In more detail
Security teams share IOCs from known attacks so others can search their logs and files for matches: a malicious file's Hash, a command-and-control address, an odd registry key or an unusual outbound connection. IOCs go stale as attackers change infrastructure, so behaviour-based detection complements them. Defang URLs when sharing them, with the URL Defanger.