IOC Extractor
Pull indicators of compromise out of any block of text, log or report.
Paste text on the left. Extraction runs as you type.
How it works
Extraction runs in three ordered passes, and the order is what keeps the output clean. Hash-length hex runs are
matched and removed first, because a 32-character hex string cannot be anything else. URLs and email addresses
come next and are masked out of the remaining text, so https://evil.com/a is reported once as a URL
rather than twice as a URL and a loose domain. What survives is then matched for IP addresses and hostnames.
Before any of that, the whole input is refanged — hxxps[://]evil[.]com becomes a URL the matcher can
see. Only delimited markers count. Space-separated styles like evil dot com are deliberately ignored,
because the words "at" and "dot" appear constantly in ordinary prose and refanging them invents indicators that
were never in the source.
Where it draws the line on domains
A hostname is accepted when its final label is alphabetic, between two and twenty-four characters, and is not a
known file extension. That last rule is what stops payload.exe and report.pdf being
reported as domains, which is the dominant false positive when the source is a log file. It also means a hostname
under a TLD that does not exist will be accepted — a deliberate trade, because the opposite error silently drops
real indicators under newer TLDs.
Example
Given this log extract:
2026-09-19T04:12:08Z beacon hxxps://cdn.evil[.]com/pixel to 203.0.113.9 dropper sha256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 wrote payload.exe, exfil to drop[at]evil[.]net
The result is one URL, one IPv4 address, one SHA-256 hash and one email address — four indicators.
payload.exe is not reported as a domain, and cdn.evil.com is not reported separately
from the URL that contains it.
Frequently asked questions
Does this tool upload what I paste?
No. Extraction runs in a Web Worker inside your own browser tab. No request carrying your input is made, which is why the tool still works with your network disconnected.
Does it recognise defanged indicators?
Yes. Common defanging styles — hxxp, [.], (.), [at], [:] — are refanged before matching, so an indicator written as evil[.]com is extracted as evil.com.
Why did it skip something that looks like a domain?
Extraction requires a valid public suffix, so strings like file.txt or version 1.2.3.4 build numbers are not reported as domains or IPs. Anything ambiguous is listed separately rather than silently dropped.
Related tools
IOC Defanger
Neutralise indicators so they can be shared without becoming clickable.
LocalIOC Deduplicator
Collapse a messy indicator list down to its unique entries.
LocalIOC Normalizer
Standardise a mixed indicator list into one consistent format.
LocalEmail Header Analyzer
Read a raw email header as an ordered delivery path with authentication results.
LocalIOC Refanger
Restore defanged indicators to their original, machine-readable form.
LocalATT&CK Technique Lookup
Find a MITRE ATT&CK technique by ID or name from a bundled dataset.
LocalFrom the intelligence desk
- Threat Actor APT28