---
title: "Declarations of Compromise®: Cutting Through the Noise to Pinpoint Serious and Imminent Threats"
description: Security teams are often overwhelmed by a flood of alerts, leading to alert fatigue and missed critical incidents. But what if you could cut through the noise and pinpoint the most serious and imminent threats to your organization? This is where Declarations of Compromise (DoC) from Clear NDR come into play.
image: https://www.stamus-networks.com/hubfs/Clear-NDR-DoC-Noise-Reduction-A.jpg
---

[![Stamus-Logo-with-R-color-small](https://www.stamus-networks.com/hubfs/Stamus-Logo-with-R-color-small.png "Stamus-Logo-with-R-color-small")](https://www.stamus-networks.com/?hsLang=en)

# Declarations of Compromise®: Cutting Through the Noise to Pinpoint Serious and Imminent Threats

 by [Phil Owens](https://www.stamus-networks.com/blog/author/phil-owens) | Jul 29, 2025 | [Network Detection and Response](https://www.stamus-networks.com/blog/tag/network-detection-and-response), [Declarations of Compromise](https://www.stamus-networks.com/blog/tag/declarations-of-compromise), [ClearNDR](https://www.stamus-networks.com/blog/tag/clearndr), [Unique to Clear NDR](https://www.stamus-networks.com/blog/tag/unique-to-clear-ndr), [Clear NDR Enterprise](https://www.stamus-networks.com/blog/tag/clear-ndr-enterprise)

![](https://www.stamus-networks.com/hubfs/Clear-NDR-DoC-Noise-Reduction-A.jpg)

Security teams are often overwhelmed by a flood of alerts, leading to alert fatigue and missed critical incidents. But what if you could cut through the noise and pinpoint the most serious and imminent threats to your organization? This is where **Declarations of Compromise (DoC)** from Clear NDR come into play.

## What is a Declaration of Compromise (DoC)?

A DoC is a high-fidelity, asset-oriented security incident event generated by Clear NDR. It's designed to provide a clear starting point for investigation by identifying true organizational compromises with near-zero false positives. Think of it as a confident "declaration" that a serious threat, such as malware, lateral movement, or an advanced persistent threat (APT), has been detected against a specific asset in your network.

## The Power of DoC: Noise Reduction and Actionable Intelligence

Traditional security monitoring often generates millions of network events. DoCs dramatically reduce this alert fatigue by transforming that vast amount of data into focused, actionable incidents. While Clear NDR collects extensive network metadata and discrete threat detections, DoCs simplify the incident responder's job by highlighting only the most critical events.

![DoC-Pyramid-Stamus-Networks-Branded](https://www.stamus-networks.com/hs-fs/hubfs/DoC-Pyramid-Stamus-Networks-Branded.png?width=4189&height=2456&name=DoC-Pyramid-Stamus-Networks-Branded.png)

Each DoC maps to specific phases of the cyber security kill chain, providing a complete attack timeline from initial compromise through full blast radius analysis. This means you not only know *what* happened but also *how* the attack progressed and *which assets* are affected.

**Key Characteristics of DoCs:**

- **Asset-oriented:** Each DoC is associated with a single asset, with all evidence and insights linked to it.
- **High confidence, high-fidelity:** DoCs are triggered only under conditions of an active incident, ensuring accuracy.
- **Low noise:** While Clear NDR logs repeated detections, only the first one generates a DoC, preventing redundant alerts.
- **Effective with UI or SIEM:** DoC events contain comprehensive information, making them valuable whether you use the Clear NDR UI or a SIEM integration.
- **Built-in and/or customized:** Stamus Networks provides extensive built-in detections, updated daily, and Clear NDR allows users to create custom DoC rules through an "escalation" process.

## Automating Your Response

DoCs are not just about detection; they're about action. They can seamlessly integrate with your existing security infrastructure through SIEM integrations and automated response capabilities via API integrations. This enables automated workflows like:

- Opening incident response (IR) tickets
- Isolating offending endpoints
- Blocking malicious IP addresses
- Initiating SOAR playbooks
- Sending instant messages to your security team

## Transforming Security Operations

Declarations of Compromise represent a paradigm shift from reactive alert processing to proactive incident management. By giving security personnel precise, high-confidence starting points and comprehensive evidence, DoCs empower teams to focus their expertise on genuine threats, significantly enhancing the efficiency and effectiveness of modern cybersecurity operations.

## Further Reading

For a more in-depth understanding, read our full Tech Brief on Declarations of Compromise and Declarations of Policy Violations on our website: [https://www.stamus-networks.com/hubfs/Library/Documents%20(PDFs)/StamusNetworks-TB-FILTERS-072025-1.pdf](https://www.stamus-networks.com/hubfs/Library/Documents%20(PDFs)/StamusNetworks-TB-FILTERS-072025-1.pdf?hsLang=en) 

To learn how analysts can pivot from a DoC to a complete package of evidence in two clicks, check out this blog entitled “Two Clicks to Evidence,” here: [https://www.stamus-networks.com/blog/reduce-mean-time-to-detection-2-clicks-to-evidence-with-clear-ndr](https://www.stamus-networks.com/blog/reduce-mean-time-to-detection-2-clicks-to-evidence-with-clear-ndr?hsLang=en) 

 To understand how Clear NDR can dramatically reduce the costs associated with retaining network forensic evidence, read these two docs:

- Optimizing Clear NDR™ Storage with Conditional Logging - [https://www.stamus-networks.com/hubfs/Library/Documents%20(PDFs)/StamusNetworks-TB-CONDITIONAL-LOG-042025-1.pdf](https://www.stamus-networks.com/hubfs/Library/Documents%20(PDFs)/StamusNetworks-TB-CONDITIONAL-LOG-042025-1.pdf?hsLang=en) 
- Reduce the Costs of SIEM Data Retention with Clear NDR™ - [https://www.stamus-networks.com/hubfs/Library/Documents%20(PDFs)/StamusNetworks-TB-CUT-SIEM-INGEST-042025-1.pdf](https://www.stamus-networks.com/hubfs/Library/Documents%20(PDFs)/StamusNetworks-TB-CUT-SIEM-INGEST-042025-1.pdf?hsLang=en) 

 

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/share.php?u=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funpacking-declarations-of-compromise-doc-your-first-line-of-defense-against-cyber-threats%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funpacking-declarations-of-compromise-doc-your-first-line-of-defense-against-cyber-threats%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funpacking-declarations-of-compromise-doc-your-first-line-of-defense-against-cyber-threats%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funpacking-declarations-of-compromise-doc-your-first-line-of-defense-against-cyber-threats%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funpacking-declarations-of-compromise-doc-your-first-line-of-defense-against-cyber-threats%3Futm_medium%3Dsocial%26utm_source%3Demail&body=Check+out+https%3A%2F%2Fwww.stamus-networks.com%2Fblog%2Funpacking-declarations-of-compromise-doc-your-first-line-of-defense-against-cyber-threats%3Futm_medium%3Dsocial%26utm_source%3Demail)

![Phil Owens](https://app.hubspot.com/settings/avatar/6045106f92f753e25d23ec7040fb7bb1)

#### Phil Owens

 Phil is the vice president of customer solutions at Stamus Networks. He has over 25 years experience in IT, networking, and cyber security. As a Systems Engineer he has been a trusted advisor to several fortune 500 companies. As a product manager he has created successful cyber security software products. Prior to joining Stamus Networks he held positions at RSA Security, AT&T and IBM. Phil is also proud to have served in the United States Air Force. Phil resides in Florida, USA.

[**](https://www.linkedin.com/in/philow/)

## Schedule a Demo of Clear NDR

[![REQUEST A DEMO](https://no-cache.hubspot.com/cta/default/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f.png)](https://cta-redirect.hubspot.com/cta/redirect/6344338/a3da5fbf-412c-4e3f-a140-f6f33ed8cc5f)

## Related posts

[![](https://www.stamus-networks.com/hubfs/U42.2%20%281%29.png) ](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

### [Clear NDR® U42.2: A New Analyst Experience and a More Powerful AI Investigation Layer](https://www.stamus-networks.com/blog/clear-ndr-enterprise-u42.2-is-now-available?hsLang=en)

At Stamus Networks, we measure releases by how much they improve the day-to-day work of security...

[![Stamus Networks: When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/hubfs/SN-Perimeter-Fails-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

### [When the Perimeter Fails, the Network Tells the Truth](https://www.stamus-networks.com/blog/when-the-perimeter-fails-the-network-tells-the-truth?hsLang=en)

SentinelOne's "Edge Decay" research names the threat. Here's how network detection and response...

[![When EDR Goes Dark: Why Network Visibility is Your Last Line of Truth](https://www.stamus-networks.com/hubfs/SN-EDR-Goes-Dark-Blog-Featured.jpg) ](https://www.stamus-networks.com/blog/when-edr-goes-dark-why-network-visibility-is-your-last-line-of-truth?hsLang=en)

### [When EDR Goes Dark: Why Network Visibility is Your Last Line of Truth](https://www.stamus-networks.com/blog/when-edr-goes-dark-why-network-visibility-is-your-last-line-of-truth?hsLang=en)

I've spent a significant part of my career participating in [NATO cyber defense exercises](https://www.stamus-networks.com/nato-ccdcoe-participation?hsLang=en) -...

[![Stamus-Logo-with-R-white](https://www.stamus-networks.com/hs-fs/hubfs/Stamus-Logo-with-R-white.png?width=2000&height=536&name=Stamus-Logo-with-R-white.png "Stamus-Logo-with-R-white")](https://www.stamus-networks.com/?hsLang=en)

 ABOUT STAMUS® NETWORKS

Stamus Networks is the network intelligence foundation for AI-powered security operations and the creator of the Clear NDR® system. Built on Suricata, the world's leading open-source network security engine, Clear NDR transforms raw network traffic into actionable security insights with unmatched transparency, customization, and effectiveness. Designed to close visibility gaps and reduce alert fatigue, Clear NDR is trusted by leading financial institutions, government agencies, and has been battle-tested over ten years in NATO's largest cybersecurity exercises. Stamus Networks empowers security teams with greater control, fewer false positives, faster response times, and a more responsive, open approach than legacy vendors.

- [**](https://www.linkedin.com/company/stamus-networks)
- [**](https://twitter.com/StamusN/)
- [**](https://www.youtube.com/Stamus-Networks)
- [* *](https://discord.gg/JUMSU9uA)
- <https://www.facebook.com/StamusNetworks>

Paris, FranceIndianapolis, USA

**[contact@stamus-networks.com](mailto:contact@stamus-networks.com)

[Privacy](https://www.stamus-networks.com/privacy-policy?hsLang=en)

 © 2014-2026 Stamus Networks, Inc. All rights Reserved.