Skip to main content
QUIETLYTIC
Cybersecurity

IOC Normalizer

Standardise a mixed indicator list into one consistent format.

Local · nothing leaves this browser Waiting for input
Esc Clear
Normalised and typed

Paste a list on the left.

How it works

An indicator list assembled from several sources arrives in several conventions: uppercase hashes from one tool, defanged domains from a PDF, URLs with inconsistent host casing. Loading that into anything that compares strings produces duplicates that are not duplicates and misses that are not misses.

Normalisation puts every entry in one form and labels it with its detected type. Hashes are lowercased. Domains are refanged and stripped of a trailing dot. URL hosts are lowercased while the path keeps its case, because a path is case-sensitive and flattening it would change what the indicator points at.

What happens to a line it cannot type

It is returned, marked unknown. A line is only confidently typed when it contains exactly one indicator and nothing else — "connection from 1.2.3.4 denied" is a log line, not an IP address, and typing it as one would misrepresent the source. Nothing is dropped between input and output, so the row count you paste is the row count you get back.

Example

EVIL[.]com becomes evil.com typed as domain;D41D8CD9… becomes lowercase, typed md5. A full log line comes back unchanged and typed unknown — run it through the IOC Extractor instead, which is built for pulling indicators out of surrounding text.

Frequently asked questions

What does normalisation change?

Hashes are lowercased, domains are refanged and stripped of trailing dots, URLs keep their case-sensitive path but lowercase the host, and every entry is labelled with its detected type.

What happens to entries it cannot type?

They are reported in a separate unrecognised list rather than being dropped or guessed at, so nothing disappears silently between input and output.

Related tools

From the intelligence desk