IOC Normalizer
Standardise a mixed indicator list into one consistent format.
Paste a list on the left.
How it works
An indicator list assembled from several sources arrives in several conventions: uppercase hashes from one tool, defanged domains from a PDF, URLs with inconsistent host casing. Loading that into anything that compares strings produces duplicates that are not duplicates and misses that are not misses.
Normalisation puts every entry in one form and labels it with its detected type. Hashes are lowercased. Domains are refanged and stripped of a trailing dot. URL hosts are lowercased while the path keeps its case, because a path is case-sensitive and flattening it would change what the indicator points at.
What happens to a line it cannot type
It is returned, marked unknown. A line is only confidently typed when it contains exactly one
indicator and nothing else — "connection from 1.2.3.4 denied" is a log line, not an IP address, and typing it as
one would misrepresent the source. Nothing is dropped between input and output, so the row count you paste is the
row count you get back.
Example
EVIL[.]com becomes evil.com typed as domain;D41D8CD9… becomes
lowercase, typed md5. A full log line comes back unchanged and typed
unknown — run it through the IOC Extractor instead, which is built
for pulling indicators out of surrounding text.
Frequently asked questions
What does normalisation change?
Hashes are lowercased, domains are refanged and stripped of trailing dots, URLs keep their case-sensitive path but lowercase the host, and every entry is labelled with its detected type.
What happens to entries it cannot type?
They are reported in a separate unrecognised list rather than being dropped or guessed at, so nothing disappears silently between input and output.
Related tools
IOC Deduplicator
Collapse a messy indicator list down to its unique entries.
LocalIOC Extractor
Pull indicators of compromise out of any block of text, log or report.
LocalIOC Defanger
Neutralise indicators so they can be shared without becoming clickable.
LocalHash Identifier
Narrow an unlabelled hash down to the algorithms that could have produced it.
LocalHash Generator
Produce SHA-1, SHA-256, SHA-384 and SHA-512 digests of text or a file.
LocalSecurity Headers Analyzer
Review a set of pasted HTTP response headers against current guidance.
Local