.
Individually, these attributes may appear ordinary. Correlated and validated, they can reveal related infrastructure and evidence of adversary setup.
Different indicators, different moments
No. IoPAs and IOCs answer different questions at different points in the attack timeline.
Dimension | IOC | IoPA |
|---|---|---|
What it documents | Known malicious activity that already occurred | Adversary infrastructure being prepared before use |
Timeline position | During or after execution | During setup, before execution |
Evidence basis | Artifacts observed in malicious activity or victim telemetry | Correlated infrastructure and common identity attributes |
MITRE ATT&CK anchor | Execution and later tactics | TA0042, Resource Development |
Question answered | What happened, and where else? | What is being prepared? |
Primary action and metric | Detection, investigation, containment, and response | Preemptive action measured through MTTP |
From observation to action
A suspicious artifact appears, such as a newly registered domain, certificate, DNS record, or server associated with known adversary behavior.
Analysis expands through registrant details, naming patterns, hosting fingerprints, certificate characteristics, and configuration choices.
Related infrastructure is grouped and tested against available evidence. Validation distinguishes meaningful preparation from coincidence, novelty, or benign activity.
The validated result becomes an IoPA with evidence and context that can support blocking, monitoring, investigation, or disruption before execution.
Observable infrastructure
Domains registered and configured during preparation, including infrastructure designed to imitate a target, supplier, executive, or trusted service.
Hosting infrastructure prepared to support phishing, redirects, payload delivery, or command and control.
Certificates obtained for staged domains before those domains become active in a campaign.
Records and name server relationships connecting staged domains to supporting infrastructure.
A different evidence class
An IOC is evidence about the past. A file hash, command address, or malicious URL becomes an IOC because analysts observed it in malicious activity.
An IoPA answers a different question. It identifies validated evidence that infrastructure is being prepared before use. It does not claim that a compromise occurred. It establishes that observable preparation warrants defensive attention.
Lower confidence would mean answering the same question with weaker evidence. An IoPA answers an earlier question through a separate validation process.
Treating IoPAs as weak IOCs discards their primary value: time before execution.
MITRE ATT&CK alignment
MITRE ATT&CK TA0042, Resource Development, describes how adversaries create, purchase, compromise, and stage the resources an attack requires. These resources include infrastructure, accounts, capabilities, and supporting materials.
TA0042 formally recognizes preparation as a distinct phase of adversary behavior.
IoPAs provide the defensive counterpart. TA0042 describes what adversaries do. IoPAs capture validated signals defenders derive from observing that activity.
This alignment turns Resource Development from a taxonomy entry into an operational source of defensive action.
From intelligence to prevention
The primary metric is MTTP, Mean Time to Preempt: the interval between observing adversary preparation and completing defensive action.
Add validated domains and infrastructure to DNS, email, network, or web controls before use.
Match security events against IoPAs to identify contact with infrastructure connected to preparation activity.
Watch validated infrastructure for changes that indicate movement from setup toward execution.
Pivot across common identity attributes to find additional infrastructure associated with the same activity.
Track time from validation to defensive action. Keep retrospective comparisons with later public report dates separate from real-time operational measurement.
Public proof examples
These examples compare earlier Malanta classifications with later public reports or historical telemetry. They do not represent prospective prediction or real-time alerting.
Malanta reported that cluster expansion identified 10 sibling domains classified malicious on October 29, 2025, approximately 210 days before WithSecure's public GREYVIBE report on May 28, 2026. This is a retrospective comparison, not a prediction.
Inspect the public IoPA evidence archiveMalanta's April 2026 analysis reported that three C2-linked seed domains were graded malicious on October 13, 2025, 172 days before Proofpoint's public disclosure on April 1, 2026. This is also a retrospective comparison.
Read the TA416 BYOIOC analysisA government department found 19 IoPA matches across 30 days of raw logs; one pivoted to mapped APT15 infrastructure. A separate Fortune 500 engagement found 31 matched domains across 14 days of email and endpoint telemetry, including Iran-related infrastructure.
Malanta-published engagement evidence, not independent validation.
Inspect the record
Malanta maintains a public GitHub repository with case datasets and supporting evidence for selected published investigations. It is an evidence archive, not a complete independent reproducibility toolkit.
Open the public IoPA evidence archivePublic lookup
A public lookup at iopa.malanta.ai is planned and is not currently live. Until it launches, the public GitHub evidence archive and existing platform workflows remain the available access points.
IOCs tell defenders what already happened. IoPAs show what is being prepared.
The distinction is not lower confidence versus higher confidence. It is preparation versus compromise, TA0042 versus execution, and preemption versus response.
Published retrospective comparisons placed Malanta classifications approximately 210 days before the WithSecure GREYVIBE report and 172 days before Proofpoint's TA416 disclosure. They are retrospective evidence, not predictions.
IoPAs make the setup phase operational. MTTP measures whether teams act on the time they provide.
What does IoPA stand for?
IoPA stands for Indicator of Pre-Attack. It is a validated, evidence-backed signal that adversary infrastructure is being prepared before use.
How is an IoPA different from an IOC?
An IOC documents malicious activity that already occurred. An IoPA identifies validated evidence of infrastructure preparation before execution. They describe different phases and support different actions.
Are IoPAs predictions?
No. IoPAs are based on observable infrastructure and validated evidence. Published lead-time examples are retrospective comparisons against later public report dates, not prospective predictions or real-time alerts.
What makes an IoPA validated?
Validation requires multiple supporting signals, correlation through common identity attributes, and evidence that the infrastructure belongs to preparation activity rather than coincidence or benign behavior.
Which MITRE ATT&CK tactic do IoPAs map to?
IoPAs anchor to TA0042, Resource Development. This tactic covers adversary acquisition and development of infrastructure, capabilities, accounts, and other resources before execution.
How do teams use IoPAs?
Teams can block staged infrastructure, monitor it for activation, enrich alerts, investigate related assets, and measure defensive action through MTTP, Mean Time to Preempt.
Deep Dive
A step-by-step examination of how preparation signals become validated IoPAs.
Concept
The reasoning behind IoPAs and the earlier point in the attack timeline they address.
Perspective
Why post-compromise artifacts cannot answer every intelligence question.
E-book
How validated pre-attack evidence changes the objective from observation to action.
Platform
See how IoPAs fit into a complete Pre-Attack Prevention workflow.
Help
Practical guidance for searching and investigating IoPAs inside the platform.
Research
Survey findings on how security teams consume threat feeds and evaluate operational value.
Framework
The authoritative framework for adversary activity during attack preparation.

