Detection & response
A trace left behind by an attack, such as a known bad web address or file, that shows a system has probably been broken into.
Formal
A piece of evidence found on a system or network - an IP address, a domain name, a file's hash value, an odd account - that is known to be linked to a past attack and so suggests a break-in has happened.
In plain English
Like the footprints and a known burglar's tools found in a garden; they do not stop the break-in, but they tell you who has been there.
In practice
A CFCS warning lists the IP addresses and file hashes a ransomware group uses; a shipping company's SOC searches three months of logs and finds one laptop that contacted one of the addresses.
Why it matters
Shared traces let one victim's bad experience warn everyone else quickly, but attackers change them easily, so they catch yesterday's attacks better than tomorrow's.