Skip to main content
QUIETLYTIC
Cybersecurity

IOC Extractor

Pull indicators of compromise out of any block of text, log or report.

Local · nothing leaves this browser Waiting for input
Esc Clear
Indicators

Paste text on the left. Extraction runs as you type.

How it works

Extraction runs in three ordered passes, and the order is what keeps the output clean. Hash-length hex runs are matched and removed first, because a 32-character hex string cannot be anything else. URLs and email addresses come next and are masked out of the remaining text, so https://evil.com/a is reported once as a URL rather than twice as a URL and a loose domain. What survives is then matched for IP addresses and hostnames.

Before any of that, the whole input is refanged — hxxps[://]evil[.]com becomes a URL the matcher can see. Only delimited markers count. Space-separated styles like evil dot com are deliberately ignored, because the words "at" and "dot" appear constantly in ordinary prose and refanging them invents indicators that were never in the source.

Where it draws the line on domains

A hostname is accepted when its final label is alphabetic, between two and twenty-four characters, and is not a known file extension. That last rule is what stops payload.exe and report.pdf being reported as domains, which is the dominant false positive when the source is a log file. It also means a hostname under a TLD that does not exist will be accepted — a deliberate trade, because the opposite error silently drops real indicators under newer TLDs.

Example

Given this log extract:

2026-09-19T04:12:08Z beacon hxxps://cdn.evil[.]com/pixel to 203.0.113.9
dropper sha256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
wrote payload.exe, exfil to drop[at]evil[.]net

The result is one URL, one IPv4 address, one SHA-256 hash and one email address — four indicators. payload.exe is not reported as a domain, and cdn.evil.com is not reported separately from the URL that contains it.

Frequently asked questions

Does this tool upload what I paste?

No. Extraction runs in a Web Worker inside your own browser tab. No request carrying your input is made, which is why the tool still works with your network disconnected.

Does it recognise defanged indicators?

Yes. Common defanging styles — hxxp, [.], (.), [at], [:] — are refanged before matching, so an indicator written as evil[.]com is extracted as evil.com.

Why did it skip something that looks like a domain?

Extraction requires a valid public suffix, so strings like file.txt or version 1.2.3.4 build numbers are not reported as domains or IPs. Anything ambiguous is listed separately rather than silently dropped.

Related tools

From the intelligence desk