Indicators of Pre-Attack

What Is an IoPA?

Every IOC confirms malicious activity already occurred. An Indicator of Pre-Attack surfaces adversary infrastructure while it is still being assembled. The question is not whether you will see the attack. It is whether you can see the preparation.

An IoPA, Indicator of Pre-Attack, is a validated, evidence-backed signal that adversary infrastructure is being prepared before use.

IoPAs connect observable preparation artifacts through common identity attributes, such as registration patterns, naming conventions, hosting choices, certificate behavior, and infrastructure configuration.

Individually, these attributes may appear ordinary. Correlated and validated, they can reveal related infrastructure and evidence of adversary setup.

Different indicators, different moments

Is an IoPA simply an earlier IOC?

No. IoPAs and IOCs answer different questions at different points in the attack timeline.

Dimension

IOC

IoPA

What it documents

Known malicious activity that already occurred

Adversary infrastructure being prepared before use

Timeline position

During or after execution

During setup, before execution

Evidence basis

Artifacts observed in malicious activity or victim telemetry

Correlated infrastructure and common identity attributes

MITRE ATT&CK anchor

Execution and later tactics

TA0042, Resource Development

Question answered

What happened, and where else?

What is being prepared?

Primary action and metric

Detection, investigation, containment, and response

Preemptive action measured through MTTP

From observation to action

How does a raw signal become an IoPA?

1. Observe the seed

A suspicious artifact appears, such as a newly registered domain, certificate, DNS record, or server associated with known adversary behavior.

2. Pivot across identity attributes

Analysis expands through registrant details, naming patterns, hosting fingerprints, certificate characteristics, and configuration choices.

3. Validate the cluster

Related infrastructure is grouped and tested against available evidence. Validation distinguishes meaningful preparation from coincidence, novelty, or benign activity.

4. Classify and act

The validated result becomes an IoPA with evidence and context that can support blocking, monitoring, investigation, or disruption before execution.

Observable infrastructure

What can an IoPA represent?

Staged domains

Domains registered and configured during preparation, including infrastructure designed to imitate a target, supplier, executive, or trusted service.

Provisioned servers

Hosting infrastructure prepared to support phishing, redirects, payload delivery, or command and control.

Issued certificates

Certificates obtained for staged domains before those domains become active in a campaign.

Configured DNS

Records and name server relationships connecting staged domains to supporting infrastructure.

A different evidence class

An IoPA is not a lower-confidence IOC

An IOC is evidence about the past. A file hash, command address, or malicious URL becomes an IOC because analysts observed it in malicious activity.

An IoPA answers a different question. It identifies validated evidence that infrastructure is being prepared before use. It does not claim that a compromise occurred. It establishes that observable preparation warrants defensive attention.

Lower confidence would mean answering the same question with weaker evidence. An IoPA answers an earlier question through a separate validation process.

Treating IoPAs as weak IOCs discards their primary value: time before execution.

MITRE ATT&CK alignment

Why do IoPAs anchor to Resource Development?

MITRE ATT&CK TA0042, Resource Development, describes how adversaries create, purchase, compromise, and stage the resources an attack requires. These resources include infrastructure, accounts, capabilities, and supporting materials.

TA0042 formally recognizes preparation as a distinct phase of adversary behavior.

IoPAs provide the defensive counterpart. TA0042 describes what adversaries do. IoPAs capture validated signals defenders derive from observing that activity.

This alignment turns Resource Development from a taxonomy entry into an operational source of defensive action.

From intelligence to prevention

What can security teams do with an IoPA?

The primary metric is MTTP, Mean Time to Preempt: the interval between observing adversary preparation and completing defensive action.

Block staged infrastructure

Add validated domains and infrastructure to DNS, email, network, or web controls before use.

Enrich triage

Match security events against IoPAs to identify contact with infrastructure connected to preparation activity.

Monitor for activation

Watch validated infrastructure for changes that indicate movement from setup toward execution.

Investigate related assets

Pivot across common identity attributes to find additional infrastructure associated with the same activity.

Measure MTTP

Track time from validation to defensive action. Keep retrospective comparisons with later public report dates separate from real-time operational measurement.

Public proof examples

What has retrospective analysis found?

These examples compare earlier Malanta classifications with later public reports or historical telemetry. They do not represent prospective prediction or real-time alerting.

GREYVIBE

Malanta reported that cluster expansion identified 10 sibling domains classified malicious on October 29, 2025, approximately 210 days before WithSecure's public GREYVIBE report on May 28, 2026. This is a retrospective comparison, not a prediction.

Inspect the public IoPA evidence archive

TA416

Malanta's April 2026 analysis reported that three C2-linked seed domains were graded malicious on October 13, 2025, 172 days before Proofpoint's public disclosure on April 1, 2026. This is also a retrospective comparison.

Read the TA416 BYOIOC analysis

Historical telemetry matches

A government department found 19 IoPA matches across 30 days of raw logs; one pivoted to mapped APT15 infrastructure. A separate Fortune 500 engagement found 31 matched domains across 14 days of email and endpoint telemetry, including Iran-related infrastructure.

Malanta-published engagement evidence, not independent validation.

Inspect the record

Claims should be inspectable

Malanta maintains a public GitHub repository with case datasets and supporting evidence for selected published investigations. It is an evidence archive, not a complete independent reproducibility toolkit.

Open the public IoPA evidence archive

Public lookup

Check a domain or IP for IoPAs

A public lookup at iopa.malanta.ai is planned and is not currently live. Until it launches, the public GitHub evidence archive and existing platform workflows remain the available access points.

Preparation and compromise are different moments

IOCs tell defenders what already happened. IoPAs show what is being prepared.

The distinction is not lower confidence versus higher confidence. It is preparation versus compromise, TA0042 versus execution, and preemption versus response.

Published retrospective comparisons placed Malanta classifications approximately 210 days before the WithSecure GREYVIBE report and 172 days before Proofpoint's TA416 disclosure. They are retrospective evidence, not predictions.

IoPAs make the setup phase operational. MTTP measures whether teams act on the time they provide.

Indicators of Pre-Attack FAQ

What does IoPA stand for?

IoPA stands for Indicator of Pre-Attack. It is a validated, evidence-backed signal that adversary infrastructure is being prepared before use.

How is an IoPA different from an IOC?

An IOC documents malicious activity that already occurred. An IoPA identifies validated evidence of infrastructure preparation before execution. They describe different phases and support different actions.

Are IoPAs predictions?

No. IoPAs are based on observable infrastructure and validated evidence. Published lead-time examples are retrospective comparisons against later public report dates, not prospective predictions or real-time alerts.

What makes an IoPA validated?

Validation requires multiple supporting signals, correlation through common identity attributes, and evidence that the infrastructure belongs to preparation activity rather than coincidence or benign behavior.

Which MITRE ATT&CK tactic do IoPAs map to?

IoPAs anchor to TA0042, Resource Development. This tactic covers adversary acquisition and development of infrastructure, capabilities, accounts, and other resources before execution.

How do teams use IoPAs?

Teams can block staged infrastructure, monitor it for activation, enrich alerts, investigate related assets, and measure defensive action through MTTP, Mean Time to Preempt.

Give your team something to act on before execution.

See how validated IoPAs can extend existing controls into the adversary setup window and make MTTP measurable.

BOOK DEMO