Skip to main content
QUIETLYTIC
Cybersecurity

IOC Deduplicator

Collapse a messy indicator list down to its unique entries.

Local · nothing leaves this browser Waiting for input
Esc Clear
Unique entries

Paste a list on the left.

How it works

A merged indicator list — three analysts' notes, two vendor reports and a SIEM export — is full of entries that are the same thing written differently. Comparing the raw strings finds almost none of them.

So comparison happens on a normalised key instead: refanged, case-folded, trimmed, trailing dot removed. EVIL.com, evil[.]com and evil.com. collapse to a single entry. The first spelling encountered is the one kept, and input order is preserved, so the output still reads against the source list rather than arriving in some arbitrary new order.

Lines split on newlines, commas and semicolons, which covers the shapes these lists actually arrive in. Blank lines are ignored rather than counted.

Example

Twelve lines containing four distinct indicators return four entries, and the status strip reports eight removed. Turning on occurrence counts appends ×3 to any entry that appeared more than once — useful for spotting which indicator every source independently reported.

Frequently asked questions

What counts as a duplicate?

Entries are compared after normalisation — case folded, whitespace trimmed, defanging removed, and trailing dots dropped. So EVIL.com, evil[.]com and evil.com collapse to one entry.

Is the original ordering kept?

Yes. The first occurrence of each unique indicator keeps its position, so the output stays readable against the source list. A count of how many times each appeared is shown alongside.

Related tools

From the intelligence desk